1*a71a9546SAutomerger Merge Workeriptables-translate -A INPUT -m connmark --mark 2 -j ACCEPT 2*a71a9546SAutomerger Merge Workernft 'add rule ip filter INPUT ct mark 0x2 counter accept' 3*a71a9546SAutomerger Merge Worker 4*a71a9546SAutomerger Merge Workeriptables-translate -A INPUT -m connmark ! --mark 2 -j ACCEPT 5*a71a9546SAutomerger Merge Workernft 'add rule ip filter INPUT ct mark != 0x2 counter accept' 6*a71a9546SAutomerger Merge Worker 7*a71a9546SAutomerger Merge Workeriptables-translate -A INPUT -m connmark --mark 10/10 -j ACCEPT 8*a71a9546SAutomerger Merge Workernft 'add rule ip filter INPUT ct mark and 0xa == 0xa counter accept' 9*a71a9546SAutomerger Merge Worker 10*a71a9546SAutomerger Merge Workeriptables-translate -A INPUT -m connmark ! --mark 10/10 -j ACCEPT 11*a71a9546SAutomerger Merge Workernft 'add rule ip filter INPUT ct mark and 0xa != 0xa counter accept' 12*a71a9546SAutomerger Merge Worker 13*a71a9546SAutomerger Merge Workeriptables-translate -t mangle -A PREROUTING -p tcp --dport 40 -m connmark --mark 0x40 14*a71a9546SAutomerger Merge Workernft 'add rule ip mangle PREROUTING tcp dport 40 ct mark 0x40 counter' 15