1iptables-translate -A INPUT -m policy --pol ipsec --dir in 2nft 'add rule ip filter INPUT meta secpath exists counter' 3 4iptables-translate -A INPUT -m policy --pol none --dir in 5nft 'add rule ip filter INPUT meta secpath missing counter' 6