How to selectively purge firewall connections?

I’m having trouble scripting a netwatch failover that doesn’t purge the entire firewall connection table. How can I match the connections for a specific interface without hardcoding the IP address?