What is better among the two for marking packets in pre-routing chain in mangle coming from a specific sublet?
-
add action=mark-packet chain=prerouting comment=“Internet Zone2–DN” disabled=no dst-address-list=“Internet Zone2”
new-packet-mark=“Internet Zone2” passthrough=no
… Internet Zone2 is defined in address-list as a subnet. -
add action=mark-connection chain=prerouting comment=“Internet Zone2–DN” disabled=no dst-address-list=“Internet Zone2”
new-connection-mark=“Internet Zone2 Conn” passthrough=yes
add action=mark-packet chain=prerouting comment=“Internet Zone2–DN” disabled=no connection-mark=“Internet Zone2 Conn”
new-packet-mark=“Internet Zone2” passthrough=no
Which one is better and why?
Thanks,
Sudipta