Mangle Rule for ipsec trafic

I’m looking for a way to mark traffic if it comes from an IPSEC tunnel.

Does anyone have an idea how I can recognize this?
I definitely don’t want to use source IPs or networks.

Have you tried the “ipsec-policy” property of firewall rules?