I am using RouterOS 4.x. Currently, i do mangle most of the connection at forward chain. Undefined connection will be captured by no-mark by default. But i still see some connection have wild connection without marking as below attachment file. Why?
no-mark-udp.png
You do not have the required permissions to view the files attached to this post.
All of the connections are unreplied (U). Since unreplied means connection was not established - connection mark will not apply. Not to worry however, all those connections are not passing any traffic. And if they do, (somehow conntrack missed it) you should be able to stop them with a filter to drop packets of invalid connections.