On 7.1RC4 on a 4011 if you have "Use IP firewall" enabled on a bridge and use a bridge filter rule to mark packets the counters on the filter rule seem to increment but any rules in the IP firewall that are set to match on that packet mark show 0 hits.
This seems to work on 6.49.