/ ip firewall mangle
add chain=prerouting p2p=all-p2p action=mark-connection new-connection-mark=p2p-connections \
passthrough=yes comment="P2P" disabled=no
add chain=prerouting connection-mark=p2p-connections action=mark-packet new-packet-mark=4 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=20 action=mark-packet new-packet-mark=3 \
passthrough=yes comment="FTP" disabled=no
add chain=prerouting protocol=tcp dst-port=20 action=mark-packet new-packet-mark=3 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=icmp action=mark-packet new-packet-mark=1 \
passthrough=yes comment="ICMP" disabled=no
add chain=prerouting protocol=udp dst-port=10000-20000 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="VOIP RTP" disabled=no
add chain=prerouting protocol=udp src-port=10000-20000 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=0-1024 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="LOW PORTS UDP" disabled=no
add chain=prerouting protocol=udp src-port=0-1024 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=80 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="HTTP" disabled=no
add chain=prerouting protocol=tcp src-port=80 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=6666-6668 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="IRC" disabled=no
add chain=prerouting protocol=tcp src-port=6666-6668 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=3128 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="PROXY" disabled=no
add chain=prerouting protocol=tcp src-port=3128 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=3130 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=3130 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=8080 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=8080 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=25 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="SMTP" disabled=no
add chain=prerouting protocol=tcp dst-port=25 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=110 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="POP3" disabled=no
add chain=prerouting protocol=tcp src-port=110 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=143 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="IMAP" disabled=no
add chain=prerouting protocol=tcp src-port=143 action=mark-packet new-packet-mark=2 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=22 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="SSH" disabled=no
add chain=prerouting protocol=tcp src-port=22 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=115 action=mark-packet new-packet-mark=3 \
passthrough=yes comment="SFTP" disabled=no
add chain=prerouting protocol=tcp src-port=115 action=mark-packet new-packet-mark=3 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=69 action=mark-packet new-packet-mark=3 \
passthrough=yes comment="TFTP" disabled=no
add chain=prerouting protocol=tcp src-port=69 action=mark-packet new-packet-mark=3 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=123 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="NTP" disabled=no
add chain=prerouting protocol=tcp src-port=123 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=161 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="SNMP" disabled=no
add chain=prerouting protocol=tcp src-port=161 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=gre action=mark-packet new-packet-mark=1 \
passthrough=yes comment="GRE" disabled=no
add chain=prerouting protocol=gre action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=3389 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="REMOTE DESKTOP" disabled=no
add chain=prerouting protocol=tcp src-port=3389 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=873 action=mark-packet new-packet-mark=3 \
passthrough=yes comment="RSYNC" disabled=no
add chain=prerouting protocol=tcp src-port=873 action=mark-packet new-packet-mark=3 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=179 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="BGP" disabled=no
add chain=prerouting protocol=tcp src-port=179 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=2605 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=2605 action=mark-packet new-packet-mark=1 \
passthrough=yes comment="" disabled=no