what you also need is to mark packets with flags: fin,syn,rst,psh,ack,urg/ack and fin,syn,rst,psh,ack,urg/syn unfortunately, mikrotik routeros can't mark urg/ack or urg/syn. at least I don't know how to do it. or maybe we're all misunderstanding, and by having 'tcp-flags=ack,fin,syn,rst,psh,ack,urg'...