This catches (ACK,FIN,PSH) as well. What are these? I will not prioritize these.maybe just mark packets with connection-type=new? =)
add chain=postrouting action=mark-packet new-packet-mark=acknoledgements passthrough=no tcp-flags=ack protocol=tcp
tags (omit passwords).