OK, I now have /ip firewall mangle (including my two preexisting rules): Flags: X - disabled, I - invalid, D - dynamic 0 chain=forward src-address=192.168.0.0/24 action=mark-connection new-connection-mark=users-con passthrough=yes 1 chain=forward connection-mark=users-con action=mark-packet new-pack...