Squid with connmark

Turnbull, John
What is the best way to intercept marked packets with squid and squid to be aware of mark and create an ACL on the mark?

I have tried setting the mark and then DNAT and redirect  to the intercept port and when printing the nmark I am getting 0

Is it required to use tproxy with tproxy-mark?


