/ip firewall mangle add action=mark-connection chain=forward comment="Bypass LAN" disabled=yes dst-address=!10.50.1.0/24 \ new-connection-mark=public_conn passthrough=yes add action=mark-packet chain=forward connection-mark=public_conn disabled=yes new-packet-mark=lan \ passthrough=no