For firewall and policy route, add matcher for "connection mark".
Also, for policy route, add option "set connection-mark <mark>"
References:
- https://wiki.nftables.org/wiki-nftables/index.php/Quick_reference-nftables_in_10_minutes#Ct
- https://wiki.nftables.org/wiki-nftables/index.php/Matching_connection_tracking_stateful_metainformation#ct_mark_-_conntrack_mark
- https://wiki.nftables.org/wiki-nftables/index.php/Setting_packet_metainformation#packet_mark_and_conntrack_mark