iptables-translate -t filter -A INPUT -m ipcomp --ipcompspi 0x12 -j ACCEPT | |
nft add rule ip filter INPUT comp cpi 18 counter accept | |
iptables-translate -t filter -A INPUT -m ipcomp ! --ipcompspi 0x12 -j ACCEPT | |
nft add rule ip filter INPUT comp cpi != 18 counter accept |