IPtables Matches

modulename: em_ipt.ko

configname: CONFIG_NET_EMATCH_IPT

Linux Kernel Configuration
└─>Networking support
└─>Networking options
└─>QoS and/or fair queueing
└─>Network packet filtering framework (Netfilter)
└─>IPtables Matches
In linux kernel since version 4.2 (release Date: 2015-08-30)  
Say Y here to be able to classify packets based on iptables
matches.
Current supported match is "policy" which allows packet classification
based on IPsec policy that was used during decapsulation

To compile this code as a module, choose M here: the
module will be called em_ipt.

source code: