/dev/stdin:226:57-60: Error: transport protocol mapping is only valid after transport protocol match
meta nfproto ipv4 ip daddr @onion counter redirect to 9040 comment "!fw4: Onion"
config ipset
<------>option name 'onion'
<------>option match 'dst_net'
<------>option enabled '1'
<------>option loadfile '/opt/ipset/blocked_ip.dat'
config redirect
option target 'DNAT'
option name 'Onion'
list proto 'tcp'
option src 'lan'
option ipset 'onion'
option dest_port '9040'
........