};
 
 struct nf_flow_key {
+       struct flow_dissector_key_meta                  meta;
        struct flow_dissector_key_control               control;
        struct flow_dissector_key_basic                 basic;
        union {
        struct nf_flow_key *mask = &match->mask;
        struct nf_flow_key *key = &match->key;
 
+       NF_FLOW_DISSECTOR(match, FLOW_DISSECTOR_KEY_META, meta);
        NF_FLOW_DISSECTOR(match, FLOW_DISSECTOR_KEY_CONTROL, control);
        NF_FLOW_DISSECTOR(match, FLOW_DISSECTOR_KEY_BASIC, basic);
        NF_FLOW_DISSECTOR(match, FLOW_DISSECTOR_KEY_IPV4_ADDRS, ipv4);
        NF_FLOW_DISSECTOR(match, FLOW_DISSECTOR_KEY_TCP, tcp);
        NF_FLOW_DISSECTOR(match, FLOW_DISSECTOR_KEY_PORTS, tp);
 
+       key->meta.ingress_ifindex = tuple->iifidx;
+       mask->meta.ingress_ifindex = 0xffffffff;
+
        switch (tuple->l3proto) {
        case AF_INET:
                key->control.addr_type = FLOW_DISSECTOR_KEY_IPV4_ADDRS;
        key->tp.dst = tuple->dst_port;
        mask->tp.dst = 0xffff;
 
-       match->dissector.used_keys |= BIT(FLOW_DISSECTOR_KEY_CONTROL) |
+       match->dissector.used_keys |= BIT(FLOW_DISSECTOR_KEY_META) |
+                                     BIT(FLOW_DISSECTOR_KEY_CONTROL) |
                                      BIT(FLOW_DISSECTOR_KEY_BASIC) |
                                      BIT(FLOW_DISSECTOR_KEY_PORTS);
        return 0;