firewall: implement selective conntrack flushing (#10225)