TCP connection

netfilter rule is configured that drops all the packets from peer to a socket we're dealing with. This rule sits
in the host netfilter tables after the criu dump command finishes and it should be there when you issue the
criu restore one. The locking method can be specified using the [ <code>--network-lock</code>]option.
Another thing to note is -- on restore there should be available the IP address, that was used by the connection.

