ChainExpressionType defines the specific operation or data type for an nftables expression. Each type corresponds to a different kind of packet processing logic or value.
Values
| Enum Value | Description |
|---|---|
|
|
Packet/byte counter expression. |
|
|
Metadata access expression (interface, mark, etc.). |
|
|
Xtables match expression (legacy iptables match). |
|
|
Payload (packet header field) access expression. |
|
|
Comparison expression (register vs constant). |
|
|
Bitwise operation expression. |
|
|
Set lookup expression. |
|
|
Load a constant value into a register. |
|
|
Verdict expression (accept, drop, continue, return). |
|
|
Connection tracking expression. |
|
|
NAT (network address translation) expression. |
|
|
IPv6 extension header expression. |
|
|
Dynamic set update expression. |
|
|
Rate limiting expression. |
|
|
Number generator expression (round-robin / random). |
|
|
Packet queueing to userspace expression. |
|
|
Packet rejection expression. |
|
|
Packet duplication expression. |
|
|
Range matching expression. |
|
|
Stateful object reference expression. |
|
|
Port redirect expression. |
|
|
Traffic quota expression. |
|
|
Xtables target expression (legacy iptables target). |
|
|
Connection count limiting expression. |
|
|
Hardware flow offload expression. |
|
|
Masquerade (dynamic SNAT) expression. |
|
|
Hash expression (for load balancing). |
|
|
SYN proxy expression. |
|
|
Connection tracking expectation expression. |
|
|
Security mark expression. |
|
|
Forwarding information base (FIB) lookup expression. |
|
|
Byte order conversion expression. |
|
|
Packet logging expression. |
|
|
Routing information expression. |
|
|
Socket information expression. |
|
|
Transparent proxy expression. |
|
|
Disable connection tracking for the packet. |
|
|
Connection tracking timeout policy expression. |
|
|
Connection tracking helper expression. |
Used by
Expressiontype: An nftables expression representing a single operation or condition within a chain rule.
Example
Example
"COUNTER"