ChainPriority defines the execution order of chains attached to the same hook. Chains with lower priority values (e.g., FIRST) are evaluated before those with higher values.
Values
| Enum Value | Description |
|---|---|
|
|
The earliest possible priority for a chain. |
|
|
Priority for connection tracking defragmentation. |
|
|
Priority for raw packet processing, before connection tracking. |
|
|
Priority for SELinux processing, executed very early. |
|
|
Priority for connection tracking. |
|
|
Priority for packet mangling (modifying packet headers). |
|
|
Priority for Destination Network Address Translation (DNAT). |
|
|
Priority for general packet filtering. |
|
|
Priority for security-related processing. |
|
|
Priority for Source Network Address Translation (SNAT). |
|
|
Priority for SELinux processing, executed very late. |
|
|
Priority for connection tracking helpers (e.g., for FTP, SIP). |
|
|
Priority for confirming connection tracking entries. |
|
|
Priority is not specified or unknown. |
Used by
Chaintype: Represents an nftables chain, which is a named list of rules that are executed in order.
Example
Example
"FIRST"