Endpoint configuration · GraphQL type

ConntrackMTInformation type

ConntrackMTInformation represents the xt_conntrack (or xt_state for older kernels) iptables match module information. It allows matching packets based on their connection tracking state and various other connection parameters.

Fields

Field Name Description
origSrcAddr - IpAddress! The original source IP address to match in the connection.
origSrcMask - String! The netmask for the original source IP address.
origDstAddr - IpAddress! The original destination IP address to match in the connection.
origDstMask - String! The netmask for the original destination IP address.
replSrcAddr - IpAddress! The replied-to source IP address to match in the connection. This is the IP that the original destination replied from.
replSrcMask - String! The netmask for the replied-to source IP address.
replDstAddr - IpAddress! The replied-to destination IP address to match in the connection. This is the IP that the original source replied to.
replDstMask - String! The netmask for the replied-to destination IP address.
expiresMin - Duration! The minimum remaining expiration time for the connection tracking entry to match, as a duration.
expiresMax - Duration! The maximum remaining expiration time for the connection tracking entry to match, as a duration.
l4Proto - NetfilterProtocol! The Layer 4 protocol (e.g., TCP, UDP, SCTP) of the connection to match.
origSrcPort - Int! The original source port to match in the connection, returned as an unsigned 16-bit integer.
origDstPort - Int! The original destination port to match in the connection, returned as an unsigned 16-bit integer.
replSrcPort - Int! The replied-to source port to match in the connection, returned as an unsigned 16-bit integer.
replDstPort - Int! The replied-to destination port to match in the connection, returned as an unsigned 16-bit integer.
matchFlags - Int! A bitmask of flags to match against the connection tracking entry's flags, returned as an unsigned 16-bit integer.
invertFlags - Int! A bitmask of flags to invert the sense of matching for specific fields, returned as an unsigned 16-bit integer.
stateMask - Int A bitmask representing the connection tracking states to match (e.g., NEW, ESTABLISHED, RELATED), returned as an unsigned 16-bit integer. Null if not specified.
statusMask - Int A bitmask representing the connection tracking status to match, returned as an unsigned 16-bit integer. Null if not specified.
origSrcPortHigh - Int The high value for the original source port range, if a range is specified, returned as an unsigned 16-bit integer. Null if not specified.
origDstPortHigh - Int The high value for the original destination port range, if a range is specified, returned as an unsigned 16-bit integer. Null if not specified.
replSrcPortHigh - Int The high value for the replied-to source port range, if a range is specified, returned as an unsigned 16-bit integer. Null if not specified.
replDstPortHigh - Int The high value for the replied-to destination port range, if a range is specified, returned as an unsigned 16-bit integer. Null if not specified.

Used by

Example

Example

{
  "origSrcAddr": IpAddress,
  "origSrcMask": "abc123",
  "origDstAddr": IpAddress,
  "origDstMask": "xyz789",
  "replSrcAddr": IpAddress,
  "replSrcMask": "abc123",
  "replDstAddr": IpAddress,
  "replDstMask": "abc123",
  "expiresMin": "600000000",
  "expiresMax": "600000000",
  "l4Proto": "UNSPECIFIED",
  "origSrcPort": 987,
  "origDstPort": 123,
  "replSrcPort": 123,
  "replDstPort": 123,
  "matchFlags": 987,
  "invertFlags": 987,
  "stateMask": 123,
  "statusMask": 123,
  "origSrcPortHigh": 987,
  "origDstPortHigh": 123,
  "replSrcPortHigh": 987,
  "replDstPortHigh": 123
}