---
title: ConntrackMTInformation type | Wartiva GraphQL API
description: ConntrackMTInformation represents the xt_conntrack (or xt_state for older kernels) iptables match module information.
url: https://wartiva.com/api-docs/types/conntrack-mt-information.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL type

# `ConntrackMTInformation` type

ConntrackMTInformation represents the `xt_conntrack` (or `xt_state` for older kernels) iptables match module information. It allows matching packets based on their connection tracking state and various other connection parameters.

## Fields

| Field Name | Description |
|---|---|
| `origSrcAddr` - [`IpAddress!`](https://wartiva.com/api-docs/types/ip-address.html) | The original source IP address to match in the connection. |
| `origSrcMask` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The netmask for the original source IP address. |
| `origDstAddr` - [`IpAddress!`](https://wartiva.com/api-docs/types/ip-address.html) | The original destination IP address to match in the connection. |
| `origDstMask` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The netmask for the original destination IP address. |
| `replSrcAddr` - [`IpAddress!`](https://wartiva.com/api-docs/types/ip-address.html) | The replied-to source IP address to match in the connection. This is the IP that the original destination replied from. |
| `replSrcMask` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The netmask for the replied-to source IP address. |
| `replDstAddr` - [`IpAddress!`](https://wartiva.com/api-docs/types/ip-address.html) | The replied-to destination IP address to match in the connection. This is the IP that the original source replied to. |
| `replDstMask` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The netmask for the replied-to destination IP address. |
| `expiresMin` - [`Duration!`](https://wartiva.com/api-docs/types/duration.html) | The minimum remaining expiration time for the connection tracking entry to match, as a duration. |
| `expiresMax` - [`Duration!`](https://wartiva.com/api-docs/types/duration.html) | The maximum remaining expiration time for the connection tracking entry to match, as a duration. |
| `l4Proto` - [`NetfilterProtocol!`](https://wartiva.com/api-docs/types/netfilter-protocol.html) | The Layer 4 protocol (e.g., TCP, UDP, SCTP) of the connection to match. |
| `origSrcPort` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | The original source port to match in the connection, returned as an unsigned 16-bit integer. |
| `origDstPort` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | The original destination port to match in the connection, returned as an unsigned 16-bit integer. |
| `replSrcPort` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | The replied-to source port to match in the connection, returned as an unsigned 16-bit integer. |
| `replDstPort` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | The replied-to destination port to match in the connection, returned as an unsigned 16-bit integer. |
| `matchFlags` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | A bitmask of flags to match against the connection tracking entry's flags, returned as an unsigned 16-bit integer. |
| `invertFlags` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | A bitmask of flags to invert the sense of matching for specific fields, returned as an unsigned 16-bit integer. |
| `stateMask` - [`Int`](https://wartiva.com/api-docs/types/int.html) | A bitmask representing the connection tracking states to match (e.g., NEW, ESTABLISHED, RELATED), returned as an unsigned 16-bit integer. Null if not specified. |
| `statusMask` - [`Int`](https://wartiva.com/api-docs/types/int.html) | A bitmask representing the connection tracking status to match, returned as an unsigned 16-bit integer. Null if not specified. |
| `origSrcPortHigh` - [`Int`](https://wartiva.com/api-docs/types/int.html) | The high value for the original source port range, if a range is specified, returned as an unsigned 16-bit integer. Null if not specified. |
| `origDstPortHigh` - [`Int`](https://wartiva.com/api-docs/types/int.html) | The high value for the original destination port range, if a range is specified, returned as an unsigned 16-bit integer. Null if not specified. |
| `replSrcPortHigh` - [`Int`](https://wartiva.com/api-docs/types/int.html) | The high value for the replied-to source port range, if a range is specified, returned as an unsigned 16-bit integer. Null if not specified. |
| `replDstPortHigh` - [`Int`](https://wartiva.com/api-docs/types/int.html) | The high value for the replied-to destination port range, if a range is specified, returned as an unsigned 16-bit integer. Null if not specified. |

## Used by

- [`XtablesInfo`](https://wartiva.com/api-docs/types/xtables-info.html) union: Xtables information union type.

## Example

### Example

```json
{
  "origSrcAddr": IpAddress,
  "origSrcMask": "abc123",
  "origDstAddr": IpAddress,
  "origDstMask": "xyz789",
  "replSrcAddr": IpAddress,
  "replSrcMask": "abc123",
  "replDstAddr": IpAddress,
  "replDstMask": "abc123",
  "expiresMin": "600000000",
  "expiresMax": "600000000",
  "l4Proto": "UNSPECIFIED",
  "origSrcPort": 987,
  "origDstPort": 123,
  "replSrcPort": 123,
  "replDstPort": 123,
  "matchFlags": 987,
  "invertFlags": 987,
  "stateMask": 123,
  "statusMask": 123,
  "origSrcPortHigh": 987,
  "origDstPortHigh": 123,
  "replSrcPortHigh": 987,
  "replDstPortHigh": 123
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
