CtExpectExpression represents an nftables expression for managing Connection Tracking (CT) expectations. CT expectations are used by connection tracking helpers (e.g., FTP, SIP) to anticipate related connections and allow them through the firewall.
Fields
| Field Name | Description |
|---|---|
l3Proto - NetfilterProtocol!
|
The Layer 3 protocol (e.g., IPv4, IPv6) for which the expectation is created. |
l4Proto - NetfilterProtocol!
|
The Layer 4 protocol (e.g., TCP, UDP) for which the expectation is created. |
dPort - Int!
|
The destination port for the expected connection, returned as an unsigned 16-bit integer. |
timeout - Uint32!
|
The timeout in seconds for which this expectation will remain active. |
size - Int!
|
The maximum number of concurrent expectations of this type, returned as an unsigned 8-bit integer. |
Used by
ChainExpressionunion: A union of all possible nftables chain expression types.
Example
Example
{
"l3Proto": "UNSPECIFIED",
"l4Proto": "UNSPECIFIED",
"dPort": 987,
"timeout": "1073741824",
"size": 123
}