Endpoint configuration · GraphQL type

CtExpectExpression type

CtExpectExpression represents an nftables expression for managing Connection Tracking (CT) expectations. CT expectations are used by connection tracking helpers (e.g., FTP, SIP) to anticipate related connections and allow them through the firewall.

Fields

Field Name Description
l3Proto - NetfilterProtocol! The Layer 3 protocol (e.g., IPv4, IPv6) for which the expectation is created.
l4Proto - NetfilterProtocol! The Layer 4 protocol (e.g., TCP, UDP) for which the expectation is created.
dPort - Int! The destination port for the expected connection, returned as an unsigned 16-bit integer.
timeout - Uint32! The timeout in seconds for which this expectation will remain active.
size - Int! The maximum number of concurrent expectations of this type, returned as an unsigned 8-bit integer.

Used by

  • ChainExpression union: A union of all possible nftables chain expression types.

Example

Example

{
  "l3Proto": "UNSPECIFIED",
  "l4Proto": "UNSPECIFIED",
  "dPort": 987,
  "timeout": "1073741824",
  "size": 123
}