---
title: CtExpectExpression type | Wartiva GraphQL API
description: CtExpectExpression represents an nftables expression for managing Connection Tracking (CT) expectations. Wartiva GraphQL API reference with examples.
url: https://wartiva.com/api-docs/types/ct-expect-expression.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL type

# `CtExpectExpression` type

CtExpectExpression represents an nftables expression for managing Connection Tracking (CT) expectations. CT expectations are used by connection tracking helpers (e.g., FTP, SIP) to anticipate related connections and allow them through the firewall.

## Fields

| Field Name | Description |
|---|---|
| `l3Proto` - [`NetfilterProtocol!`](https://wartiva.com/api-docs/types/netfilter-protocol.html) | The Layer 3 protocol (e.g., IPv4, IPv6) for which the expectation is created. |
| `l4Proto` - [`NetfilterProtocol!`](https://wartiva.com/api-docs/types/netfilter-protocol.html) | The Layer 4 protocol (e.g., TCP, UDP) for which the expectation is created. |
| `dPort` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | The destination port for the expected connection, returned as an unsigned 16-bit integer. |
| `timeout` - [`Uint32!`](https://wartiva.com/api-docs/types/uint32.html) | The timeout in seconds for which this expectation will remain active. |
| `size` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | The maximum number of concurrent expectations of this type, returned as an unsigned 8-bit integer. |

## Used by

- [`ChainExpression`](https://wartiva.com/api-docs/types/chain-expression.html) union: A union of all possible nftables chain expression types.

## Example

### Example

```json
{
  "l3Proto": "UNSPECIFIED",
  "l4Proto": "UNSPECIFIED",
  "dPort": 987,
  "timeout": "1073741824",
  "size": 123
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
