Connection tracking key for nftables ct expressions. Specifies which connection tracking metadata field to match or set in a rule. Reference: nftables — Conntrack metadata
Values
| Enum Value | Description |
|---|---|
|
|
Connection tracking state (new, established, related, invalid). |
|
|
Direction of the packet within the connection (original/reply). |
|
|
Connection tracking status flags (e.g. SNAT, DNAT, confirmed). |
|
|
Connection tracking mark. |
|
|
SELinux security mark. |
|
|
Remaining timeout before connection expires. |
|
|
Name of the connection tracking helper (e.g. ftp, sip). |
|
|
Layer 3 protocol (IPv4/IPv6). |
|
|
Source address. |
|
|
Destination address. |
|
|
Layer 4 protocol (TCP/UDP/etc.). |
|
|
Source port. |
|
|
Destination port. |
|
|
Connection tracking label bitmask. |
|
|
Total packet count for the connection. |
|
|
Total byte count for the connection. |
|
|
Average packet size. |
|
|
Connection tracking zone. |
|
|
Event mask for conntrack events. |
|
|
Source IPv4 address. |
|
|
Destination IPv4 address. |
|
|
Source IPv6 address. |
|
|
Destination IPv6 address. |
|
|
Unique connection ID. |
Used by
CtExpressiontype: Inspect or modify connection tracking (conntrack) state, such as connection state, marks, labels, addresses, or counters.
Example
Example
"STATE"