---
title: CTKey enum | Wartiva GraphQL API
description: Connection tracking key for nftables ct expressions. Specifies which connection tracking metadata field to match or set in a rule.
url: https://wartiva.com/api-docs/types/ct-key.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `CTKey` enum

Connection tracking key for nftables ct expressions. Specifies which connection tracking metadata field to match or set in a rule. Reference: [nftables — Conntrack metadata](https://wiki.nftables.org/wiki-nftables/index.php/Conntrack_metadata)

## Values

| Enum Value | Description |
|---|---|
| `STATE` | Connection tracking state (new, established, related, invalid). |
| `DIRECTION` | Direction of the packet within the connection (original/reply). |
| `STATUS` | Connection tracking status flags (e.g. SNAT, DNAT, confirmed). |
| `MARK` | Connection tracking mark. |
| `SECMARK` | SELinux security mark. |
| `EXPIRATION` | Remaining timeout before connection expires. |
| `HELPER` | Name of the connection tracking helper (e.g. ftp, sip). |
| `L3PROTOCOL` | Layer 3 protocol (IPv4/IPv6). |
| `SRC` | Source address. |
| `DST` | Destination address. |
| `PROTOCOL` | Layer 4 protocol (TCP/UDP/etc.). |
| `PROTOSRC` | Source port. |
| `PROTODST` | Destination port. |
| `LABELS` | Connection tracking label bitmask. |
| `PKTS` | Total packet count for the connection. |
| `BYTES` | Total byte count for the connection. |
| `AVGPKT` | Average packet size. |
| `ZONE` | Connection tracking zone. |
| `EVENTMASK` | Event mask for conntrack events. |
| `SRCIP` | Source IPv4 address. |
| `DSTIP` | Destination IPv4 address. |
| `SRCIP6` | Source IPv6 address. |
| `DSTIP6` | Destination IPv6 address. |
| `ID` | Unique connection ID. |

## Used by

- [`CtExpression`](https://wartiva.com/api-docs/types/ct-expression.html) type: Inspect or modify connection tracking (conntrack) state, such as connection state, marks, labels, addresses, or counters.

## Example

### Example

```json
"STATE"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
