Dynset represents an nftables dynamic set expression. Dynamic sets allow for adding, updating, or deleting elements from a set during packet processing, often used for creating dynamic blocklists or connection tracking.
Fields
| Field Name | Description |
|---|---|
srcRegKey - NftRegister!
|
Register holding the key to insert or update in the dynamic set. |
srcRegData - NftRegister!
|
Register holding the data or value to insert or update in the dynamic set. |
setID - Uint32!
|
Numeric ID of the target set, unique to the current transaction. |
setName - String!
|
The human-readable name of the target set. |
operation - DynsetOperation!
|
The type of operation (add, update, delete) to perform on the dynamic set. |
timeout - Duration!
|
The duration after which a new element in the set will expire, if supported by the set. |
invert - Boolean!
|
Whether to invert the match logic for this dynamic set operation. This can also enable expression mode for updates. |
Used by
ChainExpressionunion: A union of all possible nftables chain expression types.
Example
Example
{
"srcRegKey": "VERDICT",
"srcRegData": "VERDICT",
"setID": "1073741824",
"setName": "abc123",
"operation": "ADD",
"timeout": "600000000",
"invert": true
}