Exthdr represents an nftables expression for accessing or manipulating IPv6 extension headers, TCP options, or other protocol options.
Fields
| Field Name | Description |
|---|---|
destRegister - NftRegister!
|
The register where the result of the extended header operation will be stored. |
type - Int!
|
The type of the extended header or option to inspect/manipulate (e.g., AH, ESP, HOPOPT for IPv6), returned as an unsigned 8-bit integer. |
offset - Uint32!
|
The byte offset within the extended header or option to start reading from. |
len - Uint32!
|
The length in bytes of the data to read from the extended header or option. |
flags - ExthdrFlags!
|
Flags associated with the extended header operation, e.g., to check for presence. |
op - ExthdrOperation!
|
The specific protocol or context for the extended header operation (e.g., IPv6, TCP). |
sourceRegister - NftRegister!
|
The register holding the input value if required by the operation. |
Used by
ChainExpressionunion: A union of all possible nftables chain expression types.
Example
Example
{
"destRegister": "VERDICT",
"type": 987,
"offset": "1073741824",
"len": "1073741824",
"flags": "PRESENT",
"op": "IPV6",
"sourceRegister": "VERDICT"
}