NFTables meta key for packet metadata access. Used in meta expressions to match or set packet metadata such as interface name, mark, protocol, and packet routing information. Reference: nftables — Matching packet metainformation
Values
| Enum Value | Description |
|---|---|
|
|
Packet length in bytes (NFT_META_LEN). |
|
|
Layer 2 ethertype protocol (NFT_META_PROTOCOL). |
|
|
TC packet priority/class ID (NFT_META_PRIORITY). |
|
|
Packet mark / connection mark (NFT_META_MARK). |
|
|
Input interface index (NFT_META_IIF). |
|
|
Output interface index (NFT_META_OIF). |
|
|
Input interface name (NFT_META_IIFNAME). |
|
|
Output interface name (NFT_META_OIFNAME). |
|
|
Input interface type (NFT_META_IIFTYPE). |
|
|
Output interface type (NFT_META_OIFTYPE). |
|
|
Socket UID (NFT_META_SKUID). |
|
|
Socket GID (NFT_META_SKGID). |
|
|
Enable/disable packet tracing (NFT_META_NFTRACE). |
|
|
Routing realm / class ID (NFT_META_RTCLASSID). |
|
|
Security context mark (NFT_META_SECMARK). |
|
|
Netfilter protocol family (NFT_META_NFPROTO). |
|
|
Layer 4 protocol number (NFT_META_L4PROTO). |
|
|
Bridge input interface name (NFT_META_BRI_IIFNAME). |
|
|
Bridge output interface name (NFT_META_BRI_OIFNAME). |
|
|
Packet type (unicast, broadcast, multicast) (NFT_META_PKTTYPE). |
|
|
CPU number the packet is being processed on (NFT_META_CPU). |
|
|
Input interface group (NFT_META_IIFGROUP). |
|
|
Output interface group (NFT_META_OIFGROUP). |
|
|
Control group v1 classID (NFT_META_CGROUP). |
|
|
Pseudo-random number (NFT_META_PRANDOM). |
Used by
MetaExpressiontype: MetaExpression represents an nftables expression for accessing meta-data about the packet, the network device, or the system context.
Example
Example
"LEN"