SynProxyExpression represents an nftables expression for SYN proxying. SYN proxying protects against SYN flood attacks by intercepting and validating TCP SYN packets before passing them on to the destination, improving server resilience.
Fields
| Field Name | Description |
|---|---|
mss - Int!
|
The Maximum Segment Size (MSS) value announced to clients during the SYN-ACK handshake, returned as an unsigned 16-bit integer. This should typically match the MSS expected by the backend server. |
wscale - Int!
|
The TCP window scale factor announced to clients, returned as an unsigned 8-bit integer. This should typically match the window scale factor expected by the backend server. |
timestamp - Boolean!
|
If true, the TCP timestamp option will be passed to the backend during the handshake. |
sackPerm - Boolean!
|
If true, the TCP Selective Acknowledgement (SACK) permitted option will be passed to the backend. |
ecn - Boolean!
|
If true, the TCP Explicit Congestion Notification (ECN) option will be passed to the backend. This is not commonly set by users. |
mssValueSet - Boolean!
|
Indicates whether the 'mss' field was explicitly set by the user (even if its value is 0). |
wscaleValueSet - Boolean!
|
Indicates whether the 'wscale' field was explicitly set by the user (even if its value is 0). |
Used by
ChainExpressionunion: A union of all possible nftables chain expression types.
Example
Example
{
"mss": 987,
"wscale": 987,
"timestamp": true,
"sackPerm": false,
"ecn": false,
"mssValueSet": false,
"wscaleValueSet": false
}