table ip filter { ct timeout agressive-tcp { ... policy = { established : 100, close_wait : 4, close : 4 } } }
for consistency with map syntax. Signed-off-by: Pablo Neira Ayuso <pa...@netfilter.org> --- src/rule.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/rule.c b/src/rule.c index 6dbc553e6c33..0a91917f7568 100644 --- a/src/rule.c +++ b/src/rule.c @@ -1760,7 +1760,7 @@ static void print_proto_timeout_policy(uint8_t l4, const uint32_t *timeout, if (timeout[i] != timeout_protocol[l4].dflt_timeout[i]) { if (comma) nft_print(octx, ", "); - nft_print(octx, "%s: %u", + nft_print(octx, "%s : %u", timeout_protocol[l4].state_to_name[i], timeout[i]); comma = true; -- 2.11.0