| --fwip IP | Yes | — | IPv4 address of the firewall appliance that receives redirected
traffic. |
| --fwsubnet CIDR | No | — | IPv4 CIDR of the firewall subnet. Required only when firewall
instances sit behind a load balancer operating in Direct Server
Return (DSR) mode. |
| --hc on|off | No | on | Enable or disable the kernel health-check worker. When
off, no probe packets are sent and
health_check_state stays
0. |
| --hc_interval SECONDS | No | 1 | Probe interval in seconds (range: 1–86400). The worker sends one
probe per interval, or skips it if live firewall traffic was seen
within that window. |
| --hc_fail_count COUNT | No | 3 | Number of consecutive missed intervals before
health_check_state drops to 0
(range: 1–255). The firewall is considered stale after
hc_interval × hc_fail_count seconds with no
reply. |
| --hc_pkt 5-TUPLE | No | udp:169.254.1.1:45000:169.254.1.2:45000 | Probe 5-tuple in
proto:src_ip:src_port:dst_ip:dst_port format.
proto must be tcp or
udp. |