Networking Forums

Networking Forums > Computer Networking > Linux Networking > IPTables: "No chain/target/match by that name"

Reply
Thread Tools Display Modes

IPTables: "No chain/target/match by that name"

 
 
Martin Herbert Dietze
Guest
Posts: n/a

 
      01-11-2005, 10:03 AM
Hello,

on my system (Debian unstable, kernel 2.6.8), I don't get this
simple iptables script running:

| IPTABLES=/sbin/iptables
|
| $IPTABLES -F
| $IPTABLES -X
| $IPTABLES -Z
|
| $IPTABLES -P INPUT ACCEPT
| $IPTABLES -P OUTPUT ACCEPT
| $IPTABLES -P FORWARD ACCEPT
|
| $IPTABLES -N ilocal
| $IPTABLES -N olocal
|
| $IPTABLES -A INPUT -j ilocal -i eth0
| $IPTABLES -A OUTPUT -j olocal -o eth0
|
| $IPTABLES -v -A ilocal -m state --state ESTABLISHED,RELATED -j ACCEPT

At the last line I get this error:

| ACCEPT all opt -- in * out * 0.0.0.0/0 -> 0.0.0.0/0 state RELATED,ESTABLISHED
| iptables: No chain/target/match by that name

My kernel configuration contains these IP_NF-related options:

| CONFIG_IP_NF_CONNTRACK=y
| CONFIG_IP_NF_FTP=y
| CONFIG_IP_NF_IRC=y
| CONFIG_IP_NF_TFTP=y
| CONFIG_IP_NF_AMANDA=y
| CONFIG_IP_NF_QUEUE=y
| CONFIG_IP_NF_IPTABLES=y
| CONFIG_IP_NF_MATCH_LIMIT=y
| CONFIG_IP_NF_MATCH_IPRANGE=y
| CONFIG_IP_NF_MATCH_MAC=y
| CONFIG_IP_NF_MATCH_PKTTYPE=y
| CONFIG_IP_NF_MATCH_MARK=y
| CONFIG_IP_NF_MATCH_MULTIPORT=y
| CONFIG_IP_NF_MATCH_TOS=y
| CONFIG_IP_NF_MATCH_RECENT=y
| CONFIG_IP_NF_MATCH_ECN=y
| CONFIG_IP_NF_MATCH_DSCP=y
| CONFIG_IP_NF_MATCH_AH_ESP=y
| CONFIG_IP_NF_MATCH_LENGTH=y
| CONFIG_IP_NF_MATCH_TTL=y
| CONFIG_IP_NF_MATCH_TCPMSS=y
| CONFIG_IP_NF_MATCH_OWNER=y
| CONFIG_IP_NF_FILTER=y
| CONFIG_IP_NF_TARGET_REJECT=y
| CONFIG_IP_NF_NAT=y
| CONFIG_IP_NF_NAT_NEEDED=y
| CONFIG_IP_NF_TARGET_MASQUERADE=y
| CONFIG_IP_NF_TARGET_REDIRECT=y
| CONFIG_IP_NF_TARGET_NETMAP=y
| CONFIG_IP_NF_TARGET_SAME=y
| CONFIG_IP_NF_NAT_IRC=y
| CONFIG_IP_NF_NAT_FTP=y
| CONFIG_IP_NF_NAT_TFTP=y
| CONFIG_IP_NF_NAT_AMANDA=y

Any idea what is going wrong?

Cheers,

Martin

--
while (!asleep)
++sheep;
-=-=- -=-=-=-=-
Dipl.Ing. Martin "Herbert" Dietze -=-=- University of Buckingham -=-=-
 
Reply With Quote
 
 
 
 
Martin Herbert Dietze
Guest
Posts: n/a

 
      01-11-2005, 04:36 PM
Found it! Just for the archive:

Martin Herbert Dietze <(E-Mail Removed)> wrote:

> | $IPTABLES -v -A ilocal -m state --state ESTABLISHED,RELATED -j ACCEPT


This requires the `ipt_states' module. I did not have it
with my custom-built kernel.

Cheers,

Martin

--
Pilot: Call me a fuel truck.
Tower: You're a fuel truck.
-=-=- -=-=-=-=-
Dipl.Ing. Martin "Herbert" Dietze -=-=- University of Buckingham -=-=-
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Local forwarding with "iptables" gives "invalid arguments" newsfuzzy@geekmail.de Linux Networking 0 07-19-2006 02:47 PM
Attention Plus.net Re: SPEWS DOLTS "WindsorFox", "Kevin-!:?)", "SpinDryer" SPAM broadband newsgroup !:?) Broadband 0 11-28-2005 04:28 AM
Attention Plus.Net Re: SPEWS DOLTS "WindsorFox", "Kevin-!:?)", "SpinDryer" SPAM braodband newsgroup !:?) Broadband 0 11-28-2005 03:03 AM
"iptables mark with filter fw" vs "u32 match" =?ISO-8859-2?Q?Pawe=B3?= Staszewski Linux Networking 3 03-05-2005 09:23 PM
Problem with ISC DHCPD Lease variabels in combination with "Match if" Niels Basjes Linux Networking 0 04-08-2004 11:16 PM



1 2 3 4 5 6 7 8 9 10 11