bridge firewall conntrack problem

From: antgel (
Date: 05/15/03

Date: Thu, 15 May 2003 10:01:11 +0100

Hi all,

I've set up a Debian bridging firewall. First time I've ever done it,
but it all went smoothly thanks to the great guide on

However I'm falling at the last hurdle. I had to recompile the kernel
to include the bridging code. This was smooth as well. However I
have a problem when I try to set up a stateful rule, e.g.

iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables: No chain/target/match by that name

Other types of rule work fine. I suppose this would indicate that I
don't have ip_conntrack in the kernel, but I do, see below:

debian:/usr/local/bin# lsmod
Module Size Used by Not tainted
iptable_mangle 2112 0 (unused)
ip_conntrack_irc 2400 0 (unused)
ip_conntrack_ftp 3136 0 (unused)
ip_conntrack 12716 2 [ip_conntrack_irc ip_conntrack_ftp]
ipt_REJECT 2784 0 (unused)
ipt_LOG 3232 0 (unused)
iptable_filter 1728 0 (unused)
ip_tables 10624 4 [iptable_mangle ipt_REJECT ipt_LOG

How can I go about debugging this?


Replace 'usenet' with 'antony' if replying via email.

Relevant Pages

  • Re: New sarge install trying to find modules
    ... The installer was really smooth, ... > with, i've compiled my own kernel, with the src's from (it's ... > but on boot something is getting called, i've checked the udev configs ...
  • Re: New sarge install trying to find modules
    ... On Tue, 2004-09-14 at 20:47, Justin Guerin wrote: ... The installer was really smooth, ... >> kernel, it just errors, everything keeps booting, but i'd still like ...
  • Re: kernel 2.6.38 & auto sched
    ... SRPMs from koji) and it seems to be working just fine (must like ... I am now running the 2.6.38-1.fc15.x86_64 kernel - so far so good. ... I suspect it is quite smooth now.) ... To unsubscribe or change subscription options: ...
  • Re: [patch] CFS scheduler, -v18
    ... processes, only 7 of them show smooth rounds, while all the other ones ... I have no idea about what version brought that unexpected behaviour, ... could you send me the file the script produced. ... If your kernel has no /proc/config.gz then please send me your .config ...
  • Interactivity degrades with CONFIG_[FAIR]_GROUP_SCHED set in 2.6.24 and later
    ... I am very excited to see the CFS in the kernel. ... Interactivity is really great; much better than before. ... less smooth under load. ... seemed to not be getting an "interactive" amount of CPU time, ...