Skip to content
View in the app

A better way to browse. Learn more.

Armbian Community Forums

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

iptables module missing from 6.18.10-current-meson64 kernel

Featured Replies

Hello.

 

It seems there is an issue with iptables in the 6.18.10-current-meson64 kernel.

I can't start Docker because of this.

 

```

~# iptables -L

modprobe: FATAL: Module ip_tables not found in directory /lib/modules/6.18.10-current-meson64
iptables v1.8.11 (legacy): can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
```

As I run a docker version 28.X.X, it does not support nftable. (Cannot upgrade at the moment).

What can I do to solve the problem ?

 

Thanks
 

Edited by Jeedom Cassivet

  • Author

Thanks for your answer.

 

I very sorry to ask you one more things please. How can I check if module is present. In modules files in "/lib/modules/6.18.10-current-meson64" ?

 

I tried to do this : 

# cd /lib/modules/6.18.10-current-meson64
# grep -r "iptables" . 

Answer 

grep: ./net/ipv4/netfilter/ipt_rpfilter.ko : fichiers binaires correspondent
grep: ./net/bridge/br_netfilter.ko : fichiers binaires correspondent


I not an expert

PS : I'am on  Minimal / IOT version. Maybe it's the reason ?

Thanks

Edited by Jeedom Cassivet

  • Author

Hi,

Here what I do

 

1°)  Flash the minimal - IOT image (trixie) for Odroid N2+ on my EMMc
2°) setup Root password and user
3°) Set up locale
4°) use armbian-config to switch on kernel 6.19.0
5°) Reboot - After Reboot I can see this : 

v26.2.1 for Odroid N2 running Armbian Linux 6.19.0-edge-meson64


6°) use armbian-config to add linux header

7°) reboot

8°) use these commands:
 

# grep -r "iptables" /lib/modules/.

grep: /lib/modules/./6.19.0-edge-meson64/kernel/net/ipv4/netfilter/ipt_rpfilter.ko : fichiers binaires correspondent
grep: /lib/modules/./6.19.0-edge-meson64/kernel/net/bridge/br_netfilter.ko : fichiers binaires correspondent

# grep -r "ip_tables" /lib/modules/.
-- nothing

# find /lib/modules/ -name ip*
lot of filkes but no ip_tables.ko


9°) use armbian-upgrade
10°) reboot
11°) retry commands grep et find: same result
12°) Try to launch 

# iptables -L
command not found

13°) Install iptables 

# apt install -y iptables
# iptables -v
iptables v1.8.11 (nftables): no command specified

# iptables -L
Chain INPUT (policy ACCEPT)
target     prot opt source               destination

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

# update-alternatives --set iptables /usr/sbin/iptables-legacy
update-alternatives: utilisation de « /usr/sbin/iptables-legacy » pour fournir « /usr/sbin/iptables » (iptables) en mode manuel

# update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy
update-alternatives: utilisation de « /usr/sbin/ip6tables-legacy » pour fournir « /usr/sbin/ip6tables » (ip6tables) en mode manuel

# iptables -L
modprobe: FATAL: Module ip_tables not found in directory /lib/modules/6.19.0-edge-meson64
iptables v1.8.11 (legacy): can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.

 

14°) Reboot

15°) Try 

# iptables -L
modprobe: FATAL: Module ip_tables not found in directory /lib/modules/6.19.0-edge-meson64
iptables v1.8.11 (legacy): can't initialize iptables table `filter': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.

 

Do I made something wrong ?

Thanks 
 

6 hours ago, Jeedom Cassivet said:
# update-alternatives --set iptables /usr/sbin/iptables-legacy

Why you do this (on a normal modern Trixie kernel, actually even 1 year newer)?

 

This is what I have (runs rockchip64 7.0-rc3 kernel):

root@ranc:~# ls -al /sbin/iptables /etc/alternatives/iptables
lrwxrwxrwx 1 root root 22 Nov  1  2023 /etc/alternatives/iptables -> /usr/sbin/iptables-nft
lrwxrwxrwx 1 root root 26 Jan 16  2023 /sbin/iptables -> /etc/alternatives/iptables

On other Aarch64 computer, it dates back to 2019 already, that is a standard Debian installation, always in-place upgraded since Buster or so. The Linux kernel does things natively as NetFilter, the iptables commands are mapped. Legacy is even older and I guess the old kernel API has been removed. But do research yourself if you want to know, at least 'man iptables-legacy'

Also:

# apt install -y iptables
# iptables -v
iptables v1.8.11 (nftables): no command specified
Quote

nftables is the default and recommended firewalling framework in Debian, and it replaces the old iptables (and related) tools.

https://wiki.debian.org/nftables

 

AFAIK using iptables syntax should still work, but nft is what you probably should learn to use instead.

 

https://wiki.nftables.org/wiki-nftables/index.php/Moving_from_iptables_to_nftables

Edited by bedna

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.