IPTABLES comment: No chain/target/match by that name












0















Faced with error when adding new rule with 'comment':



# iptables -I INPUT 1 --source 66.***.***.78 -j REJECT -m comment --comment "Some"
iptables: No chain/target/match by that name.


Without comment - works normally.



Using CentOS 6.5, kernel 2.6.32



But same command works on other box, with same OS.



Both have same modules:



# cat /proc/net/ip_tables_matches
icmp
state
udplite
udp
tcp

# lsmod | grep ip
nf_conntrack_ipv4 9506 8
nf_defrag_ipv4 1483 1 nf_conntrack_ipv4
iptable_filter 2793 1
ip_tables 17831 1 iptable_filter
ipt_LOG 5845 0
ipt_REJECT 2351 5
ip6t_REJECT 4628 2
nf_conntrack_ipv6 8337 2
nf_defrag_ipv6 11156 1 nf_conntrack_ipv6
nf_conntrack 79758 3 nf_conntrack_ipv4,nf_conntrack_ipv6,xt_state
ip6table_filter 2889 1
ip6_tables 18732 1 ip6table_filter
ipv6 318183 17 ip6t_REJECT,nf_conntrack_ipv6,nf_defrag_ipv6









share|improve this question

























  • Shouldn't the /proc/net/ip_tables_matches file have 'comment' as one of its lines?

    – Sree
    Oct 17 '14 at 5:47











  • @Sree I also thought about this, but - on second box there is no such line too, but same command works...

    – setevoy
    Oct 17 '14 at 5:52
















0















Faced with error when adding new rule with 'comment':



# iptables -I INPUT 1 --source 66.***.***.78 -j REJECT -m comment --comment "Some"
iptables: No chain/target/match by that name.


Without comment - works normally.



Using CentOS 6.5, kernel 2.6.32



But same command works on other box, with same OS.



Both have same modules:



# cat /proc/net/ip_tables_matches
icmp
state
udplite
udp
tcp

# lsmod | grep ip
nf_conntrack_ipv4 9506 8
nf_defrag_ipv4 1483 1 nf_conntrack_ipv4
iptable_filter 2793 1
ip_tables 17831 1 iptable_filter
ipt_LOG 5845 0
ipt_REJECT 2351 5
ip6t_REJECT 4628 2
nf_conntrack_ipv6 8337 2
nf_defrag_ipv6 11156 1 nf_conntrack_ipv6
nf_conntrack 79758 3 nf_conntrack_ipv4,nf_conntrack_ipv6,xt_state
ip6table_filter 2889 1
ip6_tables 18732 1 ip6table_filter
ipv6 318183 17 ip6t_REJECT,nf_conntrack_ipv6,nf_defrag_ipv6









share|improve this question

























  • Shouldn't the /proc/net/ip_tables_matches file have 'comment' as one of its lines?

    – Sree
    Oct 17 '14 at 5:47











  • @Sree I also thought about this, but - on second box there is no such line too, but same command works...

    – setevoy
    Oct 17 '14 at 5:52














0












0








0








Faced with error when adding new rule with 'comment':



# iptables -I INPUT 1 --source 66.***.***.78 -j REJECT -m comment --comment "Some"
iptables: No chain/target/match by that name.


Without comment - works normally.



Using CentOS 6.5, kernel 2.6.32



But same command works on other box, with same OS.



Both have same modules:



# cat /proc/net/ip_tables_matches
icmp
state
udplite
udp
tcp

# lsmod | grep ip
nf_conntrack_ipv4 9506 8
nf_defrag_ipv4 1483 1 nf_conntrack_ipv4
iptable_filter 2793 1
ip_tables 17831 1 iptable_filter
ipt_LOG 5845 0
ipt_REJECT 2351 5
ip6t_REJECT 4628 2
nf_conntrack_ipv6 8337 2
nf_defrag_ipv6 11156 1 nf_conntrack_ipv6
nf_conntrack 79758 3 nf_conntrack_ipv4,nf_conntrack_ipv6,xt_state
ip6table_filter 2889 1
ip6_tables 18732 1 ip6table_filter
ipv6 318183 17 ip6t_REJECT,nf_conntrack_ipv6,nf_defrag_ipv6









share|improve this question
















Faced with error when adding new rule with 'comment':



# iptables -I INPUT 1 --source 66.***.***.78 -j REJECT -m comment --comment "Some"
iptables: No chain/target/match by that name.


Without comment - works normally.



Using CentOS 6.5, kernel 2.6.32



But same command works on other box, with same OS.



Both have same modules:



# cat /proc/net/ip_tables_matches
icmp
state
udplite
udp
tcp

# lsmod | grep ip
nf_conntrack_ipv4 9506 8
nf_defrag_ipv4 1483 1 nf_conntrack_ipv4
iptable_filter 2793 1
ip_tables 17831 1 iptable_filter
ipt_LOG 5845 0
ipt_REJECT 2351 5
ip6t_REJECT 4628 2
nf_conntrack_ipv6 8337 2
nf_defrag_ipv6 11156 1 nf_conntrack_ipv6
nf_conntrack 79758 3 nf_conntrack_ipv4,nf_conntrack_ipv6,xt_state
ip6table_filter 2889 1
ip6_tables 18732 1 ip6table_filter
ipv6 318183 17 ip6t_REJECT,nf_conntrack_ipv6,nf_defrag_ipv6






centos kernel iptables






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Oct 31 '14 at 6:55









Anthon

60.8k17103166




60.8k17103166










asked Oct 17 '14 at 5:32









setevoysetevoy

5291824




5291824













  • Shouldn't the /proc/net/ip_tables_matches file have 'comment' as one of its lines?

    – Sree
    Oct 17 '14 at 5:47











  • @Sree I also thought about this, but - on second box there is no such line too, but same command works...

    – setevoy
    Oct 17 '14 at 5:52



















  • Shouldn't the /proc/net/ip_tables_matches file have 'comment' as one of its lines?

    – Sree
    Oct 17 '14 at 5:47











  • @Sree I also thought about this, but - on second box there is no such line too, but same command works...

    – setevoy
    Oct 17 '14 at 5:52

















Shouldn't the /proc/net/ip_tables_matches file have 'comment' as one of its lines?

– Sree
Oct 17 '14 at 5:47





Shouldn't the /proc/net/ip_tables_matches file have 'comment' as one of its lines?

– Sree
Oct 17 '14 at 5:47













@Sree I also thought about this, but - on second box there is no such line too, but same command works...

– setevoy
Oct 17 '14 at 5:52





@Sree I also thought about this, but - on second box there is no such line too, but same command works...

– setevoy
Oct 17 '14 at 5:52










1 Answer
1






active

oldest

votes


















0














check whether the system has ip assigned on the port that you are configuring.
easy way is to remove the network configuration (ifcfg-eth*) file and configure newly so that the issue gets resolved.






share|improve this answer

























    Your Answer








    StackExchange.ready(function() {
    var channelOptions = {
    tags: "".split(" "),
    id: "106"
    };
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function() {
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled) {
    StackExchange.using("snippets", function() {
    createEditor();
    });
    }
    else {
    createEditor();
    }
    });

    function createEditor() {
    StackExchange.prepareEditor({
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: false,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: null,
    bindNavPrevention: true,
    postfix: "",
    imageUploader: {
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    },
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    });


    }
    });














    draft saved

    draft discarded


















    StackExchange.ready(
    function () {
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f162650%2fiptables-comment-no-chain-target-match-by-that-name%23new-answer', 'question_page');
    }
    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    check whether the system has ip assigned on the port that you are configuring.
    easy way is to remove the network configuration (ifcfg-eth*) file and configure newly so that the issue gets resolved.






    share|improve this answer






























      0














      check whether the system has ip assigned on the port that you are configuring.
      easy way is to remove the network configuration (ifcfg-eth*) file and configure newly so that the issue gets resolved.






      share|improve this answer




























        0












        0








        0







        check whether the system has ip assigned on the port that you are configuring.
        easy way is to remove the network configuration (ifcfg-eth*) file and configure newly so that the issue gets resolved.






        share|improve this answer















        check whether the system has ip assigned on the port that you are configuring.
        easy way is to remove the network configuration (ifcfg-eth*) file and configure newly so that the issue gets resolved.







        share|improve this answer














        share|improve this answer



        share|improve this answer








        edited Oct 31 '14 at 6:56









        Anthon

        60.8k17103166




        60.8k17103166










        answered Oct 31 '14 at 6:50









        sivakumarsivakumar

        1




        1






























            draft saved

            draft discarded




















































            Thanks for contributing an answer to Unix & Linux Stack Exchange!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid



            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.


            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function () {
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f162650%2fiptables-comment-no-chain-target-match-by-that-name%23new-answer', 'question_page');
            }
            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            How to make a Squid Proxy server?

            第一次世界大戦

            Touch on Surface Book