在 Debian 上执行 iptables 命令报错,常见原因和对应现象如下,你可以对照看是哪一种:
Debian 10+ 默认使用 nftables,传统 iptables 实际是 iptables-nft 的兼容层。
常见报错:
iptables: No chain/target/match by that name
或
Failed to initialize nft: Protocol not supported
原因
iptables-legacy 和 nft解决
# 查看当前使用的 iptables 后端
update-alternatives --list iptables
# 切换到 legacy(老式 iptables)
sudo update-alternatives --set iptables /usr/sbin/iptables-legacy
sudo update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy
报错:
command not found: iptables
解决
sudo apt update
sudo apt install iptables
报错:
Permission denied (you must be root)
解决
sudo iptables -L
现象
can't initialize iptables table `filter'
解决
--privileged报错:
iptables: Table does not exist (do you need to insmod?)
解决
sudo modprobe ip_tables
sudo modprobe nf_conntrack
建议:
nftiptables-legacy如果你能贴出完整报错信息,我可以直接告诉你具体是哪一类问题。