Compared to 2.6.15-r5, new kernel sources are missing quite important iptables features: .config:315:warning: trying to assign nonexistent symbol IP_NF_MATCH_LIMIT .config:317:warning: trying to assign nonexistent symbol IP_NF_MATCH_MAC .config:318:warning: trying to assign nonexistent symbol IP_NF_MATCH_PKTTYPE .config:319:warning: trying to assign nonexistent symbol IP_NF_MATCH_MARK .config:326:warning: trying to assign nonexistent symbol IP_NF_MATCH_LENGTH .config:328:warning: trying to assign nonexistent symbol IP_NF_MATCH_TCPMSS .config:329:warning: trying to assign nonexistent symbol IP_NF_MATCH_HELPER .config:330:warning: trying to assign nonexistent symbol IP_NF_MATCH_STATE .config:331:warning: trying to assign nonexistent symbol IP_NF_MATCH_CONNTRACK .config:334:warning: trying to assign nonexistent symbol IP_NF_MATCH_REALM .config:335:warning: trying to assign nonexistent symbol IP_NF_MATCH_SCTP .config:336:warning: trying to assign nonexistent symbol IP_NF_MATCH_DCCP .config:337:warning: trying to assign nonexistent symbol IP_NF_MATCH_COMMENT .config:339:warning: trying to assign nonexistent symbol IP_NF_MATCH_STRING .config:345:warning: trying to assign nonexistent symbol IP_NF_TARGET_NFQUEUE .config:357:warning: trying to assign nonexistent symbol IP_NF_TARGET_MARK .config:358:warning: trying to assign nonexistent symbol IP_NF_TARGET_CLASSIFY Is this replaced by some other options?
Yes, xtables (s/CONFIG_IP_NF/CONFIG_NETFILTER_XT/) You should notice the new options when running "make oldconfig."