On Thu, Aug 26, 2004 at 06:54:21PM -0400, Jason Opperisano wrote: > yup--most distros do not compile the string match (i *think* suse > does). try: > > ls /lib/modules/`uname -r`/kernel/net/ipv4/netfilter/ipt_string.o > > and make sure you have the actual module. if not, grab p-o-m and > follow the instructions: > > http://www.netfilter.org/documentation/HOWTO/netfilter-extensions-HOWTO.html Yes, I thought that was the case, not seeing "string" anywhere in /lib/modules... sorry, I should have said that I'd looked. I'm not sure about upgrading netfilter on a distribution like Debian, apt-get trundles along nicely, I'm kind of loathe to play. Is anyone else here using a more recent version of netfilter on Debian? -- mors omnia vincit