Bug 143790 - ip6tables missing state module
ip6tables missing state module
Product: Red Hat Enterprise Linux 4
Classification: Red Hat
Component: rhel-sg (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Don Domingo
Thomas Woerner
: Documentation
Depends On:
  Show dependency treegraph
Reported: 2004-12-28 00:07 EST by Eric Moret
Modified: 2010-08-25 19:16 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-01-14 20:28:01 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Eric Moret 2004-12-28 00:07:55 EST
Description of problem:
State module missing for ip6tables

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. Configure ipv6
# cat >> /etc/sysconfig/network
# service network restart

2. Configure ip6tables
# ip6tables -A INPUT -s ::/0 -d ::/0 -p tcp -m tcp --dport 22 -j 

3. Use ip6tables state module
# ip6tables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT

Actual Results: 
ip6tables v1.2.8: Couldn't load match 
`state':/lib/iptables/libip6t_state.so: cannot open shared object 
file: No such file or directory

Try `ip6tables -h' or 'ip6tables --help' for more information.

Expected Results:  No error message

Additional info:

This is working on iptables (ipv4) but not on ip6tables contrary to 
Redhat's documentation: chapter "Firewalls", "IP6Tables".
Comment 1 Thomas Woerner 2005-03-18 11:25:07 EST
There is no state module for ipv6 in the kernel.
Comment 2 David Miller 2005-03-19 22:59:29 EST
Therefore, this is a documentation error.

The functionality simply doesn't exist, neither in kernel
nor in the iptables utilities.

Can someone reassign to the proper component for the referenced
Comment 3 Ernie Petrides 2005-03-29 16:44:03 EST
Hello, Eric.  I'm reassigning this bug to the "rhel-sag" component under
the assumption (er, make that, guess) that you're referring to the Red Hat
Administrator's Guide.  Could you please confirm the exact title of the
documentation containing the chapter and section you've listed above?

Thanks in advance.  -ernie
Comment 6 Eric Moret 2005-11-11 19:38:20 EST
A patch for this feature can be found at:


This patch is currently shipping in Suse 9.x
Comment 8 Eric Moret 2006-04-03 23:39:00 EDT
Actually see my last message this is not strictly documentation any more, as 
there is a patch. Why not applying the patch instead of fixing the 
Comment 11 Eric Moret 2006-10-17 20:07:45 EDT
Ping, this was apparently fixed in iptables-ipv6-1.3.5-1.2, can you close this bug?

Comment 12 David O'Brien 2006-10-17 20:27:06 EDT
No longer Doc-related. Set QA to Thomas as I think he owns ip6tables as well...
Please reassign if necessary. Documentation keyword removed
Comment 13 Matthew Booth 2006-12-03 16:37:01 EST
I can confirm that the state module is in iptables-ipv6-1.3.5-1.2.1 (FC6).
However, it's not documented in 'man ip6tables', so if I hadn't read to the very
end of this bug I wouldn't know that.

The man page needs to be updated before this can be closed.
Comment 14 David O'Brien 2006-12-03 21:51:35 EST
Reassigning since the content services group currently doesn't handle man pages.
Comment 15 Michael Hideo 2007-10-22 22:50:39 EDT
Removing automation notification

Note You need to log in before you can comment on or make changes to this bug.