Hi, On Sat, Aug 15, 2026 at 04:20:58AM +0200, Alban Browaeys wrote:
sudo systemctl status ferm-early [sudo] Mot de passe de prahal : ● ferm-early.service - Early Firewall configuration with ferm Loaded: loaded (/usr/lib/systemd/system/ferm-early.service; enabled; preset: enabled) Active: active (exited) since Sat 2026-08-15 04:13:44 CEST; 2min 21s ago Invocation: 0a3fb74a9c0749fdbbd990231f0aed49 Docs: man:ferm(1) https://systemd.io/NETWORK_ONLINE/ Process: 2072 ExecStart=/usr/libexec/ferm/ferm-systemd activate_early (code=exited, status=0/SUCCESS) Main PID: 2072 (code=exited, status=0/SUCCESS) Mem peak: 10M CPU: 123msaoût 15 04:13:43 hermes ferm-systemd[2072]: Activating firewall rules: /usr/sbin/ferm /etc/ferm/ferm-early.conf août 15 04:13:44 hermes ferm-systemd[2072]: Early Firewall rules activated successfully prahal ~ sudo systemctl status ferm × ferm.service - Firewall configuration with ferm Loaded: loaded (/usr/lib/systemd/system/ferm.service; enabled; preset: enabled) Active: failed (Result: exit-code) since Sat 2026-08-15 04:13:52 CEST; 2min 16s ago Invocation: 8755fafd7aff4c03966f34de2b382782 Docs: man:ferm(1) Process: 2876 ExecStartPre=/usr/bin/touch /run/ferm/inhibit-early (code=exited, status=0/SUCCESS) Process: 2891 ExecStart=/usr/libexec/ferm/ferm-systemd activate (code=exited, status=1/FAILURE) Main PID: 2891 (code=exited, status=1/FAILURE) Mem peak: 9.3M CPU: 183ms août 15 04:13:52 hermes ferm-systemd[2891]: Activating firewall rules: /usr/sbin/ferm /etc/ferm/ferm.conf août 15 04:13:52 hermes ferm-systemd[2956]: iptables-restore v1.8.13 (nf_tables): Chain 'FORWARD-early' does not exist août 15 04:13:52 hermes ferm-systemd[2956]: Error occurred at line: 102 août 15 04:13:52 hermes ferm-systemd[2956]: Try `iptables-restore -h' or 'iptables-restore --help' for more information. août 15 04:13:52 hermes ferm-systemd[2903]: Failed to run /usr/sbin/iptables-restore août 15 04:13:52 hermes ferm-systemd[2903]: Firewall rules rolled back. prahal ~ 3 ls -l /etc/alternatives/iptables* lrwxrwxrwx 1 root root 22 15 août 03:49 /etc/alternatives/iptables -> /usr/sbin/iptables-nft lrwxrwxrwx 1 root root 30 15 août 03:49 /etc/alternatives/iptables-restore -> /usr/sbin/iptables-nft-restore lrwxrwxrwx 1 root root 27 15 août 03:49 /etc/alternatives/iptables-save -> /usr/sbin/iptables-nft-save prahal ~ ls -l /etc/alternatives/ip6tables* lrwxrwxrwx 1 root root 23 15 août 04:09 /etc/alternatives/ip6tables -> /usr/sbin/ip6tables-nft lrwxrwxrwx 1 root root 31 15 août 04:09 /etc/alternatives/ip6tables-restore -> /usr/sbin/ip6tables-nft-restore lrwxrwxrwx 1 root root 28 15 août 04:09 /etc/alternatives/ip6tables-save -> /usr/sbin/ip6tables-nft-save Note I don't have a vanilly Debian ferm setup but a debops one (ie /etc/ferm/ferm.conf is not Debian vanilla). But it seems unrelated to current issue.
Can you reproduce this with a Debian vanilla ferm.conf? If not, can you show the configuration that fails?
What is your /etc/alternatives/iptables* pointing to? Can you reproduce the issues by emptying out all tables and manually going through the same motions that the ferm-early and the ferm services do? Especially, what rules does ferm-early install?
Greetings Marc -- ----------------------------------------------------------------------------- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Leimen, Germany | lose things." Winona Ryder | Fon: *49 6224 1600402 Nordisch by Nature | How to make an American Quilt | Fax: *49 6224 1600421

