Please enable DEBUG_IP_FIREWALL_USER in net/netfilter/x_tables.c as well and retry. Results of the raw or mangle table would also be interesting because they contain a different number of built-in chains.
Sorry it took so long, I was away. Adding this define does not seem to do much (table->private->number prints only):
On boot (1 nat rule): ip_tables: (C) 2000-2006 Netfilter Core Team Netfilter messages via NETLINK v0.30. ip_conntrack version 2.4 (1536 buckets, 12288 max) - 224 bytes per conntrack translate_table: size 632 Finished chain 0 Finished chain 3 Finished chain 4 table->private->number = 4 t->private->number = 4 translate_table: size 800 Bad offset cba528d4 modprobe iptable_nat succeeded in manual modprobe. modprobe iptable_filter: translate_table: size 632 Bad offset cbbd910c modprobe iptable_mangle: translate_table: size 936 Bad offset cbbd80dc modprobe iptable_raw: translate_table: size 480 Bad offset cb8abd44 Retrying ifup and ifdown that tried to do iptables -D and iptables -I: t->private->number = 4 t->private->number = 4 t->private->number = 4 translate_table: size 800 Bad offset cbbd80dc t->private->number = 4 And retrying it more (succeeded this time): t->private->number = 4 t->private->number = 4 translate_table: size 800 Finished chain 0 Finished chain 3 Finished chain 4 ip_tables: Translated table do_replace: oldnum=4, initnum=4, newnum=5 t->private->number = 5 -- Meelis Roos ([EMAIL PROTECTED]) - To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://vger.kernel.org/majordomo-info.html