iptables: No chain/target/match 🐳 Docker

driver failed programming external connectivity on endpoint: iptables: No chain/target/match by that name

Docker’s iptables rules were wiped (firewalld/ufw reload, iptables flush) while Docker was running, so it can’t publish ports.

Seen on: Docker

Meaning

Docker creates DOCKER chains at startup. Restarting the firewall afterwards deletes them; the next container with -p fails. Restarting Docker recreates the chains.

Common causes

  • firewalld or ufw reloaded after Docker started
  • iptables -F run manually
  • nftables/iptables-legacy mismatch

⚡ Quick fix

  1. sudo systemctl restart docker
  2. Start the firewall before Docker
  3. Use the same iptables backend for both

Detailed fix by platform

Linux

  1. bash
    sudo systemctl restart docker
    sudo iptables -t nat -L DOCKER -n | head

How to diagnose

  1. Chains — iptables -t nat -L DOCKER
  2. Order — Was the firewall restarted after Docker?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.