driver failed programming external connectivity on endpoint: iptables: No chain/target/match by that name
Docker’s iptables rules were wiped (firewalld/ufw reload, iptables flush) while Docker was running, so it can’t publish ports.
Seen on:
Docker
Meaning
Docker creates DOCKER chains at startup. Restarting the firewall afterwards deletes them; the next container with -p fails. Restarting Docker recreates the chains.
Common causes
- firewalld or ufw reloaded after Docker started
- iptables -F run manually
- nftables/iptables-legacy mismatch
⚡ Quick fix
- sudo systemctl restart docker
- Start the firewall before Docker
- Use the same iptables backend for both
Detailed fix by platform
Linux
- bash
sudo systemctl restart docker sudo iptables -t nat -L DOCKER -n | head
How to diagnose
- Chains — iptables -t nat -L DOCKER
- Order — Was the firewall restarted after Docker?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Docker
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026