Something recent (perhaps this update to libnftnl) broke iptables. Re-emerging it fixed the problem.
Fri Feb 11 07:45:54 2022 >>> net-libs/libnftnl-1.2.1 iptables started giving errors such as this: /sbin/iptables -A BASE_INPUT_CHAIN -m conntrack --ctstate ESTABLISHED -j ACCEPT ERROR (2): iptables v1.8.7 (legacy): Couldn't load match `conntrack':No such file or directory Don't reboot (or restart the firewall on) any servers, in particular remote ones, before ensuring that your install of iptables is working. -- Alan J. Wylie https://www.wylie.me.uk/ Dance like no-one's watching. / Encrypt like everyone is. Security is inversely proportional to convenience