Push traffic to Proxy Filter Dansguardian :
PREROUTING Chain :
this will have all traffic destined for port tcp 80 to jump to unfiltered_web chain.
iptables -I PREROUTING -p tcp -m tcp –dport 80 -j unfiltered_web
unfiltered_web chain entry :
iptables -I unfiltered_web -d 83.166.168.43 -p tcp -m tcp –dport 80 -j ACCEPT
iptables -I unfiltered_web -d 212.41.178.44 -p tcp -m tcp –dport 80 -j ACCEPT
iptables -I unfiltered_web -s 172.16.2.49 -p tcp -m tcp –dport 80 -j ACCEPT
Once unfiltered traffic to bypass proxy dansguardian using unfiltered_web chain as above,
the last entry is to poing it back to filtered_web chain, in order to have other ip addresses or
subnets HTTP traffic filtered using the filtered_web chain . to have proxy filter HTTP traffic :
This will cause unfiltered_web to jump to filtered_web chain
iptables -I unfiltered_web-j filtered_web
filtered_web chain entry :
This will cause filtered_web chain to push all HTTP traffic to dansguardian proxy server
on 172.16.150.248 on tcp port 8080.
Tcp 80 will be DNAT to tcp port 8080 to destination address of 172.16.150.248.
iptables -I filtered_web -p tcp -m tcp –dport 80 -j DNAT –to-destination 172.16.150.248:8080
In Brief Summary :
iptables -I PREROUTING -p tcp -m tcp –dport 80 -j unfiltered_web
!
iptables -I unfiltered_web -j filtered_web
(Make changes in this chain for unfiltered traffic as seen above)
!
iptables -I filtered_web -p tcp -m tcp –dport 80 -j DNAT –to-destination 172.16.150.248:8080
Additional Notes :
For HTTP external sites that need to bypass proxy due to HTTPS authentication,
These are the changes that need to be made within iptables :
sudo iptables -t nat -I PREROUTING -s 172.16.0.0/16 -d 83.166.168.51/32 -p tcp -m tcp –dport 443 -j ACCEPT
!
sudo iptables -I FORWARD 18 -s 172.16.0.0/16 -d 83.166.168.51/32 -p tcp -m tcp –dport 443 -j ACCEPT
Quick Summary :
sudo iptables -t nat -I PREROUTING 1 -i eth 0 -s 10.10.0.0/16 -p tcp -m tcp –dport 80 -j unfiltered_web
!
sudo iptables -t nat -I unfiltered_web 1 -i eth0 -s 10.10.34.12/32 -j ACCEPT
sudo iptables -t nat -I unfiltered_web 2 -i eth0 -j filtered_web
!
sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080
Comments
(There are currently no comments for this post.)