Create New -t nat Chain :
!
sudo iptables -t nat -N ssl_https
sudo iptables -t nat -N unfiltered_web
sudo iptables -t nat -N filtered_web
**********************************************************************

Firstly we need to allow HTTPS Traffic to the Internet :
Allow Subnet HTTPS Traffic to jump to Chain ssl_https :

sudo iptables -t nat -I PREROUTING 1 -s 10.10.0.0/16 -p tcp -m tcp –dport 443 -j ssl_https
Allow HTTPS Traffic to Accept :

sudo iptables -t nat -I ssl_https 1 -p tcp -m tcp –dport 443 -j ACCEPT
!

Secondly need to Create a FORWARD Chain Rule in order to allow HTTPS Traffic as this is the
second chain down the line that gets Inspected
:
!

Lets create a new Chain :

sudo iptables -N ssl-https
!
Allow HTTPS Traffic to jump to Chain ssl-https
sudo iptables -I FORWARD 1 -p tcp -m tcp –dport 443 -jssl-https :
!

Allow HTTPS Traffic to ACCEPT :
sudo iptables -I
ssl-https 1 -p tcp -m tcp –dport 443 -j ACCEPT
!

Thirdly Allow  HTTPS Traffic to SNAT to Public Assigned Address for local break-out ” 88.834.85.88″ :

sudo iptables -t nat -I internet_web 1 -o eth0 -p tcp -m tcp –dport 443  -j SNAT –to 88.834.85.88

or

sudo iptables -t nat -I POSTROUTING 1 -o eth0 -s 10.200.0.5/32 -j MASQUERADE
sudo iptables -t nat -I POSTROUTING 1 -o eth0 -s 192.0.0.0/16 -j MASQUERADE

Action that should take place is to ‘masquerade‘ packets, i.e. replacing the sender’s address by the
router’s address for local break-out to the internet.

B00m… Complete….
**********************************************************************

Another Scenerio : Allow HTTP Traffic to be Filtered by Content Filter also allow certain ip addresses
to be bypass Content Filter, where this additional rule will be configured under unfiltered_web Chain.
!

Create Filtered and unfiltered nat Chains in order for PREROUTING Chain tojump to in order to
consolidate rules more profoundly
:
!
Allow Subnet HTTP Traffic to jump to Chain unfiltered_web :
sudo iptables -t nat -I PREROUTING 2 -s 10.10.0.0/16 -p tcp -m tcp –dport 80 -j unfiltered_web
!
Allow HTTP Traffic to bypass Content Filter :
sudo iptables -t nat -I unfiltered_web 1 -d “public-ip” -p tcp -m tcp –dport 80 -j ACCEPT
!
Allow Filtered HTTP Traffic to jump to Chain filtered_web :
sudo iptables -t nat -I unfiltered_web 2 -p tcp -m tcp –dport 80 -j filtered_web
!

This is where HTTPS Traffic gets Redirect to Content Filter.
Allow HTTP Traffic to Redirect to Port 8080 (Content Filter Listening Port)

sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080
or
sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j DNAT –to-destination 10.200.0.5:800
!


Now we need to have HTTP Traffic NaTTeD out for Local break out to the Internet in order for the
unfiltered_web chain
:
This is Configured in the POSTROUTING Chain.
!
Lets Create a new Chain Internet_web in order to organise chains more profoundly.

sudo iptables -t nat -N internet_web
!
Allow HTTP & HTTPS Traffic NaTTeD to jump to Chain previously created “internet_web”
sudo iptables -t nat -I POSTROUTING 2 -o eth0 -p tcp -m tcp –dport 80 -j internet_web
!
Allow HTTP & HTTPS Traffic to SNAT to Public Assigned Address for local break-out ” 88.834.85.88″ :
sudo iptables -t nat -I internet_web 2 -o eth0 -p tcp -m tcp –dport 80  -j SNAT –to 88.8234.85.88
B00m…