!
sudo iptables -t nat -N ssl_https
sudo iptables -t nat -N unfiltered_web
sudo iptables -t nat -N filtered_web
**********************************************************************
Firstly we need to allow HTTPS Traffic to the Internet :
Allow Subnet HTTPS Traffic to jump to Chain ssl_https :
sudo iptables -t nat -I PREROUTING 1 -s 10.10.0.0/16 -p tcp -m tcp –dport 443 -j ssl_https
sudo iptables -t nat -I ssl_https 1 -p tcp -m tcp –dport 443 -j ACCEPT
!
Secondly need to Create a FORWARD Chain Rule in order to allow HTTPS Traffic as this is the
second chain down the line that gets Inspected :
!
Lets create a new Chain :
sudo iptables -N ssl-https
!
Allow HTTPS Traffic to jump to Chain ssl-https
sudo iptables -I FORWARD 1 -p tcp -m tcp –dport 443 -jssl-https :
!
Allow HTTPS Traffic to ACCEPT :
sudo iptables -I ssl-https 1 -p tcp -m tcp –dport 443 -j ACCEPT
!
Thirdly Allow HTTPS Traffic to SNAT to Public Assigned Address for local break-out ” 88.834.85.88″ :
sudo iptables -t nat -I internet_web 1 -o eth0 -p tcp -m tcp –dport 443 -j SNAT –to 88.834.85.88
or
sudo iptables -t nat -I POSTROUTING 1 -o eth0 -s 10.200.0.5/32 -j MASQUERADE
sudo iptables -t nat -I POSTROUTING 1 -o eth0 -s 192.0.0.0/16 -j MASQUERADE
Action that should take place is to ‘masquerade‘ packets, i.e. replacing the sender’s address by the
router’s address for local break-out to the internet.
B00m… Complete….
**********************************************************************
to be bypass Content Filter, where this additional rule will be configured under unfiltered_web Chain.
!
Create Filtered and unfiltered nat Chains in order for PREROUTING Chain tojump to in order to
consolidate rules more profoundly :
!
sudo iptables -t nat -I PREROUTING 2 -s 10.10.0.0/16 -p tcp -m tcp –dport 80 -j unfiltered_web
!
sudo iptables -t nat -I unfiltered_web 1 -d “public-ip” -p tcp -m tcp –dport 80 -j ACCEPT
!
sudo iptables -t nat -I unfiltered_web 2 -p tcp -m tcp –dport 80 -j filtered_web
!
This is where HTTPS Traffic gets Redirect to Content Filter.
Allow HTTP Traffic to Redirect to Port 8080 (Content Filter Listening Port)
sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080
or
sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j DNAT –to-destination 10.200.0.5:800
!
Now we need to have HTTP Traffic NaTTeD out for Local break out to the Internet in order for the
unfiltered_web chain :
!
sudo iptables -t nat -N internet_web
!
sudo iptables -t nat -I POSTROUTING 2 -o eth0 -p tcp -m tcp –dport 80 -j internet_web
sudo iptables -t nat -I internet_web 2 -o eth0 -p tcp -m tcp –dport 80 -j SNAT –to 88.8234.85.88
Comments
(There are currently no comments for this post.)