Allows Incoming HTTP requests on Port Tcp 80 to jump to the unfiltered_web chain :
sudo iptables -I PREROUTING -p tcp -m tcp –dport 80 -j unfiltered_web

Allows HTTP traffic to permit port 80 traffic or to jump to filtered_web chain :
sudo iptables -A unfiltered_web -s 80.74.22.132 -j ACCEPT
sudo iptables -A unfiltered_web -j filtered_web

Allows HTTP traffic on filtered_web chain to get redirected to the content filter server
listening on tcp port 8080
:

sudo iptables -A filtered_web -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080

show commands :

sudo iptables -t nat -vnL unfiltered_web –line-numbers

Scenerio :

This server has SSL enabled. Server ip address 10.10.1.91
Dansguardian content filter only filters http port 80 traffic.

In order to allow an internal vpn subnet / host address to access web server
on port 80.

We need to complete the following below :

Configure Port forward :

iptables -t nat -I PREROUTING -d 1.1.1.1 -p tcp -m multiport –dports 80,443 -j DNAT –to-destination 10.10.1.91

Configure rule to allow subnet 172.17.1.1/24 to webserver within the vpn on port 80

iptables -t nat -I unfiltered_web 1 -s 172.17.1.0/24 -d 10.10.1.91 -m tcp -p tcp –dport 80 -j ACCEPT

Complete…

This rule allows all http port 80 traffic to be redirected to proxy port 8080 destined
to the dansguardian content filter on 172.16.150.248.

All http traffic will get redirect to the content filter server listening on tcp port 8080

iptables -I filtered_web -p tcp -m tcp —dport 80 -j DNAT –to-destination 172.16.150.248:8080


Quick Summary :

sudo iptables -t nat -I PREROUTING 1 -i eth 0 – 10.10.0.0/16 -p tcp -m tcp –dport 80 -j unfiltered_web
!
sudo iptables -t nat -I unfiltered_web 1 -i eth0 -s 10.10.34.12/32 -j ACCEPT
sudo iptables -t nat -I unfiltered_web 2 -i eth0 -j filtered_web
!

sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080