VRF SITES HTTP CONTENT FILTERED ON DANSGUARDIAN

Here is an additional firewall rule needs to be added in order for NO-NAT traffic from VRF sites
coming into the FIREWALL on the INPUT chain :

Quick Summary : This is the basic Firewall rule with Natted Traffic coming in and hitting the
PREROUTING Chain :

sudo iptables -t nat -I PREROUTING 1 -p tcp -m tcp –dport 80 -j unfiltered_web
!
sudo iptables -t nat -I unfiltered_web 2 -i eth0 -j filtered_web
!
sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080

 

Additional rule here for sites within the VRF coming into Firewall advertising their
Local Lan address & hitting the INPUT Chain :

sudo iptables -I INPUT 1 -s 172.16.0.0/16 -p tcp -m tcp –dport 80 -j ACCEPT