{"id":1427,"date":"2011-02-03T13:08:01","date_gmt":"2011-02-03T13:08:01","guid":{"rendered":"http:\/\/wiki.freeiz.com\/?p=1427"},"modified":"2016-08-09T12:06:32","modified_gmt":"2016-08-09T12:06:32","slug":"linux-danaguardian-proxy-iptables","status":"publish","type":"post","link":"https:\/\/wiki-see.info\/wp\/2011\/02\/03\/linux-danaguardian-proxy-iptables\/","title":{"rendered":"Linux Danaguardian Proxy Iptables"},"content":{"rendered":"<p><span style=\"color: #000000;\"><strong><span style=\"color: #800000;\">Push traffic to Proxy Filter Dansguardian<\/span><\/strong> :<\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"color: #000080;\">PREROUTING Chain<\/span> :<br \/>\n<em>this will have all traffic destined for port tcp 80 to jump to<strong> unfiltered_web<\/strong> chain<\/em>.<\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"color: #000080;\">iptables -I<\/span>\u00a0<span style=\"color: #800000;\">PREROUTING<\/span> <span style=\"color: #000080;\">-p tcp -m tcp &#8211;dport 80 -j<\/span> <span style=\"color: #800000;\">unfiltered_web<\/span><\/span><\/p>\n<p><span style=\"color: #000000;\"><strong><span style=\"color: #800000;\">unfiltered_web<\/span><\/strong> chain entry\u00a0:<\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"color: #000080;\">iptables -I<\/span>\u00a0<span style=\"color: #800000;\">unfiltered_web<\/span> <span style=\"color: #000080;\">-d 83.166.168.43 -p tcp -m tcp &#8211;dport 80 -j<\/span><span style=\"color: #800000;\"> ACCEPT<br \/>\n<\/span><span style=\"color: #000080;\">iptables -I<\/span>\u00a0<span style=\"color: #800000;\">unfiltered_web<\/span> <span style=\"color: #000080;\">-d 212.41.178.44 -p tcp -m tcp &#8211;dport 80 -j<\/span><span style=\"color: #800000;\"> ACCEPT<br \/>\n<\/span><span style=\"color: #000080;\">iptables -I<\/span>\u00a0<span style=\"color: #800000;\">unfiltered_web<\/span> <span style=\"color: #000080;\">-s 172.16.2.49 -p tcp -m tcp &#8211;dport 80 -j<\/span> <span style=\"color: #800000;\">ACCEPT<\/span><\/span><\/p>\n<p><span style=\"color: #000000;\"><em>Once unfiltered traffic to bypass proxy dansguardian using <strong><span style=\"color: #800000;\">unfiltered_web<\/span><\/strong> chain as above,<br \/>\nthe last entry is to poing it back to <strong><span style=\"color: #800000;\">filtered_web chain<\/span><\/strong>,\u00a0 in order to have other ip addresses or<br \/>\nsubnets\u00a0HTTP traffic filtered using the<strong> <span style=\"color: #800000;\">filtered_we<\/span><\/strong><span style=\"color: #800000;\">b<\/span> chain .<\/em> to have proxy filter HTTP traffic :<\/span><\/p>\n<p><span style=\"color: #000000;\">This will cause\u00a0<strong><span style=\"color: #800000;\">unfiltered_web<\/span><\/strong> to jump to <strong><span style=\"color: #800000;\">filtered_web<\/span><\/strong> chain<\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"color: #000080;\">iptables -I <\/span><span style=\"color: #800000;\">unfiltered_web<\/span><span style=\"color: #000080;\">-j<\/span><span style=\"color: #800000;\"> filtered_web<\/span><\/span><\/p>\n<p><span style=\"color: #000000;\"><em><strong><span style=\"color: #800000;\">filtered_web<\/span><\/strong> chain entry<\/em> :<\/span><\/p>\n<p><em><span style=\"color: #000000;\">This will cause<strong> <span style=\"color: #800000;\">filtered_web<\/span><\/strong> chain to push all HTTP traffic to <span style=\"color: #000080;\">dansguardian proxy server<\/span><br \/>\non <strong>172.16.150.248<\/strong> on tcp port <strong>8080.<\/strong><\/span><\/em><\/p>\n<p><span style=\"color: #000000;\">Tcp 80 will be <span style=\"color: #000080;\">DNAT<\/span> to\u00a0tcp port 8080\u00a0to destination address of <span style=\"color: #000080;\">172.16.150.248<\/span>.<\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"color: #000080;\">iptables -I<\/span>\u00a0<span style=\"color: #800000;\">filtered_web<\/span><span style=\"color: #000080;\"> -p tcp -m tcp &#8211;dport 80 -j<\/span> <span style=\"color: #800000;\">DNAT<\/span> <span style=\"color: #000080;\">&#8211;to-destination<\/span> <span style=\"color: #800000;\">172.16.150.248:8080<\/span><\/span><\/p>\n<p><span style=\"color: #000000;\"><strong><span style=\"color: #800000;\">In Brief Summary<\/span><\/strong> :<\/span><\/p>\n<p><span style=\"color: #000000;\">iptables -I\u00a0<span style=\"color: #800000;\">PREROUTING<\/span> -p tcp -m tcp &#8211;dport 80 -j <span style=\"color: #800000;\">unfiltered_web<\/span><br \/>\n<span style=\"color: #000080;\">!<\/span><br \/>\n<span style=\"color: #000080;\"> iptables -I<\/span> <span style=\"color: #800000;\">unfiltered_web<\/span><\/span><span style=\"color: #000000;\"> -j<\/span><span style=\"color: #000080;\"> filtered_web<\/span><span style=\"color: #000000;\"><br \/>\n<\/span><span style=\"color: #000000;\">(<em><strong>Make changes in this chain for unfiltered traffic as seen above<\/strong><\/em>)<\/span><span style=\"color: #000000;\"><br \/>\n<\/span><span style=\"color: #000000;\">!<br \/>\niptables -I\u00a0<\/span><span style=\"color: #000000;\"><span style=\"color: #800000;\">filtered_web<\/span><\/span><span style=\"color: #000000;\"> -p tcp -m tcp &#8211;dport 80 -j<\/span><span style=\"color: #000000;\"> <span style=\"color: #800000;\">DNAT<\/span><\/span><span style=\"color: #000000;\"> &#8211;to-destination<\/span><span style=\"color: #000000;\"> <span style=\"color: #800000;\">172.16.150.248:8080<\/span><\/span><\/p>\n<p><span style=\"color: #000000;\"><strong><span style=\"color: #000080;\">Additional Notes<\/span><\/strong> :<\/span><\/p>\n<p><span style=\"color: #000000;\">For<\/span><strong> <\/strong><span style=\"color: #000000;\"><strong><span style=\"color: #800000;\">HTTP<\/span><\/strong><\/span> <span style=\"color: #000000;\">external sites that need to bypass proxy due to<\/span><span style=\"color: #000000;\"> <strong><span style=\"color: #800000;\">HTTPS authentication<\/span><\/strong>,<br \/>\n<\/span><span style=\"color: #000000;\">These are the changes that need to be made within iptables :<\/span><\/p>\n<p><span style=\"color: #000000;\">sudo iptables -t nat -I<\/span><span style=\"color: #000000;\"> <span style=\"color: #800000;\">PREROUTING<\/span><\/span> <span style=\"color: #000000;\">-s 172.16.0.0\/16 -d 83.166.168.51\/32 -p tcp -m tcp &#8211;dport 443 -j ACCEPT<br \/>\n!<\/span><br \/>\n<span style=\"color: #000000;\">sudo iptables -I<\/span><span style=\"color: #000000;\"> <span style=\"color: #800000;\">FORWARD<\/span><\/span><span style=\"color: #000000;\"> 1<\/span><span style=\"color: #000000;\">8 -s 172.16.0.0\/16 -d 83.166.168.51\/32 -p tcp -m tcp &#8211;dport 443 -j ACCEPT<\/span><\/p>\n<p><span style=\"color: #800000;\">Quick Summary<\/span> <span style=\"color: #000000;\">:<\/span><\/p>\n<p><span style=\"color: #000000;\">sudo iptables -t nat -I<\/span> <span style=\"color: #800000;\">PREROUTING<\/span>\u00a0<span style=\"color: #000000;\">1 -i eth 0 -s 10.10.0.0\/16 -p tcp -m tcp &#8211;dport 80 -j<\/span><span style=\"color: #000080;\"> unfiltered_web<br \/>\n<\/span><span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">sudo iptables -t nat -I<\/span> <span style=\"color: #800000;\">unfiltered_web <\/span><span style=\"color: #000000;\">1 -i eth0 -s 10.10.34.12\/32 -j<\/span> <span style=\"color: #000080;\">ACCEPT<br \/>\n<\/span><span style=\"color: #000000;\">sudo iptables -t nat -I<\/span> <span style=\"color: #800000;\">unfiltered_web<\/span> <span style=\"color: #000000;\">2 -i eth0\u00a0-j<\/span><span style=\"color: #000080;\"> filtered_web<br \/>\n<\/span><span style=\"color: #000000;\">!<\/span><br \/>\n<span style=\"color: #000000;\">s<\/span><span style=\"color: #000000;\">udo iptables -t nat -I<\/span><span style=\"color: #800000;\"> filtered_web <\/span><span style=\"color: #000000;\">1 -i eth0 -p tcp -m tcp &#8211;dport 80 -j<\/span> <span style=\"color: #993366;\">REDIRECT<\/span> <span style=\"color: #000000;\">&#8211;to-ports 8080<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Push traffic to Proxy Filter Dansguardian : PREROUTING Chain : this will have all traffic destined for port tcp 80 to jump to unfiltered_web chain. iptables -I\u00a0PREROUTING -p tcp -m tcp &#8211;dport 80 -j unfiltered_web unfiltered_web chain entry\u00a0: iptables -I\u00a0unfiltered_web -d 83.166.168.43 -p tcp -m tcp &#8211;dport 80 -j ACCEPT iptables -I\u00a0unfiltered_web -d 212.41.178.44 -p [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18,8],"tags":[230,567],"class_list":["post-1427","post","type-post","status-publish","format-standard","hentry","category-iptables-linux","category-linux","tag-dansguardian","tag-proxy-iptables"],"_links":{"self":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/comments?post=1427"}],"version-history":[{"count":1,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1427\/revisions"}],"predecessor-version":[{"id":4900,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1427\/revisions\/4900"}],"wp:attachment":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/media?parent=1427"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/categories?post=1427"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/tags?post=1427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}