Creating iptables filter rules applicable to both FORWARD and OUTPUT chains

view full story

http://www.unix.com – Hi all, I have a script which permits users to access to a large list of IP ranges. Before, access to these ranges was granted by using a shell script to perform the necessary FORWARD chain command to allow traffic coming from the br0 interface and exiting the WAN interface, since br0 was the only interface which would access these ranges. Code: iptables -I FORWARD 6 -i br0 -d $CIDR -o $WAN_IFACE -j ACCEPT However I have now implemented a caching proxy on the local gateway, and so I need to permit access to the IP ranges on the OUTPUT chain. Code: iptables -I OUTPUT 8 -d $CI (HowTos)