You need to allow inbound traffic on ports 80 (http) and 443 (https)
Something like this in your iptables config script:
Code:
/sbin/iptables -I INPUT -p tcp -m multiport --dports 80,443 -j ACCEPT -m comment --comment "Allow outbound http and https"
Then you might also need to allow the established connections to go back out:
Code:
/sbin/iptables -I OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
Note the -I flags are inserting the rules at the beginning of the rule chain. This is to make sure they will actually be applied before some other rejection rules kick in.
Now depending on your setup you may want to use the -A flag (append) and place the rules at a specific location in your overall config.
These are just examples that may open holes that are larger than you want them to be. If you post your current config and provide more input on what traffic you want to be blocked more detailed advice could be given...