Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Bypass Transparent HTTPS Proxy

    Scheduled Pinned Locked Moved Cache/Proxy
    14 Posts 7 Posters 4.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      chris4916
      last edited by

      If you do not configure MITM, when configuring transparent proxy, then HTTP flow will go thorough proxy while HTTPS will not.
      Does it fit your expectation?

      Jah Olela Wembo: Les mots se muent en maux quand ils indisposent, agressent ou blessent.

      1 Reply Last reply Reply Quote 0
      • L
        lockye
        last edited by

        No, I want MITM to work for everything else, I just don't want it to intercept the Roku Boxes.  I have to use transparent proxy otherwise the Roku boxes can not go through the proxy as there are no proxy setting menu on them.

        1 Reply Last reply Reply Quote 0
        • C
          chris4916
          last edited by

          Thus you will have to manually update the prerouting rules but then I wonder how this would be kept in case you perform any other modification through GUI  ???

          Jah Olela Wembo: Les mots se muent en maux quand ils indisposent, agressent ou blessent.

          1 Reply Last reply Reply Quote 0
          • L
            lockye
            last edited by

            And that is were I hit a brick wall.

            I have tried various configurations but I have not had any luck getting it to work.

            1 Reply Last reply Reply Quote 0
            • L
              lockye
              last edited by

              Anyone?

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                I don't think you can carve it up like that.  Ditch the transparent proxy for explicit and your life will be much easier in this regard.

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  It's dead simple: stop setting up transparent proxy on interfaces where you do NOT want transparent proxy. IOW - stick those boxes on another separate interface.

                  1 Reply Last reply Reply Quote 0
                  • L
                    lockye
                    last edited by

                    The reason I use the transparent proxy is because I have content filtering setup, it blocks all the annoying commercials even on the roku.

                    1 Reply Last reply Reply Quote 0
                    • A
                      agixdota
                      last edited by

                      same problem, but I can't solved this problem.  ;D

                      1 Reply Last reply Reply Quote 0
                      • N
                        Netizen1
                        last edited by

                        @doktornotor:

                        It's dead simple: stop setting up transparent proxy on interfaces where you do NOT want transparent proxy. IOW - stick those boxes on another separate interface.

                        Stop using transparent proxy…

                        1 Reply Last reply Reply Quote 0
                        • G
                          gaf2014
                          last edited by

                          @lockye:

                          The reason I use the transparent proxy is because I have content filtering setup, it blocks all the annoying commercials even on the roku.

                          Hi lockye,

                          have you ever tried to use a NAT rule in your inbound Interface?
                          For me it's working. All devices that don't like SSL interception are in the Group "grp_no_https_interception". That's all.
                          You also need to have a firewall rule in place to allow the traffic.

                          NAT.jpg
                          NAT.jpg_thumb

                          1 Reply Last reply Reply Quote 0
                          • L
                            lockye
                            last edited by

                            THANKYOU

                            I had tried something similar but could not get it to work, I must have been missing something.

                            I followed your directions and it does what I need it to do. Thanks for including the attachment, very helpful.

                            Thanks again

                            1 Reply Last reply Reply Quote 0
                            • A
                              agixdota
                              last edited by

                              @gaf2014:

                              @lockye:

                              The reason I use the transparent proxy is because I have content filtering setup, it blocks all the annoying commercials even on the roku.

                              Hi lockye,

                              have you ever tried to use a NAT rule in your inbound Interface?
                              For me it's working. All devices that don't like SSL interception are in the Group "grp_no_https_interception". That's all.
                              You also need to have a firewall rule in place to allow the traffic.

                              hello, can you give rule firewall rule to allow the traffic  ;D (im try make firewall rule same as nat forward but cant bypass https connection)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.