Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SSL Man In the Middle Filtering blocking any app

    Scheduled Pinned Locked Moved Cache/Proxy
    17 Posts 6 Posters 5.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • reza3swR
      reza3sw
      last edited by

      Thanks but
      I set manualy proxy and port in android phone..but didn't work any app

      And define rule in NAT port forward
      80 and 443 redirect to pfsense lan address port 3128

      But not work any app

      یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

      نهج البلاغه

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Many believe that HTTPS MITM is an unsound practice if not immoral. Personally, I am one of them.

        When you click transparent proxy you automatically get a port forward on the squid interfaces that forwards all port 80 traffic to 3128.

        If you also check HTTPS you also get a port forward for port 443 traffic to port 3129.

        Those are the default ports.

        If you set the clients manually you do not need port forwards and should disable transparent mode.

        Everything you should need is here:

        https://www.youtube.com/watch?v=xm_wEezrWf4

        1 Reply Last reply Reply Quote 0
        • reza3swR
          reza3sw
          last edited by reza3sw

          Thanks for your good answer ... The things you said are true, but the problem with Internet access is that the smartphone apps are still up to date with MITM...
          But when I use MITM - splice all ...any app work correctly

          I also believe that https MITM is not applicable ... but where need control bandwidth through squid...

          یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

          نهج البلاغه

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Splice all is not MITM.

            1 Reply Last reply Reply Quote 0
            • reza3swR
              reza3sw
              last edited by

              ... I mean, in Man in the middle, enable the splice all option, the problem is resolved, but the monitoring on 443 is not complete.

              یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

              نهج البلاغه

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                This post is deleted!
                1 Reply Last reply Reply Quote 0
                • reza3swR
                  reza3sw
                  last edited by

                  I searched on other sites that are related to squid.
                  This problem has been reported by squid users but no solutions have been made

                  Has anyone had this problem? Has it resolved?

                  یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

                  نهج البلاغه

                  1 Reply Last reply Reply Quote 0
                  • R
                    reggie14
                    last edited by

                    Android apps, by default, don't trust roots installed by the user/admin. This security feature was added in Android N.

                    1 Reply Last reply Reply Quote 0
                    • reza3swR
                      reza3sw
                      last edited by

                      Thanks
                      There is no solution right now?

                      یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

                      نهج البلاغه

                      1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan
                        last edited by

                        The MITM "problem" will probably never get solved.

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 1
                        • reza3swR
                          reza3sw
                          last edited by

                          @gertjan said in SSL Man In the Middle Filtering blocking any app:

                          The MITM "problem" will probably never get solved.

                          Thank you very much

                          یاد کنید مرگ را، در هم کوبنده لذات و تیره و تلخ کننده شهوات را

                          نهج البلاغه

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.