aboutsummaryrefslogtreecommitdiffstats
path: root/doc-src/transparent/linux.html
diff options
context:
space:
mode:
authorMaximilian Hils <git@maximilianhils.com>2014-01-28 17:29:28 +0100
committerMaximilian Hils <git@maximilianhils.com>2014-01-28 17:29:28 +0100
commit1e3e0dd1271afda59ec244b64391b6579a998dce (patch)
tree5f1f617ccc8ea2b29650c10197407b1d3ecb7139 /doc-src/transparent/linux.html
parent17f09aa0afe9695505b746c370e1c5b889c19058 (diff)
parent3aa78f9ff38471f84a471618e1a43ca02fc65b6a (diff)
downloadmitmproxy-1e3e0dd1271afda59ec244b64391b6579a998dce.tar.gz
mitmproxy-1e3e0dd1271afda59ec244b64391b6579a998dce.tar.bz2
mitmproxy-1e3e0dd1271afda59ec244b64391b6579a998dce.zip
merge master
Diffstat (limited to 'doc-src/transparent/linux.html')
-rw-r--r--doc-src/transparent/linux.html43
1 files changed, 43 insertions, 0 deletions
diff --git a/doc-src/transparent/linux.html b/doc-src/transparent/linux.html
new file mode 100644
index 00000000..96b7132a
--- /dev/null
+++ b/doc-src/transparent/linux.html
@@ -0,0 +1,43 @@
+On Linux, mitmproxy integrates with the iptables redirection mechanism to
+achieve transparent mode.
+
+<ol class="tlist">
+
+ <li> <a href="@!urlTo('ssl.html')!@">Install the mitmproxy
+ certificates on the test device</a>. </li>
+
+ <li> Enable IP forwarding:
+
+ <pre class="terminal">sysctl -w net.ipv4.ip_forward=1</pre>
+
+ You may also want to consider enabling this permanently in
+ <b>/etc/sysctl.conf</b>.
+
+ </li>
+
+ <li> Create an iptables ruleset that redirects the desired traffic to the
+ mitmproxy port. Details will differ according to your setup, but the
+ ruleset should look something like this:
+
+<pre class="terminal">iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 8080
+iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 443 -j REDIRECT --to-port 8080</pre>
+
+ </li>
+
+ <li> Fire up mitmproxy. You probably want a command like this:
+
+ <pre class="terminal">mitmproxy -T --host</pre>
+
+ The <b>-T</b> flag turns on transparent mode, and the <b>--host</b>
+ argument tells mitmproxy to use the value of the Host header for URL
+ display.
+
+ </li>
+
+ <li> Finally, configure your test device to use the host on which mitmproxy is
+ running as the default gateway.</li>
+
+</ol>
+
+
+For a detailed walkthrough, have a look at the <a href="@!urlTo('tutorials/transparent-dhcp.html')!@"><i>Transparently proxify virtual machines</i></a> tutorial.