Hi!Can you please give more info about "transparent SSL mode that PFSense has where there is no need to add the CA in every client"?
hmmmm how can you do transparent SSL proxy without using a CA for which you have the private key?
of course there is splice option which I cant find it in opnsense.
forget this method, I just want to control url access even via https
Quote from: samnet on August 24, 2020, 10:59:53 pmforget this method, I just want to control url access even via httpsand no. you can not view requested url (if you mean exactly full url) without mitm. only tcp info, tls hello and sni info (if any).
Im still not getting this right, do you mean its impossible to see full URLs without MITM?
is there a splice option in opnsense?
thanks for clarification. can you pls suggest any way for controlling URL access in a network with 100 desktops / laptops / mobiles many of them logging via Active Directory win2012
Get an AD integrated Proxy product, force proxy via group policy, deny Internet access for everyone but proxy on OPNsense.