# Intercepting tcp connections with TLS 1.2 and custom certificates

**URL:** <https://discourse.mitmproxy.org/t/intercepting-tcp-connections-with-tls-1-2-and-custom-certificates/307>\
**Category:** help\
**Created:** [January 16, 2017, 9:18am UTC](https://discourse.mitmproxy.org/t/intercepting-tcp-connections-with-tls-1-2-and-custom-certificates/307 "2017-01-16T09:18:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bottee](https://avatars.discourse-cdn.com/v4/letter/b/ce7236/32.png) [@bottee](https://discourse.mitmproxy.org/u/bottee)\
**Post date:** [January 16, 2017, 9:18am UTC](https://discourse.mitmproxy.org/t/intercepting-tcp-connections-with-tls-1-2-and-custom-certificates/307/1 "2017-01-16T09:18:23Z")

</div>

Hi,

when trying to intercept non HTTPS tcp connections with TLS 1.2 in a local network without DNS name, following error happen:

warn [xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx):yyyy: Cannot connect to server, no server address given.

What is my mistake?

Steps to reproduce the problem:

- creating self signed server cert.pem and client certificate client-cert.pem
- client and server are running in local network without dns.
- mitmproxy --tcp [xxx.xxx.xxx.xxx](http://xxx.xxx.xxx.xxx):yyyy --cert \*=./cert.pem --client-cert ./client-cert.pem

Mitmproxy version: 1.0.2  
Python version: 3.5.2  
Platform: Linux-4.4.36-8-default-x86\_64-with-SuSE-42.2-x86\_64  
SSL version: OpenSSL 1.1.0c 10 Nov 2016  
Linux distro: openSUSE 42.2 x86\_64

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [January 17, 2017, 9:52pm UTC](https://discourse.mitmproxy.org/t/intercepting-tcp-connections-with-tls-1-2-and-custom-certificates/307/2 "2017-01-17T21:52:18Z")

</div>

How are you redirecting connections to mitmproxy?  
This looks mitmproxy has no information about the connection destination, see [http://docs.mitmproxy.org/en/stable/modes.html](http://docs.mitmproxy.org/en/stable/modes.html).

---

<div class="post-metadata">

**Author:** ![bottee](https://avatars.discourse-cdn.com/v4/letter/b/ce7236/32.png) [@bottee](https://discourse.mitmproxy.org/u/bottee)\
**Post date:** [January 23, 2017, 9:38am UTC](https://discourse.mitmproxy.org/t/intercepting-tcp-connections-with-tls-1-2-and-custom-certificates/307/3 "2017-01-23T09:38:53Z")

</div>

Hi,

thank you for your fast response!

Mitmproxy, the client and the server are in the same local network. With --tcp I provide mitmproxy the ip-address of the server. The client is configured to use the ip address of the mitmproxy server as destination. The server has no DNS name, only an IP-Address.

Is this scenario possible?

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [January 23, 2017, 12:18pm UTC](https://discourse.mitmproxy.org/t/intercepting-tcp-connections-with-tls-1-2-and-custom-certificates/307/4 "2017-01-23T12:18:31Z")

</div>

With `--tcp` you specify for which hosts you want to use TCP mode, but that doesn’t imply the target. You need to start mitmproxy as a reverse proxy as well (disregard the http[s] at the beginning of the URL - that’ll be overridden by --tcp).
