# Intercepting tcp connections with TLS 1.2 and custom certificates

**URL:** <https://discourse.mitmproxy.org/t/intercepting-tcp-connections-with-tls-1-2-and-custom-certificates/307>\
**Category:** help\
**Created:** [January 16, 2017, 9:18am UTC](https://discourse.mitmproxy.org/t/intercepting-tcp-connections-with-tls-1-2-and-custom-certificates/307 "2017-01-16T09:18:23Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [January 23, 2017, 12:18pm UTC](https://discourse.mitmproxy.org/t/intercepting-tcp-connections-with-tls-1-2-and-custom-certificates/307/4 "2017-01-23T12:18:31Z")

</div>

With `--tcp` you specify for which hosts you want to use TCP mode, but that doesn’t imply the target. You need to start mitmproxy as a reverse proxy as well (disregard the http[s] at the beginning of the URL - that’ll be overridden by --tcp).

---

_[View the full topic](https://discourse.mitmproxy.org/t/intercepting-tcp-connections-with-tls-1-2-and-custom-certificates/307)._
