启用iptables PREROUTING规则后手机无法上网,原因何在?(目标:捕获手机SSL流量)
Hey Dave, let's figure out why your phone loses internet access after adding those iptables PREROUTING rules. These are the most likely causes and how to fix them:
1. IP Forwarding Isn't Enabled on Your Laptop
When you redirect your phone's traffic to mitmproxy, your laptop needs to forward that traffic to the actual internet servers. If IP forwarding is turned off, the system will just drop those packets, leaving your phone without connectivity.
- Check if it's enabled:
cat /proc/sys/net/ipv4/ip_forward - If the output is
0, enable it temporarily:echo 1 > /proc/sys/net/ipv4/ip_forward - To make this permanent (survives reboots), edit
/etc/sysctl.conf, uncomment or add:
Then runnet.ipv4.ip_forward=1sysctl -pto apply the change.
2. Missing FORWARD Chain Rules
Even with IP forwarding on, iptables might block traffic from your phone's hotspot interface (wlan0) to your laptop's Ethernet interface. You need to explicitly allow this forwarding:
iptables -A FORWARD -i wlan0 -o eth0 -j ACCEPT iptables -A FORWARD -i eth0 -o wlan0 -j ACCEPT
This lets mitmproxy send processed traffic out to the internet via Ethernet, and allows response traffic to flow back to your phone.
3. mitmproxy Isn't Running in Transparent Mode (or Not Listening on 8080)
Your iptables rules send traffic to port 8080, but if mitmproxy isn't running there in transparent mode, those connections have nowhere to go.
- Start mitmproxy in transparent mode with:
Or if you prefer the headless version:mitmproxy --mode transparentmitmdump --mode transparent - Verify mitmproxy is listening on 8080:
You should see a line withss -tulpn | grep 8080mitmproxybound to0.0.0.0:8080.
4. Port 8080 Is Already in Use by Another Program
If another app (like a web server, another proxy, or debugging tool) is using port 8080, mitmproxy can't bind to it, and your redirected traffic will fail.
- Check what's using 8080:
lsof -i :8080 - Either kill the conflicting process, or change mitmproxy's listening port (e.g., to 8081) and update your iptables rules:
mitmproxy --mode transparent --listen-port 8081 iptables -t nat -A PREROUTING -i wlan0 -p tcp --dport 80 -j REDIRECT --to-port 8081 iptables -t nat -A PREROUTING -i wlan0 -p tcp --dport 443 -j REDIRECT --to-port 8081
5. Missing mitmproxy CA Certificate on Your Phone
While this won't cause total internet outage (you'll usually get certificate errors), some strict apps will refuse to connect entirely, making it seem like you have no access.
- On your phone, connect to the laptop hotspot and visit
http://mitm.it - Download the CA certificate for your phone's OS, then install it to the system trusted certificate store (not just the user store—many apps ignore user-trusted certs).
Start with checking IP forwarding and FORWARD rules first—those are the most common oversights when setting up transparent proxying!
内容的提问来源于stack exchange,提问作者Dave

