You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

启用iptables PREROUTING规则后手机无法上网,原因何在?(目标:捕获手机SSL流量)

Hey Dave, let's figure out why your phone loses internet access after adding those iptables PREROUTING rules. These are the most likely causes and how to fix them:

Common Issues & Fixes

1. IP Forwarding Isn't Enabled on Your Laptop

When you redirect your phone's traffic to mitmproxy, your laptop needs to forward that traffic to the actual internet servers. If IP forwarding is turned off, the system will just drop those packets, leaving your phone without connectivity.

  • Check if it's enabled:
    cat /proc/sys/net/ipv4/ip_forward
    
  • If the output is 0, enable it temporarily:
    echo 1 > /proc/sys/net/ipv4/ip_forward
    
  • To make this permanent (survives reboots), edit /etc/sysctl.conf, uncomment or add:
    net.ipv4.ip_forward=1
    
    Then run sysctl -p to apply the change.

2. Missing FORWARD Chain Rules

Even with IP forwarding on, iptables might block traffic from your phone's hotspot interface (wlan0) to your laptop's Ethernet interface. You need to explicitly allow this forwarding:

iptables -A FORWARD -i wlan0 -o eth0 -j ACCEPT
iptables -A FORWARD -i eth0 -o wlan0 -j ACCEPT

This lets mitmproxy send processed traffic out to the internet via Ethernet, and allows response traffic to flow back to your phone.

3. mitmproxy Isn't Running in Transparent Mode (or Not Listening on 8080)

Your iptables rules send traffic to port 8080, but if mitmproxy isn't running there in transparent mode, those connections have nowhere to go.

  • Start mitmproxy in transparent mode with:
    mitmproxy --mode transparent
    
    Or if you prefer the headless version:
    mitmdump --mode transparent
    
  • Verify mitmproxy is listening on 8080:
    ss -tulpn | grep 8080
    
    You should see a line with mitmproxy bound to 0.0.0.0:8080.

4. Port 8080 Is Already in Use by Another Program

If another app (like a web server, another proxy, or debugging tool) is using port 8080, mitmproxy can't bind to it, and your redirected traffic will fail.

  • Check what's using 8080:
    lsof -i :8080
    
  • Either kill the conflicting process, or change mitmproxy's listening port (e.g., to 8081) and update your iptables rules:
    mitmproxy --mode transparent --listen-port 8081
    iptables -t nat -A PREROUTING -i wlan0 -p tcp --dport 80 -j REDIRECT --to-port 8081
    iptables -t nat -A PREROUTING -i wlan0 -p tcp --dport 443 -j REDIRECT --to-port 8081
    

5. Missing mitmproxy CA Certificate on Your Phone

While this won't cause total internet outage (you'll usually get certificate errors), some strict apps will refuse to connect entirely, making it seem like you have no access.

  • On your phone, connect to the laptop hotspot and visit http://mitm.it
  • Download the CA certificate for your phone's OS, then install it to the system trusted certificate store (not just the user store—many apps ignore user-trusted certs).

Start with checking IP forwarding and FORWARD rules first—those are the most common oversights when setting up transparent proxying!

内容的提问来源于stack exchange,提问作者Dave

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:41:24