# Bro behind a TLS reverse proxy

**URL:** <https://community.zeek.org/t/bro-behind-a-tls-reverse-proxy/5248>\
**Category:** Zeek\
**Created:** [April 10, 2018, 3:21pm UTC](https://community.zeek.org/t/bro-behind-a-tls-reverse-proxy/5248 "2018-04-10T15:21:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![promerocenic](https://avatars.discourse-cdn.com/v4/letter/p/2acd7d/32.png) [@promerocenic](https://community.zeek.org/u/promerocenic)\
**Post date:** [April 10, 2018, 3:21pm UTC](https://community.zeek.org/t/bro-behind-a-tls-reverse-proxy/5248/1 "2018-04-10T15:21:00Z")

</div>

I don’t know if this messes up your test, but I didn’t have tshark on the physical box I’m running. Below is the output showing the date via tcpdump options. It looks correct.

$ tcpdump -ttttnnr lo-port-80.pcap  
reading from file lo-port-80.pcap, link-type EN10MB (Ethernet)  
2018-04-10 08:13:20.209770 IP6 ::1.49258 \> ::1.80: Flags [S], seq 485780875, win 43690, options [mss 65476,sackOK,TS val 1090368614 ecr 0,nop,wscale 7], length 0  
2018-04-10 08:13:20.209809 IP6 ::1.80 \> ::1.49258: Flags [R.], seq 0, ack 485780876, win 0, length 0  
2018-04-10 08:13:20.210015 IP 127.0.0.1.43960 \> 127.0.0.1.80: Flags [S], seq 859064153, win 43690, options [mss 65495,sackOK,TS val 1090368615 ecr 0,nop,wscale 7], length 0  
2018-04-10 08:13:20.210046 IP 127.0.0.1.80 \> 127.0.0.1.43960: Flags [R.], seq 0, ack 859064154, win 0, length 0  
$

Philip

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:45pm UTC](https://community.zeek.org/t/bro-behind-a-tls-reverse-proxy/5248/2 "2022-05-06T15:45:41Z")

</div>


