Client Proxy (TLS terminate) Origin server
drag to pan · scroll / pinch to zoom

Added latency history

Connections by category (allowed / blocked)

TLS Interception at a Forward Proxy — 2D

A TLS-inspecting (SSL-inspecting) forward proxy is not a single encrypted tunnel — it is two independent TLS sessions joined by a brief plaintext window inside the proxy itself. This 2D simulator renders that pipeline as a pannable, zoomable diagram: client connections travel to the proxy over one TLS session, get decrypted and classified against an editable, live-tunable security policy, and — if allowed — are re-encrypted onto a second TLS session toward the real origin server. Toggling inspection off shows the blind spot it exists to close: connections become opaque again and policy can no longer see, let alone block, what's inside them. Two companion panels track the actual per-connection processing latency over time and the running tally of allowed vs. blocked connections per traffic category, both driven by the same sliders that control the flow above.