Community discussions

MikroTik App
 
kve
just joined
Topic Author
Posts: 1
Joined: Wed Sep 08, 2021 7:55 am
Location: Tashkent

Feature Request: SSTP Client TLS SNI Extension

Wed Sep 08, 2021 8:15 am

Please add an option to the sstp client that allows to specify the SNI extension in the tls client hello message. This would be very useful when using haproxy for example, and will increase the effectiveness of the protocol when passing through various firewalls and dpi.
Thank you!
 
soheilsh
Member Candidate
Member Candidate
Posts: 112
Joined: Fri Nov 26, 2010 3:39 pm

Re: Feature Request: SSTP Client TLS SNI Extension

Thu Aug 10, 2023 10:36 pm

This issue of sni in sstp is very important and adding it is not difficult at all, with the situation that governments have taken to suppress the internet, network tools need to be equipped with such things, but unfortunately, Mikrotik has no interest in updating these things. does not have
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4498
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: Feature Request: SSTP Client TLS SNI Extension

Fri Aug 11, 2023 5:57 am

Never thought about this, but I can see how SNI be useful with SSTP.

But it still HTTPS, so you theoretically use NGNIX in a container as reverse proxy for SSTP . As NGNIX could deal with the TLS SNI, and then proxy to real Mikrotik SSTP server without it. More work, but be one solution.
 
Eugenn
just joined
Posts: 2
Joined: Tue Nov 21, 2023 11:41 am

Re: Feature Request: SSTP Client TLS SNI Extension

Tue Nov 21, 2023 11:45 am

I'd like to support this request.
Please add possibility to specify SNI in SSTP protocol
 
oskarsk
MikroTik Support
MikroTik Support
Posts: 70
Joined: Mon May 13, 2019 9:41 am

Re: Feature Request: SSTP Client TLS SNI Extension

Tue Apr 16, 2024 5:06 pm

Feature added, will be available within next testing version, 7.15beta10
 
User avatar
own3r1138
Forum Veteran
Forum Veteran
Posts: 728
Joined: Sun Feb 14, 2021 12:33 am
Location: Pleiades
Contact:

Re: Feature Request: SSTP Client TLS SNI Extension

Tue Apr 16, 2024 8:44 pm

Feature added, will be available within next testing version, 7.15beta10
Hooray
 
Student99
just joined
Posts: 2
Joined: Tue Sep 24, 2024 10:21 pm

Re: Feature Request: SSTP Client TLS SNI Extension

Tue Sep 24, 2024 10:27 pm

Hi, this feature has only 2 option (yes/no)
Is there a way to put the specific TLS SNI address?
or this option does not exist in Mikrotik OS yet?
I tried in terminal too, this feature only has that 2 option that the GUI shows(yes/no)
 
User avatar
vecernik87
Forum Veteran
Forum Veteran
Posts: 891
Joined: Fri Nov 10, 2017 8:19 am

Re: Feature Request: SSTP Client TLS SNI Extension

Wed Sep 25, 2024 4:18 am

The SNI value is implied by server address. If my client connects to vpn.example.com, then SNI value should be vpn.example.com

What use case is for having specific SNI, which would be different from server's address?
 
Student99
just joined
Posts: 2
Joined: Tue Sep 24, 2024 10:21 pm

Re: Feature Request: SSTP Client TLS SNI Extension

Fri Sep 27, 2024 1:45 pm

Some SSTP clients In android devices like "open sstp client" & "vpn client pro" give this option. you try to connect to your vpn server like "vpn.example.com" but you use the SNI value "somthingelse.somthingelse.com" In those guide I studied some of the SNI they used was "yahoo.com" or "cdn.appflyer.com" I don't really know the fundamental of the using SNI but these custom SNI option helps to bypass some restriction for connecting to SSTP server in my location.
That's why i need to use custom SNI and not the one my vpn server provides.