TLS Inspector Filter (proto)

This extension has the qualified name envoy.filters.listener.tls_inspector


This extension is intended to be robust against both untrusted downstream and upstream traffic.


This extension extends and can be used with the following extension category:

This extension must be configured with one of the following type URLs:

Allows detecting whether the transport appears to be TLS or plaintext.


[extensions.filters.listener.tls_inspector.v3.TlsInspector proto]

  "enable_ja3_fingerprinting": {...},
  "initial_read_buffer_size": {...}

(BoolValue) Populate JA3 fingerprint hash using data from the TLS Client Hello packet. Default is false.


(UInt32Value) The size in bytes of the initial buffer requested by the tls_inspector. If the filter needs to read additional bytes from the socket, the filter will double the buffer up to it’s default maximum of 64KiB. If this size is not defined, defaults to maximum 64KiB that the tls inspector will consume.