This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples.
Microsoft Public License
6.88k
stars
4.92k
forks
source link
FWPM_LAYER_ALE_CONNECT_REDIRECT_V4: Can't redirect to local proxy #979
Hi all, I am trying to develop a WFP driver which can be used to redirect outgoing TCP connections to a local proxy server. To better understand the different components involved, I tried running WFPSampler project on a new Windows 11 installation:
and I can see that the following filter is registered at the ALE_CONNECT_REDIRECT_V4 layer:
Unfortunately, no traffic is ever reaching the locally running proxy server. If I make an HTTP connection to a remote server, it simply succeeds as if there are no WFP rules.
I am new to kernel development and not sure how can I further debug this and whether the callout function is ever invoked. I never managed to get TraceView working.
Hi all, I am trying to develop a WFP driver which can be used to redirect outgoing TCP connections to a local proxy server. To better understand the different components involved, I tried running WFPSampler project on a new Windows 11 installation:
After running this command, it seems that the WFPSampler service is successfully invoked through RPC:
and I can see that the following filter is registered at the ALE_CONNECT_REDIRECT_V4 layer:
Unfortunately, no traffic is ever reaching the locally running proxy server. If I make an HTTP connection to a remote server, it simply succeeds as if there are no WFP rules.
I am new to kernel development and not sure how can I further debug this and whether the callout function is ever invoked. I never managed to get TraceView working.
Any pointers would be greatly appreciated.