# Unable to passthrough tls

**URL:** <https://community.traefik.io/t/unable-to-passthrough-tls/6690>\
**Category:** Traefik v2\
**Tags:** kubernetes-crd, kubernetes-ingress\
**Created:** [June 28, 2020, 1:10pm UTC](https://community.traefik.io/t/unable-to-passthrough-tls/6690 "2020-06-28T13:10:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aleyrizvi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/aleyrizvi/32/7293_2.png) [@aleyrizvi](https://community.traefik.io/u/aleyrizvi)\
**Post date:** [June 28, 2020, 1:10pm UTC](https://community.traefik.io/t/unable-to-passthrough-tls/6690/1 "2020-06-28T13:10:49Z")

</div>

Hello,  
I am trying to create an IngressRouteTCP to expose my mail server web UI. Mail server handles his own tls servers so a tls passthrough seems logical. Here is my ingress:

```auto
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRouteTCP
metadata:
  name: miab-websecure
  namespace: devusta
spec:
  entryPoints:
  - websecure
  routes:
  - match: "HostSNI(`mail.devusta.com`)"
    tls:
        passthrough: true
    services:
    - name: mailinabox
      port: 443

```

However, if you access [https://mail.devusta.com](https://mail.devusta.com) it shows self signed certificate from traefik. Shouldn't it be not handling tls if passthrough is enabled?

PS: I am learning traefik and kubernetes so more comfortable with Ingress. Is it possible to use tcp router with Ingress instead of IngressRouteTCP? An example would be great.

---

<div class="post-metadata">

**Author:** ![mikesir87](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/mikesir87/32/4582_2.png) [@mikesir87](https://community.traefik.io/u/mikesir87)\
**Post date:** [December 2, 2021, 10:35pm UTC](https://community.traefik.io/t/unable-to-passthrough-tls/6690/2 "2021-12-02T22:35:27Z")

</div>

Hi @aleyrizvi! Did you ever get this figured out? I'm running into the exact same problem now.

---

<div class="post-metadata">

**Author:** ![NEwa-05](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/newa-05/32/4584_2.png) [@NEwa-05](https://community.traefik.io/u/NEwa-05)\
**Post date:** [December 3, 2021, 9:28am UTC](https://community.traefik.io/t/unable-to-passthrough-tls/6690/3 "2021-12-03T09:28:19Z")

</div>

Hello,

Last time I did a TLS passthrough the tls part was out of the routes you define in your ingressRoute.

This was my ingressRoute 3 month ago:

```yaml
---
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRouteTCP
metadata:
  name: foobar-api-iro
spec:
  entryPoints: 
    - websecure
  tls:
    passthrough: true
  routes:
  - match: HostSNI(`api.mageekbox.eu`)
    services:
    - name: foobar-api-svc
      port: 80

```

Hope this would work for you.

---

<div class="post-metadata">

**Author:** ![mikesir87](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/mikesir87/32/4582_2.png) [@mikesir87](https://community.traefik.io/u/mikesir87)\
**Post date:** [January 28, 2022, 2:58pm UTC](https://community.traefik.io/t/unable-to-passthrough-tls/6690/4 "2022-01-28T14:58:46Z")

</div>

Finally looping back on this. @NEwa-05 - you rock! That worked perfectly! I'm not sure what I was messing up before and couldn't get working, but that does the trick. Thank you!

---

<div class="post-metadata">

**Author:** ![NEwa-05](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/newa-05/32/4584_2.png) [@NEwa-05](https://community.traefik.io/u/NEwa-05)\
**Post date:** [February 7, 2022, 10:17am UTC](https://community.traefik.io/t/unable-to-passthrough-tls/6690/5 "2022-02-07T10:17:04Z")

</div>

Bit late on the answer, but good to know it works for you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bd81ebdb578656e76e56ff3cc3eed021d3ba132d.png) [@system](https://community.traefik.io/u/system)\
**Post date:** [July 3, 2023, 6:50pm UTC](https://community.traefik.io/t/unable-to-passthrough-tls/6690/6 "2023-07-03T18:50:32Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
