Tunneler intercept-only mode?

Hi All,

I see that the tunneler clients can run in run-host mode that only allows host configurations (or at least does not allow intercept functionality), and can run in run mode that allow both host and intercept configurations.

Q: Is there a way to configure the tunneler to only accept intercept configurations?

Motivation: I would like to allow extended family access to some resources on my network while assuring them that the tunneler client does not allow me access to their phone/pc/etc. I have verified that the Android (Ziti Mobile Edge) and Linux (ziti-edge-tunnel) tunneler clients both allow me to do just that. Unhappily in addition and from a transparency perspective, the ZME Android client shows the host configuration as an intercept when it is in fact a host config.

Thank you!

Hi @shawncp, it's a long-standing idea/request that we just haven't been able to find the time to implement.

It's come up now and then in the years since that's issue was opened but it's something we continue to bring up every few months or so.

I'm sure we will get to it, but like all our other good ideas, it's just a properly/prioritization problem. Cheers

Thank you @TheLumberjack for the reference. I have added a bump to the github issue.