Reverse proxy problems on local network with FiOS G3100

My situation is a tad complex. I'm on FiOS, a G3100 router. (Other than the TVs) the only thing connected to the G3100 is a Google puck system (which the G3100 sees as Everything, including a Synology DiskStation, is on the Google WiFi network, which is 192.168.86.*. I'm trying to securely access applications on a Ubuntu box at, at various ports.

On the G3100 I've forwarded HTTP and HTTPS to the Google router. On the Google router I've forwarded those ports to the Synology. I've used the Synology reverse proxy capabilities to forward various subdomains (e.g., to the appropriate ports on the Ubuntu box (e.g., The Synology app takes care of getting Let's Encrypt certificates issued; I've done those on a per-app basis.

From outside my local network it all works perfectly.

Inside the local network, it worked perfectly for many months, but now I started getting certificate errors (Certificate does not match the URL). When I examine the certificate, it tells me it was issued to, when it should have been issued to

In short, connections inside the network are being given a different SSL certificate than those outside the network.

I know enough to be dangerous.

Help, please?


It sounds like the FiOS system was updated and is now listening to TLS (port 443) or is doing a MITM IPS/Web filtering type service for you.
Do you reach the correct destination/content when you ignore the cert warning and continue?

No, I can't connect even ignoring the cert warning; Chrome gives me an HSTS error and says it can't connect to the site. When I examine the certificate I'm told the CN is

I agree it seems as if FiOS is doing a man-in-the-middle. But I don't know what to do about it.


Login to the FiOS gateway router and see what it does.
Call the provider if you can't find what your looking for.

I've been all through the router's menus without finding anything that seems relevant.

I guess calling Verizon is indeed the next step.


