diladele here with MITM. Again set as a subCa. Our vlan guest network has the same filter levels, as part of the documentation staff have to install the subCA root cert or they dont get https (so most of the internet really). We DPI block vpns too. Sure there will be some way around but we are an educational establishment so we need to be strict.

