SSL illegal_parameter_in_client_hello for handshake in Transparent Proxy Scenario

you need to use tcpdump/wireshark to see what the issue is, usually it will be something like assuming that the ECH / SNI comes in a single frame, which it doesn’t always for larger keys like Chrome’s post-quantum key exchange.

See https://tldr.fail/