How to VPN: Set Up a Shadowsocks Server with Shadowsocks 2022

Contents

    This article assumes you are already logged into your VPS/Dedicated Server. Don’t have an account with us, feel free to sign up over at our Portal. Once registered check out our selection of VPS and Dedicated Servers.
    Already have one? Then feel free to proceed to follow the how-to guide below.

    When to use a Shadowsocks server

    A Shadowsocks server is a good choice for getting past moderate filtering, and it is light enough for the smallest VPS. Be aware of its limits: since November 2021, China’s Great Firewall has detected and blocked traffic that looks fully encrypted, which includes plain Shadowsocks. Shadowsocks 2022 adds mandatory replay protection, which makes your server reject captured Shadowsocks handshakes if they are replayed, but it does not hide Shadowsocks from traffic analysis. On heavily filtered networks, run it alongside a second protocol, such as our AmneziaWG tunnel, so one can take over when the other is blocked.

    Run every command in this guide as root. If you log in with your cloud username, switch to root first with sudo -i.

    Install the requirements

    You only need a few basic tools to download and unpack the release. Use the command for your operating system.

    Ubuntu and Debian

    apt update
    apt install -y curl xz-utils

    AlmaLinux

    dnf install -y curl tar xz

    Download shadowsocks-rust

    This finds the latest release on GitHub, downloads it with its checksum, verifies the file and unpacks the programs into /usr/local/bin. The commands are the same on Ubuntu, Debian and AlmaLinux, and they are for x86-64 servers, which includes every Packetra VPS and dedicated server. If you run them elsewhere, uname -m must print x86_64.

    # Find the latest version
    VER=$(curl -s https://api.github.com/repos/shadowsocks/shadowsocks-rust/releases/latest | grep -o '"tag_name": *"[^"]*"' | head -1 | cut -d '"' -f4)
    echo $VER
    
    # Download the release and its checksum
    cd /tmp
    curl -LO "https://github.com/shadowsocks/shadowsocks-rust/releases/download/${VER}/shadowsocks-${VER}.x86_64-unknown-linux-musl.tar.xz"
    curl -LO "https://github.com/shadowsocks/shadowsocks-rust/releases/download/${VER}/shadowsocks-${VER}.x86_64-unknown-linux-musl.tar.xz.sha256"
    
    # Verify the download, then install
    sha256sum -c "shadowsocks-${VER}.x86_64-unknown-linux-musl.tar.xz.sha256"
    tar -xJf "shadowsocks-${VER}.x86_64-unknown-linux-musl.tar.xz" -C /usr/local/bin --no-same-owner
    
    # If this prints a version number, the install worked
    ssserver --version

    The checksum line must end in OK. If it does not, delete the files and download them again.

    Check the server clock

    Shadowsocks 2022 rejects connections when the server and client clocks are more than 30 seconds apart, so the server’s clock must be synchronised.

    timedatectl

    Look for System clock synchronized: yes. If it says no, install a time service: apt install -y chrony on Ubuntu and Debian, or dnf install -y chrony && systemctl enable --now chronyd on AlmaLinux.

    Generate your key

    Shadowsocks 2022 does not use an ordinary password. It needs a random key of an exact length, and shadowsocks-rust can generate one for you.

    KEY=$(ssservice genkey -m "2022-blake3-aes-256-gcm")
    echo $KEY

    Copy the key somewhere safe. You will need it for the client, and anyone who has it can use your server.

    Write the server configuration

    This creates the configuration file with your key already filled in. It listens on port 443, because networks commonly allow outbound TCP traffic on that port. That does not make Shadowsocks look like HTTPS or keep it from being detected, and some networks still block UDP on port 443. If a web server already uses port 443 on this machine, choose another port and use it in every later step.

    mkdir -p /etc/shadowsocks-rust
    cat > /etc/shadowsocks-rust/config.json <<EOF
    {
        "server": "0.0.0.0",
        "server_port": 443,
        "password": "$KEY",
        "method": "2022-blake3-aes-256-gcm",
        "mode": "tcp_and_udp",
        "timeout": 7200
    }
    EOF
    cat /etc/shadowsocks-rust/config.json

    Check that the password line shows your key. If it is empty, your session lost the KEY value: run the key command again and repeat this step. To accept IPv6 connections as well, change "0.0.0.0" to "::".

    Run it as a service

    Next, create a dedicated user so the server does not run as root, then a service file so it starts automatically at boot.

    # A system user with no login and no home directory
    useradd --system --user-group --no-create-home --shell /usr/sbin/nologin shadowsocks
    chown root:shadowsocks /etc/shadowsocks-rust/config.json
    chmod 640 /etc/shadowsocks-rust/config.json
    
    # The service file
    cat > /etc/systemd/system/shadowsocks-rust.service <<'EOF'
    [Unit]
    Description=Shadowsocks-rust server
    After=network-online.target
    Wants=network-online.target
    
    [Service]
    Type=simple
    User=shadowsocks
    Group=shadowsocks
    AmbientCapabilities=CAP_NET_BIND_SERVICE
    CapabilityBoundingSet=CAP_NET_BIND_SERVICE
    NoNewPrivileges=yes
    ExecStart=/usr/local/bin/ssserver -c /etc/shadowsocks-rust/config.json
    Restart=on-failure
    
    [Install]
    WantedBy=multi-user.target
    EOF
    
    # Start it now and at every boot
    systemctl daemon-reload
    systemctl enable --now shadowsocks-rust
    systemctl status shadowsocks-rust --no-pager

    The status should show active (running). If it does not, journalctl -u shadowsocks-rust -n 50 shows why.

    Open the port in your firewall

    Only needed if a firewall is active on the server. Shadowsocks uses both TCP and UDP, so open both.

    Ubuntu and Debian with ufw

    ufw allow 443/tcp
    ufw allow 443/udp

    AlmaLinux with firewalld

    firewall-cmd --permanent --add-port=443/tcp
    firewall-cmd --permanent --add-port=443/udp
    firewall-cmd --reload

    Set up the client

    Your client app must support the Shadowsocks 2022 cipher. These do:

    • Android: shadowsocks-android, version 5.3.3 or later
    • Windows, macOS and Linux: v2rayN, which runs Shadowsocks through its sing-box or Xray core
    • Command line on Linux and macOS: sslocal, from the same shadowsocks-rust download
    • iOS: check that the app lists 2022-blake3-aes-256-gcm among its ciphers before you install or buy it

    Add a new Shadowsocks server in the app with these settings:

    Server:     YOUR_PUBLIC_IP
    Port:       443
    Password:   YOUR_KEY
    Encryption: 2022-blake3-aes-256-gcm

    To use sslocal instead, run the command below on your own computer. It opens a SOCKS5 proxy on port 1080 that you can point your browser or other apps at.

    sslocal -b 127.0.0.1:1080 -s YOUR_PUBLIC_IP:443 -m "2022-blake3-aes-256-gcm" -k "YOUR_KEY"

    Older Shadowsocks clients may not list the 2022 cipher. If yours does not, switch to one of the apps above rather than downgrading the server to an older cipher.

    Verify the connection

    Connect in your client app, then open a site like WhatIsMyIpAddress. It should show your server’s IP address, not your own. If you use sslocal, you can test from the same computer:

    curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me

    On the server, journalctl -u shadowsocks-rust -f shows the service log live while you connect.

    Final Words

    You now have a Shadowsocks server running the 2022 cipher as an unprivileged system service that starts at boot. It is fast, light and simple to share with a few people. It is not invisible to the most aggressive filters, so where censorship is severe, keep a second protocol such as AmneziaWG ready and see our guide to censorship-resistant hosting for the wider picture.

    Frequently Asked Questions

    Why Shadowsocks 2022 instead of the older ciphers?
    The 2022 edition uses a proper random key instead of a password, adds protection against replayed traffic, and was designed to fix weaknesses that let censors probe older Shadowsocks servers. Use it unless a client you cannot replace does not support it.

    My client won’t connect and there’s no clear error. What’s wrong?
    Check four things in this order: the key and the cipher must match the server exactly, the server and client clocks must be within 30 seconds of each other, the port must be open for both TCP and UDP, and the service must be running. Then look at journalctl -u shadowsocks-rust -n 50 on the server.

    Will a Shadowsocks server work in China, Iran or Russia?
    Sometimes, and it varies by country, ISP and network. Plain Shadowsocks can be detected or blocked on heavily filtered networks, so do not rely on it as your only connection method, and test from the network you care about.

    Shadowsocks or AmneziaWG?
    Both. Shadowsocks works per app as a proxy and is very light, while AmneziaWG is a full tunnel for the whole device. Running both on one server gives you a fallback when one gets blocked.

    Good to Know
    Your key is the authentication secret for your Shadowsocks server, so keep it private and generate a new one if it leaks: run the key command again, put the new key in /etc/shadowsocks-rust/config.json, then systemctl restart shadowsocks-rust and update your clients. Check for new shadowsocks-rust releases now and then and repeat the download step to upgrade, followed by a restart. Run into any issues? Open a support ticket through the client portal and our team will help you.

    Updated on October 6, 2026
    Was this article helpful?

    Leave a Reply

    Your email address will not be published. Required fields are marked *