Shadowsocks is a lightweight encrypted proxy built to get around internet censorship. In this guide you will set up a Shadowsocks server on your Packetra VPS using shadowsocks-rust, the actively maintained implementation, with the modern Shadowsocks 2022 cipher. It takes about fifteen minutes.
When to use a Shadowsocks server
A Shadowsocks server is a good choice for getting past moderate filtering, and it is light enough for the smallest VPS. Be aware of its limits: since November 2021, China’s Great Firewall has detected and blocked traffic that looks fully encrypted, which includes plain Shadowsocks. Shadowsocks 2022 adds mandatory replay protection, which makes your server reject captured Shadowsocks handshakes if they are replayed, but it does not hide Shadowsocks from traffic analysis. On heavily filtered networks, run it alongside a second protocol, such as our AmneziaWG tunnel, so one can take over when the other is blocked.
Run every command in this guide as root. If you log in with your cloud username, switch to root first with sudo -i.
Install the requirements
You only need a few basic tools to download and unpack the release. Use the command for your operating system.
Ubuntu and Debian
apt update
apt install -y curl xz-utils
AlmaLinux
dnf install -y curl tar xz
Download shadowsocks-rust
This finds the latest release on GitHub, downloads it with its checksum, verifies the file and unpacks the programs into /usr/local/bin. The commands are the same on Ubuntu, Debian and AlmaLinux, and they are for x86-64 servers, which includes every Packetra VPS and dedicated server. If you run them elsewhere, uname -m must print x86_64.
# Find the latest version
VER=$(curl -s https://api.github.com/repos/shadowsocks/shadowsocks-rust/releases/latest | grep -o '"tag_name": *"[^"]*"' | head -1 | cut -d '"' -f4)
echo $VER
# Download the release and its checksum
cd /tmp
curl -LO "https://github.com/shadowsocks/shadowsocks-rust/releases/download/${VER}/shadowsocks-${VER}.x86_64-unknown-linux-musl.tar.xz"
curl -LO "https://github.com/shadowsocks/shadowsocks-rust/releases/download/${VER}/shadowsocks-${VER}.x86_64-unknown-linux-musl.tar.xz.sha256"
# Verify the download, then install
sha256sum -c "shadowsocks-${VER}.x86_64-unknown-linux-musl.tar.xz.sha256"
tar -xJf "shadowsocks-${VER}.x86_64-unknown-linux-musl.tar.xz" -C /usr/local/bin --no-same-owner
# If this prints a version number, the install worked
ssserver --version
The checksum line must end in OK. If it does not, delete the files and download them again.
Check the server clock
Shadowsocks 2022 rejects connections when the server and client clocks are more than 30 seconds apart, so the server’s clock must be synchronised.
timedatectl
Look for System clock synchronized: yes. If it says no, install a time service: apt install -y chrony on Ubuntu and Debian, or dnf install -y chrony && systemctl enable --now chronyd on AlmaLinux.
Generate your key
Shadowsocks 2022 does not use an ordinary password. It needs a random key of an exact length, and shadowsocks-rust can generate one for you.
KEY=$(ssservice genkey -m "2022-blake3-aes-256-gcm")
echo $KEY
Copy the key somewhere safe. You will need it for the client, and anyone who has it can use your server.
Write the server configuration
This creates the configuration file with your key already filled in. It listens on port 443, because networks commonly allow outbound TCP traffic on that port. That does not make Shadowsocks look like HTTPS or keep it from being detected, and some networks still block UDP on port 443. If a web server already uses port 443 on this machine, choose another port and use it in every later step.
mkdir -p /etc/shadowsocks-rust
cat > /etc/shadowsocks-rust/config.json <<EOF
{
"server": "0.0.0.0",
"server_port": 443,
"password": "$KEY",
"method": "2022-blake3-aes-256-gcm",
"mode": "tcp_and_udp",
"timeout": 7200
}
EOF
cat /etc/shadowsocks-rust/config.json
Check that the password line shows your key. If it is empty, your session lost the KEY value: run the key command again and repeat this step. To accept IPv6 connections as well, change "0.0.0.0" to "::".
Run it as a service
Next, create a dedicated user so the server does not run as root, then a service file so it starts automatically at boot.
# A system user with no login and no home directory
useradd --system --user-group --no-create-home --shell /usr/sbin/nologin shadowsocks
chown root:shadowsocks /etc/shadowsocks-rust/config.json
chmod 640 /etc/shadowsocks-rust/config.json
# The service file
cat > /etc/systemd/system/shadowsocks-rust.service <<'EOF'
[Unit]
Description=Shadowsocks-rust server
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=shadowsocks
Group=shadowsocks
AmbientCapabilities=CAP_NET_BIND_SERVICE
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
NoNewPrivileges=yes
ExecStart=/usr/local/bin/ssserver -c /etc/shadowsocks-rust/config.json
Restart=on-failure
[Install]
WantedBy=multi-user.target
EOF
# Start it now and at every boot
systemctl daemon-reload
systemctl enable --now shadowsocks-rust
systemctl status shadowsocks-rust --no-pager
The status should show active (running). If it does not, journalctl -u shadowsocks-rust -n 50 shows why.
Open the port in your firewall
Only needed if a firewall is active on the server. Shadowsocks uses both TCP and UDP, so open both.
Ubuntu and Debian with ufw
ufw allow 443/tcp
ufw allow 443/udp
AlmaLinux with firewalld
firewall-cmd --permanent --add-port=443/tcp
firewall-cmd --permanent --add-port=443/udp
firewall-cmd --reload
Set up the client
Your client app must support the Shadowsocks 2022 cipher. These do:
- Android: shadowsocks-android, version 5.3.3 or later
- Windows, macOS and Linux: v2rayN, which runs Shadowsocks through its sing-box or Xray core
- Command line on Linux and macOS:
sslocal, from the same shadowsocks-rust download - iOS: check that the app lists
2022-blake3-aes-256-gcmamong its ciphers before you install or buy it
Add a new Shadowsocks server in the app with these settings:
Server: YOUR_PUBLIC_IP
Port: 443
Password: YOUR_KEY
Encryption: 2022-blake3-aes-256-gcm
To use sslocal instead, run the command below on your own computer. It opens a SOCKS5 proxy on port 1080 that you can point your browser or other apps at.
sslocal -b 127.0.0.1:1080 -s YOUR_PUBLIC_IP:443 -m "2022-blake3-aes-256-gcm" -k "YOUR_KEY"
Older Shadowsocks clients may not list the 2022 cipher. If yours does not, switch to one of the apps above rather than downgrading the server to an older cipher.
Verify the connection
Connect in your client app, then open a site like WhatIsMyIpAddress. It should show your server’s IP address, not your own. If you use sslocal, you can test from the same computer:
curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me
On the server, journalctl -u shadowsocks-rust -f shows the service log live while you connect.
Final Words
You now have a Shadowsocks server running the 2022 cipher as an unprivileged system service that starts at boot. It is fast, light and simple to share with a few people. It is not invisible to the most aggressive filters, so where censorship is severe, keep a second protocol such as AmneziaWG ready and see our guide to censorship-resistant hosting for the wider picture.

Leave a Reply