How to VPN: Set Up an SSH SOCKS Proxy on Your VPS

Contents

    This article assumes you are already logged into your VPS/Dedicated Server. Don’t have an account with us, feel free to sign up over at our Portal. Once registered check out our selection of VPS and Dedicated Servers.
    Already have one? Then feel free to proceed to follow the how-to guide below.

    How an SSH SOCKS proxy works

    When you connect with ssh -D, SSH opens a small SOCKS proxy on your own computer. Any app you point at that proxy sends its traffic through the encrypted SSH connection to your VPS, and the VPS forwards it to the internet. Only the apps you configure use the tunnel; everything else on your computer goes out as normal.

    It is the quickest private tunnel you can set up, but it has limits. It carries TCP only, so it suits browsing and most apps but not UDP-based calls or games. And SSH is easy for filters to recognise, because every SSH connection starts with a plain-text version banner. On heavily censored networks, use our AmneziaWG or Shadowsocks guides instead.

    Check that the server allows forwarding

    OpenSSH allows TCP forwarding by default, so this usually needs no changes. To confirm, run this on your server:

    sudo sshd -T | grep -i -E "allowtcpforwarding|disableforwarding"

    You want to see allowtcpforwarding yes and disableforwarding no. If either is different, look for AllowTcpForwarding or DisableForwarding in /etc/ssh/sshd_config and in any files under /etc/ssh/sshd_config.d/. After making a change, check the configuration before you restart SSH, because a mistake can stop SSH from coming back and lock you out:

    sudo sshd -t

    If it prints no errors, restart SSH with sudo systemctl restart ssh on Ubuntu and Debian or sudo systemctl restart sshd on AlmaLinux.

    The tunnel itself does not need root. On a Packetra Cloud VPS, log in with the cloud username from your welcome email, as you normally would.

    Start the SSH SOCKS proxy on Linux or macOS

    Run this on your own computer, not on the server. Replace your_user and YOUR_PUBLIC_IP with your login and your server’s IP address.

    ssh -D 127.0.0.1:1080 -N -C your_user@YOUR_PUBLIC_IP
    • -D 127.0.0.1:1080 opens the SOCKS proxy on port 1080, reachable only from your own computer
    • -N connects without opening a remote shell, since you only want the tunnel
    • -C enables SSH compression, which can help on slow connections but makes little difference for web traffic that is already compressed

    After you log in, the terminal looks idle. That is normal: the proxy runs for as long as the window stays open. If your server uses a different SSH port, add -p and the port number.

    Start the SSH SOCKS proxy on Windows

    With PowerShell. Windows 10 (version 1809 and later) and Windows 11 include the OpenSSH client as an optional feature. If ssh is not recognised, add OpenSSH Client under Settings, Optional features. Then run the same command as on Linux:

    ssh -D 127.0.0.1:1080 -N -C your_user@YOUR_PUBLIC_IP

    With PuTTY. Enter your server’s IP address under Session. Go to Connection, SSH, Tunnels, type 1080 as the source port, select Dynamic, click Add, then Open and log in. Save the session first if you want to reuse it.

    Point your browser at the proxy

    Firefox is the easiest, because it has its own proxy settings. Open Settings, scroll to Network Settings and click Settings. Choose Manual proxy configuration, enter 127.0.0.1 as the SOCKS Host and 1080 as the port, select SOCKS v5, and tick Proxy DNS when using SOCKS v5 so your DNS lookups go through the tunnel too.

    Chrome uses the system proxy by default, so the simplest way is to start it with a proxy flag. Close every Chrome window first, or the flag is ignored. With a SOCKS5 proxy, Chrome always resolves hostnames on the proxy side, so DNS goes through the tunnel as well.

    # Windows (PowerShell)
    & "C:\Program Files\Google\Chrome\Application\chrome.exe" --proxy-server="socks5://127.0.0.1:1080"
    
    # macOS
    open -na "Google Chrome" --args --proxy-server="socks5://127.0.0.1:1080"
    
    # Linux
    google-chrome --proxy-server="socks5://127.0.0.1:1080"

    Verify it works

    In the browser you configured, open a site like WhatIsMyIpAddress. It should show your server’s IP address, not your own. From a terminal, you can test without a browser:

    curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me

    Keep the tunnel running

    On Linux and macOS, this version runs in the background and sends a keepalive every 30 seconds, so a dead connection is noticed and closed instead of hanging. It also exits with an error if it cannot open the proxy, for example because port 1080 is already in use, so you never think it is running when it is not:

    ssh -f -N -C -D 127.0.0.1:1080 -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 your_user@YOUR_PUBLIC_IP
    
    # To stop it later
    pkill -f "D 127.0.0.1:1080"

    If you want the tunnel to reconnect by itself after a network drop, the autossh tool can restart SSH automatically.

    Use an SSH key instead of a password

    If you use the tunnel often, log in with a key. It is safer than a password and you will not be asked to type one every time. On Linux and macOS:

    ssh-keygen -t ed25519
    ssh-copy-id your_user@YOUR_PUBLIC_IP

    Final Words

    You now have an SSH SOCKS proxy that takes one command to start and needs nothing installed on your server. It is ideal for private browsing on public Wi-Fi or for reaching sites as if you were in your server’s country. For a tunnel that covers your whole device, or one built to get past censorship, use AmneziaWG or Shadowsocks, and see our guide to censorship-resistant hosting for the wider picture.

    Frequently Asked Questions

    Is an SSH SOCKS proxy the same as a VPN?
    No. A VPN carries all of your device’s traffic, while an SSH SOCKS proxy only carries traffic from the apps you point at it, and only TCP. For many people that is enough, and it needs no software on the server.

    Does it hide my DNS lookups?
    Only if the app sends them through the proxy. In Firefox, tick Proxy DNS when using SOCKS v5. Chrome does this automatically with a SOCKS5 proxy. For command-line tools, use options like curl’s --socks5-hostname.

    Will it work against censorship?
    On lightly filtered networks, often yes. On heavily filtered ones, SSH tunnels are easy to recognise and can be slowed or blocked, so use AmneziaWG or Shadowsocks there.

    Why does it sometimes feel slow?
    All traffic shares one SSH connection over TCP, so a lossy network or a large download can slow everything else in the tunnel. For heavy use, a full tunnel such as AmneziaWG performs better.

    Good to Know
    Keep the proxy bound to 127.0.0.1 as shown. The proxy runs on your own computer, and binding it to 0.0.0.0 or another non-loopback address could let other devices that can reach your computer use your SSH tunnel. Anyone who can log in to your server can also open a tunnel through it, so protect your SSH login with a key and a strong passphrase. Run into any issues? Open a support ticket through the client portal and our team will help you.

    Updated on October 6, 2026
    Was this article helpful?

    Leave a Reply

    Your email address will not be published. Required fields are marked *