An SSH SOCKS proxy sends your browser’s traffic through an encrypted SSH connection to your server, so websites see your server’s IP address instead of yours. It needs nothing installed on the server, works with the login you already have, and takes about five minutes.
How an SSH SOCKS proxy works
When you connect with ssh -D, SSH opens a small SOCKS proxy on your own computer. Any app you point at that proxy sends its traffic through the encrypted SSH connection to your VPS, and the VPS forwards it to the internet. Only the apps you configure use the tunnel; everything else on your computer goes out as normal.
It is the quickest private tunnel you can set up, but it has limits. It carries TCP only, so it suits browsing and most apps but not UDP-based calls or games. And SSH is easy for filters to recognise, because every SSH connection starts with a plain-text version banner. On heavily censored networks, use our AmneziaWG or Shadowsocks guides instead.
Check that the server allows forwarding
OpenSSH allows TCP forwarding by default, so this usually needs no changes. To confirm, run this on your server:
sudo sshd -T | grep -i -E "allowtcpforwarding|disableforwarding"
You want to see allowtcpforwarding yes and disableforwarding no. If either is different, look for AllowTcpForwarding or DisableForwarding in /etc/ssh/sshd_config and in any files under /etc/ssh/sshd_config.d/. After making a change, check the configuration before you restart SSH, because a mistake can stop SSH from coming back and lock you out:
sudo sshd -t
If it prints no errors, restart SSH with sudo systemctl restart ssh on Ubuntu and Debian or sudo systemctl restart sshd on AlmaLinux.
The tunnel itself does not need root. On a Packetra Cloud VPS, log in with the cloud username from your welcome email, as you normally would.
Start the SSH SOCKS proxy on Linux or macOS
Run this on your own computer, not on the server. Replace your_user and YOUR_PUBLIC_IP with your login and your server’s IP address.
ssh -D 127.0.0.1:1080 -N -C your_user@YOUR_PUBLIC_IP
- -D 127.0.0.1:1080 opens the SOCKS proxy on port 1080, reachable only from your own computer
- -N connects without opening a remote shell, since you only want the tunnel
- -C enables SSH compression, which can help on slow connections but makes little difference for web traffic that is already compressed
After you log in, the terminal looks idle. That is normal: the proxy runs for as long as the window stays open. If your server uses a different SSH port, add -p and the port number.
Start the SSH SOCKS proxy on Windows
With PowerShell. Windows 10 (version 1809 and later) and Windows 11 include the OpenSSH client as an optional feature. If ssh is not recognised, add OpenSSH Client under Settings, Optional features. Then run the same command as on Linux:
ssh -D 127.0.0.1:1080 -N -C your_user@YOUR_PUBLIC_IP
With PuTTY. Enter your server’s IP address under Session. Go to Connection, SSH, Tunnels, type 1080 as the source port, select Dynamic, click Add, then Open and log in. Save the session first if you want to reuse it.
Point your browser at the proxy
Firefox is the easiest, because it has its own proxy settings. Open Settings, scroll to Network Settings and click Settings. Choose Manual proxy configuration, enter 127.0.0.1 as the SOCKS Host and 1080 as the port, select SOCKS v5, and tick Proxy DNS when using SOCKS v5 so your DNS lookups go through the tunnel too.
Chrome uses the system proxy by default, so the simplest way is to start it with a proxy flag. Close every Chrome window first, or the flag is ignored. With a SOCKS5 proxy, Chrome always resolves hostnames on the proxy side, so DNS goes through the tunnel as well.
# Windows (PowerShell)
& "C:\Program Files\Google\Chrome\Application\chrome.exe" --proxy-server="socks5://127.0.0.1:1080"
# macOS
open -na "Google Chrome" --args --proxy-server="socks5://127.0.0.1:1080"
# Linux
google-chrome --proxy-server="socks5://127.0.0.1:1080"
Verify it works
In the browser you configured, open a site like WhatIsMyIpAddress. It should show your server’s IP address, not your own. From a terminal, you can test without a browser:
curl --socks5-hostname 127.0.0.1:1080 https://ifconfig.me
Keep the tunnel running
On Linux and macOS, this version runs in the background and sends a keepalive every 30 seconds, so a dead connection is noticed and closed instead of hanging. It also exits with an error if it cannot open the proxy, for example because port 1080 is already in use, so you never think it is running when it is not:
ssh -f -N -C -D 127.0.0.1:1080 -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 your_user@YOUR_PUBLIC_IP
# To stop it later
pkill -f "D 127.0.0.1:1080"
If you want the tunnel to reconnect by itself after a network drop, the autossh tool can restart SSH automatically.
Use an SSH key instead of a password
If you use the tunnel often, log in with a key. It is safer than a password and you will not be asked to type one every time. On Linux and macOS:
ssh-keygen -t ed25519
ssh-copy-id your_user@YOUR_PUBLIC_IP
Final Words
You now have an SSH SOCKS proxy that takes one command to start and needs nothing installed on your server. It is ideal for private browsing on public Wi-Fi or for reaching sites as if you were in your server’s country. For a tunnel that covers your whole device, or one built to get past censorship, use AmneziaWG or Shadowsocks, and see our guide to censorship-resistant hosting for the wider picture.

Leave a Reply