{"id":572,"date":"2026-10-06T21:08:28","date_gmt":"2026-10-06T21:08:28","guid":{"rendered":"https:\/\/packetra.com\/knowledgebase\/?post_type=ht_kb&#038;p=572"},"modified":"2026-10-06T21:08:30","modified_gmt":"2026-10-06T21:08:30","slug":"how-to-vpn-ssh-socks-proxy","status":"publish","type":"ht_kb","link":"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-ssh-socks-proxy\/","title":{"rendered":"How to VPN: Set Up an SSH SOCKS Proxy on Your VPS"},"content":{"rendered":"\n<p class=\"has-primary-color has-text-color has-link-color has-small-font-size wp-elements-1 wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#9c9c9c\" class=\"has-inline-color\">An SSH SOCKS proxy sends your browser&#8217;s traffic through an encrypted SSH connection to your server, so websites see your server&#8217;s IP address instead of yours. It needs nothing installed on the server, works with the login you already have, and takes about five minutes.<\/mark><\/p>\n\n\n\n<p class=\"wp-block-ht-blocks-messages wp-block-hb-message wp-block-hb-message--withicon is-style-alert\">This article assumes you are already logged into your VPS\/Dedicated Server. Don&#8217;t have an account with us, feel free to sign up over at our <a href=\"https:\/\/portal.packetra.com\/register.php\"><strong>Portal<\/strong><\/a>. Once registered check out our selection of <a href=\"https:\/\/packetra.com\/hosting\/cloud-hosting\"><strong>VPS<\/strong><\/a> and <a href=\"https:\/\/packetra.com\/hosting\/dedicated-hosting\"><strong>Dedicated Servers<\/strong><\/a>. <br>Already have one? Then feel free to proceed to follow the how-to guide below.<\/p>\n\n\n\n<h3 class=\"wp-block-heading step-heading\">How an SSH SOCKS proxy works<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When you connect with <code>ssh -D<\/code>, SSH opens a small SOCKS proxy on your own computer. Any app you point at that proxy sends its traffic through the encrypted SSH connection to your VPS, and the VPS forwards it to the internet. Only the apps you configure use the tunnel; everything else on your computer goes out as normal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is the quickest private tunnel you can set up, but it has limits. It carries TCP only, so it suits browsing and most apps but not UDP-based calls or games. And SSH is easy for filters to recognise, because every SSH connection starts with a plain-text version banner. On heavily censored networks, use our <a href=\"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-setup-amneziawg-censorship-resistant-wireguard-tunnel\/\"><strong>AmneziaWG<\/strong><\/a> or <a href=\"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-setup-shadowsocks-server\/\"><strong>Shadowsocks<\/strong><\/a> guides instead.<\/p>\n\n\n\n<h3 class=\"wp-block-heading step-heading\">Check that the server allows forwarding<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">OpenSSH allows TCP forwarding by default, so this usually needs no changes. To confirm, run this on your server:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo sshd -T | grep -i -E \"allowtcpforwarding|disableforwarding\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You want to see <strong>allowtcpforwarding yes<\/strong> and <strong>disableforwarding no<\/strong>. If either is different, look for <code>AllowTcpForwarding<\/code> or <code>DisableForwarding<\/code> in <code>\/etc\/ssh\/sshd_config<\/code> and in any files under <code>\/etc\/ssh\/sshd_config.d\/<\/code>. After making a change, check the configuration before you restart SSH, because a mistake can stop SSH from coming back and lock you out:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo sshd -t<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If it prints no errors, restart SSH with <code>sudo systemctl restart ssh<\/code> on Ubuntu and Debian or <code>sudo systemctl restart sshd<\/code> on AlmaLinux.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The tunnel itself does not need root. On a Packetra Cloud VPS, log in with the cloud username from your welcome email, as you normally would.<\/p>\n\n\n\n<h3 class=\"wp-block-heading step-heading\">Start the SSH SOCKS proxy on Linux or macOS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Run this on your own computer, not on the server. Replace <strong>your_user<\/strong> and <strong>YOUR_PUBLIC_IP<\/strong> with your login and your server&#8217;s IP address.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ssh -D 127.0.0.1:1080 -N -C your_user@YOUR_PUBLIC_IP<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>-D 127.0.0.1:1080<\/strong> opens the SOCKS proxy on port 1080, reachable only from your own computer<\/li>\n\n\n\n<li><strong>-N<\/strong> connects without opening a remote shell, since you only want the tunnel<\/li>\n\n\n\n<li><strong>-C<\/strong> enables SSH compression, which can help on slow connections but makes little difference for web traffic that is already compressed<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">After you log in, the terminal looks idle. That is normal: the proxy runs for as long as the window stays open. If your server uses a different SSH port, add <code>-p<\/code> and the port number.<\/p>\n\n\n\n<h3 class=\"wp-block-heading step-heading\">Start the SSH SOCKS proxy on Windows<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>With PowerShell.<\/strong> Windows 10 (version 1809 and later) and Windows 11 include the OpenSSH client as an optional feature. If <code>ssh<\/code> is not recognised, add <strong>OpenSSH Client<\/strong> under Settings, Optional features. Then run the same command as on Linux:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ssh -D 127.0.0.1:1080 -N -C your_user@YOUR_PUBLIC_IP<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>With PuTTY.<\/strong> Enter your server&#8217;s IP address under <strong>Session<\/strong>. Go to <strong>Connection<\/strong>, <strong>SSH<\/strong>, <strong>Tunnels<\/strong>, type <strong>1080<\/strong> as the source port, select <strong>Dynamic<\/strong>, click <strong>Add<\/strong>, then <strong>Open<\/strong> and log in. Save the session first if you want to reuse it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading step-heading\">Point your browser at the proxy<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Firefox<\/strong> is the easiest, because it has its own proxy settings. Open <strong>Settings<\/strong>, scroll to <strong>Network Settings<\/strong> and click <strong>Settings<\/strong>. Choose <strong>Manual proxy configuration<\/strong>, enter <strong>127.0.0.1<\/strong> as the SOCKS Host and <strong>1080<\/strong> as the port, select <strong>SOCKS v5<\/strong>, and tick <strong>Proxy DNS when using SOCKS v5<\/strong> so your DNS lookups go through the tunnel too.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Chrome<\/strong> uses the system proxy by default, so the simplest way is to start it with a proxy flag. Close every Chrome window first, or the flag is ignored. With a SOCKS5 proxy, Chrome always resolves hostnames on the proxy side, so DNS goes through the tunnel as well.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Windows (PowerShell)\n&amp; \"C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe\" --proxy-server=\"socks5:\/\/127.0.0.1:1080\"\n\n# macOS\nopen -na \"Google Chrome\" --args --proxy-server=\"socks5:\/\/127.0.0.1:1080\"\n\n# Linux\ngoogle-chrome --proxy-server=\"socks5:\/\/127.0.0.1:1080\"<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading step-heading\">Verify it works<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In the browser you configured, open a site like <a href=\"https:\/\/whatismyipaddress.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>WhatIsMyIpAddress<\/strong><\/a>. It should show your server&#8217;s IP address, not your own. From a terminal, you can test without a browser:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>curl --socks5-hostname 127.0.0.1:1080 https:\/\/ifconfig.me<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading step-heading\">Keep the tunnel running<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On Linux and macOS, this version runs in the background and sends a keepalive every 30 seconds, so a dead connection is noticed and closed instead of hanging. It also exits with an error if it cannot open the proxy, for example because port 1080 is already in use, so you never think it is running when it is not:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ssh -f -N -C -D 127.0.0.1:1080 -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 your_user@YOUR_PUBLIC_IP\n\n# To stop it later\npkill -f \"D 127.0.0.1:1080\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If you want the tunnel to reconnect by itself after a network drop, the <strong>autossh<\/strong> tool can restart SSH automatically.<\/p>\n\n\n\n<h3 class=\"wp-block-heading step-heading\">Use an SSH key instead of a password<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you use the tunnel often, log in with a key. It is safer than a password and you will not be asked to type one every time. On Linux and macOS:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ssh-keygen -t ed25519\nssh-copy-id your_user@YOUR_PUBLIC_IP<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading step-heading\">Final Words<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You now have an SSH SOCKS proxy that takes one command to start and needs nothing installed on your server. It is ideal for private browsing on public Wi-Fi or for reaching sites as if you were in your server&#8217;s country. For a tunnel that covers your whole device, or one built to get past censorship, use AmneziaWG or Shadowsocks, and see our guide to <a href=\"https:\/\/packetra.com\/articles\/censorship-resistant-hosting\"><strong>censorship-resistant hosting<\/strong><\/a> for the wider picture.<\/p>\n\n\n\n<p class=\"wp-block-ht-blocks-messages wp-block-hb-message wp-block-hb-message--withicon is-style-info\"><strong>Frequently Asked Questions<\/strong><br><br><strong>Is an SSH SOCKS proxy the same as a VPN?<\/strong><br>No. A VPN carries all of your device&#8217;s traffic, while an SSH SOCKS proxy only carries traffic from the apps you point at it, and only TCP. For many people that is enough, and it needs no software on the server.<br><br><strong>Does it hide my DNS lookups?<\/strong><br>Only if the app sends them through the proxy. In Firefox, tick Proxy DNS when using SOCKS v5. Chrome does this automatically with a SOCKS5 proxy. For command-line tools, use options like curl&#8217;s <code>--socks5-hostname<\/code>.<br><br><strong>Will it work against censorship?<\/strong><br>On lightly filtered networks, often yes. On heavily filtered ones, SSH tunnels are easy to recognise and can be slowed or blocked, so use AmneziaWG or Shadowsocks there.<br><br><strong>Why does it sometimes feel slow?<\/strong><br>All traffic shares one SSH connection over TCP, so a lossy network or a large download can slow everything else in the tunnel. For heavy use, a full tunnel such as AmneziaWG performs better.<\/p>\n\n\n\n<p class=\"wp-block-ht-blocks-messages wp-block-hb-message wp-block-hb-message--withicon is-style-success\"><strong>Good to Know<\/strong><br>Keep the proxy bound to 127.0.0.1 as shown. The proxy runs on your own computer, and binding it to 0.0.0.0 or another non-loopback address could let other devices that can reach your computer use your SSH tunnel. Anyone who can log in to your server can also open a tunnel through it, so protect your SSH login with a key and a strong passphrase. Run into any issues? Open a support ticket through the <a href=\"https:\/\/portal.packetra.com\/submitticket.php\"><strong>client portal<\/strong><\/a> and our team will help you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An SSH SOCKS proxy sends your browser&#8217;s traffic through an encrypted SSH connection to your server, so websites see your server&#8217;s IP address instead of yours. It needs nothing installed on the server, works with the login you already have, and takes about five minutes. How an SSH SOCKS proxy&#8230;<\/p>\n","protected":false},"author":1,"comment_status":"open","ping_status":"closed","template":"","format":"standard","meta":{"footnotes":""},"ht-kb-category":[72],"ht-kb-tag":[74,80,79,73],"class_list":["post-572","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-vpn-privacy","ht_kb_tag-privacy","ht_kb_tag-socks-proxy","ht_kb_tag-ssh","ht_kb_tag-vpn"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SSH SOCKS Proxy: Tunnel Your Browser Through a VPS<\/title>\n<meta name=\"description\" content=\"Set up an SSH SOCKS proxy with one command: tunnel your browser through your VPS on Windows, macOS or Linux, with DNS and keepalive tips.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-ssh-socks-proxy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SSH SOCKS Proxy: Tunnel Your Browser Through a VPS\" \/>\n<meta property=\"og:description\" content=\"Set up an SSH SOCKS proxy with one command: tunnel your browser through your VPS on Windows, macOS or Linux, with DNS and keepalive tips.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-ssh-socks-proxy\/\" \/>\n<meta property=\"og:site_name\" content=\"Packetra Knowledgebase\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-06T21:08:30+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/kb\\\/how-to-vpn-ssh-socks-proxy\\\/\",\"url\":\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/kb\\\/how-to-vpn-ssh-socks-proxy\\\/\",\"name\":\"SSH SOCKS Proxy: Tunnel Your Browser Through a VPS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/#website\"},\"datePublished\":\"2026-10-06T21:08:28+00:00\",\"dateModified\":\"2026-10-06T21:08:30+00:00\",\"description\":\"Set up an SSH SOCKS proxy with one command: tunnel your browser through your VPS on Windows, macOS or Linux, with DNS and keepalive tips.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/kb\\\/how-to-vpn-ssh-socks-proxy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/kb\\\/how-to-vpn-ssh-socks-proxy\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/kb\\\/how-to-vpn-ssh-socks-proxy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Articles\",\"item\":\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/kb\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"How to VPN: Set Up an SSH SOCKS Proxy on Your VPS\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/#website\",\"url\":\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/\",\"name\":\"Packetra Knowledgebase\",\"description\":\"Hosting Guides, VPS Help &amp; Support\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/packetra.com\\\/knowledgebase\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SSH SOCKS Proxy: Tunnel Your Browser Through a VPS","description":"Set up an SSH SOCKS proxy with one command: tunnel your browser through your VPS on Windows, macOS or Linux, with DNS and keepalive tips.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-ssh-socks-proxy\/","og_locale":"en_US","og_type":"article","og_title":"SSH SOCKS Proxy: Tunnel Your Browser Through a VPS","og_description":"Set up an SSH SOCKS proxy with one command: tunnel your browser through your VPS on Windows, macOS or Linux, with DNS and keepalive tips.","og_url":"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-ssh-socks-proxy\/","og_site_name":"Packetra Knowledgebase","article_modified_time":"2026-10-06T21:08:30+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-ssh-socks-proxy\/","url":"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-ssh-socks-proxy\/","name":"SSH SOCKS Proxy: Tunnel Your Browser Through a VPS","isPartOf":{"@id":"https:\/\/packetra.com\/knowledgebase\/#website"},"datePublished":"2026-10-06T21:08:28+00:00","dateModified":"2026-10-06T21:08:30+00:00","description":"Set up an SSH SOCKS proxy with one command: tunnel your browser through your VPS on Windows, macOS or Linux, with DNS and keepalive tips.","breadcrumb":{"@id":"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-ssh-socks-proxy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-ssh-socks-proxy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/packetra.com\/knowledgebase\/kb\/how-to-vpn-ssh-socks-proxy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/packetra.com\/knowledgebase\/"},{"@type":"ListItem","position":2,"name":"Articles","item":"https:\/\/packetra.com\/knowledgebase\/kb\/"},{"@type":"ListItem","position":3,"name":"How to VPN: Set Up an SSH SOCKS Proxy on Your VPS"}]},{"@type":"WebSite","@id":"https:\/\/packetra.com\/knowledgebase\/#website","url":"https:\/\/packetra.com\/knowledgebase\/","name":"Packetra Knowledgebase","description":"Hosting Guides, VPS Help &amp; Support","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/packetra.com\/knowledgebase\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/packetra.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb\/572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/packetra.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/packetra.com\/knowledgebase\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/packetra.com\/knowledgebase\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/packetra.com\/knowledgebase\/wp-json\/wp\/v2\/comments?post=572"}],"version-history":[{"count":1,"href":"https:\/\/packetra.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb\/572\/revisions"}],"predecessor-version":[{"id":573,"href":"https:\/\/packetra.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb\/572\/revisions\/573"}],"wp:attachment":[{"href":"https:\/\/packetra.com\/knowledgebase\/wp-json\/wp\/v2\/media?parent=572"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/packetra.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb-category?post=572"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/packetra.com\/knowledgebase\/wp-json\/wp\/v2\/ht-kb-tag?post=572"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}