Dante SOCKS Proxy: Installation and Configuration

Dante SOCKS Proxy is a flexible SOCKS server that allows network clients to connect to hosts through a firewall. It supports SOCKS version 4, 5, and client authentication. Using a SOCKS proxy can enhance privacy, bypass network restrictions, or facilitate internal network access from specific points.

1. Installation

Dante server is available in the default repositories of most Debian-based Linux distributions.

sudo apt update
sudo apt install dante-server

2. Configuration (danted.conf)

The main configuration file for Dante is /etc/danted.conf. It defines the proxy’s network interfaces, authentication methods, and access rules.

Backup Existing Configuration

Before making changes, it’s always a good idea to back up the original configuration file.

sudo mv /etc/danted.conf /etc/danted.conf.bak

Edit the Configuration File

Open the configuration file for editing.

sudo vim /etc/danted.conf
# Or use your preferred text editor:
# sudo nano /etc/danted.conf

Example danted.conf Configuration

Below is an example configuration for a basic SOCKS5 proxy allowing unauthenticated access from any source.

# Log output configuration
logoutput: /var/log/socks.log
 
# Internal interface and port where Dante listens for client connections
internal: <internal_interface> port = <listen_port>
# Example: internal: ens3 port = 50080
 
# External interface through which Dante forwards client requests
external: <external_interface>
# Example: external: ens3
 
# Client authentication method (none means no authentication)
clientmethod: none
 
# SOCKS authentication method (none means no authentication)
socksmethod: none
 
# User context for privileged operations (usually root)
user.privileged: root
# User context for unprivileged operations
user.notprivileged: nobody
 
# Client access rules: who is allowed to connect to Dante
# This rule allows all clients (0.0.0.0/0) to connect to any destination (0.0.0.0/0)
client pass {
        from: 0.0.0.0/0 to: 0.0.0.0/0
        log: error connect disconnect
}
# Client block rules: explicitly deny clients (optional)
client block {
        from: 0.0.0.0/0 to: 0.0.0.0/0
        log: connect error
}
 
# SOCKS access rules: what clients are allowed to do through Dante
# This rule allows all SOCKS connections from any source to any destination
socks pass {
        from: 0.0.0.0/0 to: 0.0.0.0/0
        log: error connect disconnect
}
# SOCKS block rules: explicitly deny SOCKS requests (optional)
socks block {
        from: 0.0.0.0/0 to: 0.0.0.0/0
        log: connect error
}
  • Replace <internal_interface> and <external_interface> with your server’s actual network interface names (e.g., eth0, ens3).
  • Replace <listen_port> with the port Dante should listen on (e.g., 1080, 50080).

3. Service Management

After modifying the configuration file, you need to restart the Dante service for the changes to take effect.

Check Service Status

sudo systemctl status danted

Restart Service

sudo systemctl restart danted

Enable Service on Boot

sudo systemctl enable danted

4. Testing the SOCKS Proxy

You can test your SOCKS proxy using tools like curl.

curl --socks5 <proxy_ip>:<listen_port> http://ipecho.net/plain
# Example:
curl --socks5 192.168.1.10:50080 http://ipecho.net/plain

This command should return the public IP address of your Dante proxy server, indicating that the traffic is routed through it.


Security Warning: An unauthenticated SOCKS proxy accessible from the internet can be abused by attackers. Always configure strong authentication (clientmethod: username none and socksmethod: username) and strict access rules (client pass { from: ... }) to limit who can use your proxy.