Dante SOCKS Proxy: Installation and Configuration
Dante SOCKS Proxy is a flexible SOCKS server that allows network clients to connect to hosts through a firewall. It supports SOCKS version 4, 5, and client authentication. Using a SOCKS proxy can enhance privacy, bypass network restrictions, or facilitate internal network access from specific points.
1. Installation
Dante server is available in the default repositories of most Debian-based Linux distributions.
sudo apt update
sudo apt install dante-server2. Configuration (danted.conf)
The main configuration file for Dante is /etc/danted.conf. It defines the proxy’s network interfaces, authentication methods, and access rules.
Backup Existing Configuration
Before making changes, it’s always a good idea to back up the original configuration file.
sudo mv /etc/danted.conf /etc/danted.conf.bakEdit the Configuration File
Open the configuration file for editing.
sudo vim /etc/danted.conf
# Or use your preferred text editor:
# sudo nano /etc/danted.confExample danted.conf Configuration
Below is an example configuration for a basic SOCKS5 proxy allowing unauthenticated access from any source.
# Log output configuration
logoutput: /var/log/socks.log
# Internal interface and port where Dante listens for client connections
internal: <internal_interface> port = <listen_port>
# Example: internal: ens3 port = 50080
# External interface through which Dante forwards client requests
external: <external_interface>
# Example: external: ens3
# Client authentication method (none means no authentication)
clientmethod: none
# SOCKS authentication method (none means no authentication)
socksmethod: none
# User context for privileged operations (usually root)
user.privileged: root
# User context for unprivileged operations
user.notprivileged: nobody
# Client access rules: who is allowed to connect to Dante
# This rule allows all clients (0.0.0.0/0) to connect to any destination (0.0.0.0/0)
client pass {
from: 0.0.0.0/0 to: 0.0.0.0/0
log: error connect disconnect
}
# Client block rules: explicitly deny clients (optional)
client block {
from: 0.0.0.0/0 to: 0.0.0.0/0
log: connect error
}
# SOCKS access rules: what clients are allowed to do through Dante
# This rule allows all SOCKS connections from any source to any destination
socks pass {
from: 0.0.0.0/0 to: 0.0.0.0/0
log: error connect disconnect
}
# SOCKS block rules: explicitly deny SOCKS requests (optional)
socks block {
from: 0.0.0.0/0 to: 0.0.0.0/0
log: connect error
}- Replace
<internal_interface>and<external_interface>with your server’s actual network interface names (e.g.,eth0,ens3). - Replace
<listen_port>with the port Dante should listen on (e.g.,1080,50080).
3. Service Management
After modifying the configuration file, you need to restart the Dante service for the changes to take effect.
Check Service Status
sudo systemctl status dantedRestart Service
sudo systemctl restart dantedEnable Service on Boot
sudo systemctl enable danted4. Testing the SOCKS Proxy
You can test your SOCKS proxy using tools like curl.
curl --socks5 <proxy_ip>:<listen_port> http://ipecho.net/plain
# Example:
curl --socks5 192.168.1.10:50080 http://ipecho.net/plainThis command should return the public IP address of your Dante proxy server, indicating that the traffic is routed through it.
Security Warning: An unauthenticated SOCKS proxy accessible from the internet can be abused by attackers. Always configure strong authentication (clientmethod: username none and socksmethod: username) and strict access rules (client pass { from: ... }) to limit who can use your proxy.