Skip to content
Article / 6 min read

SOCKS5 Configurator for Linux: proxychains, redsocks, and Per-App Routing

Linux doesn't have a single SOCKS5 switch, but you can route per-app with proxychains, transparently with redsocks, or via environment variables. Here's how to configure each, verify DNS, and avoid leaks.

Searching for a "SOCKS5 configurator" on Linux often leads to confusion: there is no system-wide SOCKS5 toggle in GNOME or KDE like there is for HTTP proxies. Instead, Linux gives you flexible building blocks. This guide covers the practical ways to route traffic through a SOCKS5 proxy on Linux—per-app, transparently, and for specific CLI tools—with code you can adapt.

How SOCKS5 Works on Linux (and Why DNS Matters)

SOCKS5 is a generic proxy protocol that can handle TCP connections (and UDP with some extensions, but most implementations stick to TCP). On Linux, the key distinction is between socks5 and socks5h:

  • socks5:// resolves DNS locally on your machine, then sends the IP to the proxy.
  • socks5h:// sends the hostname to the proxy, which resolves it remotely.

For geo-restricted content or avoiding DNS leaks, socks5h is usually the right choice. If your proxy provider gives you a SOCKS5 endpoint, you can often force remote DNS by using the h variant or a setting like "Proxy DNS when using SOCKS v5" in Firefox.

Per-App Routing with proxychains

proxychains-ng is the maintained fork of the classic proxychains tool. It uses LD_PRELOAD to intercept network calls from dynamically linked programs and route them through your proxy. It is the closest Linux equivalent to Proxifier on Windows or macOS, though it works differently under the hood.

Install it on Debian/Ubuntu:

sudo apt install proxychains4

On Arch:

sudo pacman -S proxychains-ng

Edit the configuration file (usually /etc/proxychains4.conf or ~/.proxychains/proxychains.conf). At the end, define your proxy:

[ProxyList]
socks5 127.0.0.1 1080

If your proxy requires authentication:

socks5 203.0.113.10 1080 username password

To route DNS through the proxy, keep the proxy_dns line uncommented in the config. This makes proxychains use remote DNS, similar to socks5h.

Run any command through the proxy:

proxychains4 curl https://ifconfig.me
proxychains4 firefox

Note: proxychains does not work with statically linked binaries, setuid binaries, or applications that make raw socket calls. It also does not proxy UDP traffic by default. For those cases, consider the transparent proxy approach below.

Transparent Proxy with redsocks

If you want to route all TCP traffic (or specific ports) through a SOCKS5 proxy without per-app configuration, redsocks can redirect connections at the kernel level. This is more complex and can break your network if misconfigured, so proceed with caution.

Install redsocks:

sudo apt install redsocks

Create a configuration file, for example /etc/redsocks.conf:

redsocks {
    local_ip = 127.0.0.1;
    local_port = 12345;
    ip = 203.0.113.10;
    port = 1080;
    type = socks5;
    login = "username";
    password = "password";
}

Then use iptables to redirect outgoing TCP traffic to the local redsocks port. For example, to redirect all TCP traffic except local networks:

sudo iptables -t nat -N REDSOCKS
sudo iptables -t nat -A REDSOCKS -d 0.0.0.0/8 -j RETURN
sudo iptables -t nat -A REDSOCKS -d 10.0.0.0/8 -j RETURN
sudo iptables -t nat -A REDSOCKS -d 127.0.0.0/8 -j RETURN
sudo iptables -t nat -A REDSOCKS -d 169.254.0.0/16 -j RETURN
sudo iptables -t nat -A REDSOCKS -d 172.16.0.0/12 -j RETURN
sudo iptables -t nat -A REDSOCKS -d 192.168.0.0/16 -j RETURN
sudo iptables -t nat -A REDSOCKS -p tcp -j REDIRECT --to-ports 12345
sudo iptables -t nat -A OUTPUT -p tcp -j REDSOCKS

This setup redirects outbound TCP from the local machine. Adjust the rules to match your needs (e.g., exclude certain users or destinations). Remember that DNS is often UDP; redsocks can handle TCP DNS, but you may need additional configuration for UDP. Many users combine redsocks with a local DNS resolver like dnscrypt-proxy or unbound to avoid leaks.

Environment Variables and CLI Tools

Many command-line tools respect environment variables such as http_proxy, https_proxy, and all_proxy. For SOCKS5, the most reliable is all_proxy with the socks5h scheme:

export all_proxy=socks5h://127.0.0.1:1080
curl https://ifconfig.me

Some tools also honor http_proxy and https_proxy with a socks5:// URL, but support varies. For specific tools, configure them directly:

  • curl: use --socks5-hostname 127.0.0.1:1080 (equivalent to socks5h).
  • git: git config --global http.proxy socks5h://127.0.0.1:1080
  • SSH: use dynamic forwarding to create a local SOCKS proxy: ssh -D 1080 -N user@remote-host. Then point other tools to 127.0.0.1:1080.

Browser Configuration on Linux

Firefox has excellent SOCKS5 support. Go to Settings → Network Settings → Manual proxy configuration, set the SOCKS Host to 127.0.0.1 and Port to 1080, choose SOCKS v5, and check "Proxy DNS when using SOCKS v5". This makes Firefox use remote DNS.

Chrome and Chromium on Linux can be launched with a proxy flag:

google-chrome --proxy-server="socks5://127.0.0.1:1080"

However, this does not proxy DNS by default. Chrome will resolve hostnames locally, which can leak DNS. To force remote DNS, you can use --host-resolver-rules or a proxy extension that handles SOCKS5 with remote DNS. Alternatively, use a system-wide transparent proxy like redsocks to avoid per-browser flags.

Verifying Your Setup and Checking for Leaks

After configuring, always verify that traffic is going through the proxy and that DNS is not leaking. Quick checks:

  • Apparent IP: curl https://ifconfig.me or curl https://ipinfo.io/ip. (If using proxychains, prefix with proxychains4.)
  • DNS leak test: visit a site like dnsleaktest.com in your browser and check whether the DNS servers belong to your ISP or your proxy provider.
  • WebRTC leaks: in browsers, WebRTC can reveal your real IP. Disable WebRTC or use an extension to block it if needed.
  • Terminal DNS check: dig +short example.com will use your system resolver unless you've configured proxychains or a local DNS forwarder. To see if DNS is proxied, compare results with and without the proxy.

Common Pitfalls and How to Avoid Them

  • Using socks5:// when you need socks5h://: This is the most common cause of DNS leaks. If your tool supports it, always use the h variant.
  • Assuming all apps honor proxychains: Statically linked binaries and some sandboxed apps bypass LD_PRELOAD. Test each app you need.
  • Forgetting about UDP and QUIC: SOCKS5 proxies typically only handle TCP. QUIC (used by HTTP/3) runs over UDP and may bypass your proxy. Disable QUIC in your browser if you need absolute consistency.
  • IPv6 leaks: If your proxy only supports IPv4, IPv6 traffic may go out directly. Disable IPv6 or route it through the proxy if supported.
  • Transparent proxy loops: With redsocks, be careful not to redirect traffic that the proxy itself needs (e.g., traffic to the proxy server's IP). Use exclusion rules.

Closing Takeaway

Linux doesn't offer a one-click SOCKS5 configurator, but that's a feature, not a bug. You can choose per-app routing with proxychains, transparent redirection with redsocks, or simple environment variables for CLI tools. Pick the method that matches your workflow, then verify DNS and leaks before trusting it with sensitive traffic.