// Engineering Log
Proxy Servers: Part 4 — Dante
Published on 2026-09-21
Dante — a free SOCKS proxy server from Inferno Nettverk. It implements the SOCKS4, SOCKS4a and SOCKS5 protocols (RFC 1928) and is distributed under the BSD/CMU license. The latest version is 1.4.4, released in December 2024. In Debian and Ubuntu the server is installed from the dante-server package, the service itself is called danted.
How SOCKS differs from an HTTP proxy
An HTTP proxy parses HTTP protocol requests: it sees the page address, headers, can cache responses and filter content. A SOCKS proxy operates at a lower level: the client asks it to connect to a given address and port, after which the proxy simply forwards bytes in both directions without inspecting their meaning. Therefore any TCP traffic can be passed through SOCKS — SSH, mail protocols, databases, messengers — and SOCKS5 also supports UDP.
Protocol versions differ in capabilities:
- SOCKS4 — TCP only, no password authentication, destination is given as an IP address;
- SOCKS4a — same, but allows passing a hostname to be resolved by the proxy;
- SOCKS5 — TCP and UDP, IPv6, username/password authentication.
What Dante is used for
- Single egress point. Application traffic from an internal network goes to the Internet through one server, from a single address and under a single set of rules.
- Access to resources with IP whitelists. If an external service accepts only from a specific address, run Dante on a machine with that address.
- Egress through another server or another country. The destination server sees the proxy address, not the client. This is used for checking regional versions of sites and working with services accessible only from certain countries.
- Access control. Dante rules define which addresses can connect to the proxy and where traffic through it is allowed to go.
- Proxying all traffic of a system or container. Applications that don’t support SOCKS natively can be sent through a proxy using tun2socks — described in the articles for a container and for the whole system.
Installation
On Debian and Ubuntu:
sudo apt update
sudo apt install dante-serverConfiguration is located in /etc/danted.conf. Immediately after installation the service may not start — the default file doesn’t specify interfaces. That’s normal: you need to write the configuration first.
Working configuration with password
Below is a SOCKS5 proxy configuration that accepts connections on port 1080 and allows only users with a password. Replace the external interface name (eth0) with yours — it is shown by ip -br addr.
logoutput: syslog
internal: eth0 port = 1080
external: eth0
clientmethod: none
socksmethod: username
user.privileged: root
user.notprivileged: nobody
client pass {
from: 0.0.0.0/0 to: 0.0.0.0/0
log: error connect disconnect
}
socks pass {
from: 0.0.0.0/0 to: 0.0.0.0/0
command: bind connect udpassociate
log: error connect disconnect
}What’s happening here:
internal— the address and port on which Dante accepts client connections;external— the interface from which the proxy establishes connections to target servers;clientmethod— check at the TCP connection level, before the SOCKS session begins;nonemeans nothing is checked at this stage;socksmethod: username— username and password check within SOCKS5. Dante verifies them against the system user database, so it needs root privileges to read the passwords at startup (user.privileged), while doing the main work as an unprivileged user (user.notprivileged);client pass— who is allowed to connect to the proxy;socks pass— which SOCKS commands and to where are allowed:connect— normal TCP connection,bind— incoming connections (needed, for example, for active FTP),udpassociate— UDP association.
Rules are checked top to bottom; the first matching one applies. If none match, access is denied.
A proxy user is created as a regular system account without login shell:
sudo useradd -r -M -s /usr/sbin/nologin proxyuser
sudo passwd proxyuserStart and check:
sudo systemctl restart danted
sudo systemctl status danted
curl -x socks5h://proxyuser:PASSWORD@192.0.2.10:1080 https://ifconfig.meThe socks5h prefix means the site name is resolved by the proxy, not the client. The command should output the external address of the server running Dante.
Client connections
- Browser. In Firefox a SOCKS proxy is set in Network settings: host, port 1080, SOCKS v5 type and the checkbox “Proxy DNS when using SOCKS v5” (send DNS through the proxy). Chromium and Chromium-based browsers use system settings or the launch parameter
--proxy-server="socks5://192.0.2.10:1080"; they don’t support passwords for SOCKS, so for them the proxy is usually limited by source addresses. - Console programs. Many utilities, including curl, understand the environment variable
ALL_PROXY=socks5h://proxyuser:PASSWORD@192.0.2.10:1080. - SSH. Connecting to a server through a SOCKS proxy is set in
~/.ssh/configwithProxyCommand nc -X 5 -x 192.0.2.10:1080 %h %p(requires OpenBSD netcat). This method does not transmit a password, so it’s suitable for proxies restricted by source addresses. - Applications without proxy support are directed to SOCKS via tun2socks or proxychains.
Restricting access by address
If the proxy is needed only for office employees or only for your other servers, restrict the source in client pass:
client pass {
from: 198.51.100.0/24 to: 0.0.0.0/0
log: error
}You can also forbid access to internal networks in socks pass so that the proxy cannot be used to reach your internal infrastructure. A blocking rule should be placed above an allowing rule:
socks block {
from: 0.0.0.0/0 to: 10.0.0.0/8
log: connect error
}Common mistakes
- Open proxy. A configuration without a password and with
from: 0.0.0.0/0is quickly found by scanners and used to send spam and launch attacks from your address. Either enablesocksmethod: username, or restrict sources by address — preferably both. - Password transmitted in clear text. That’s how SOCKS5 works: username and password go over the network unencrypted. Dante’s documentation warns about this explicitly. If clients connect over the Internet, run SOCKS inside an SSH tunnel or WireGuard.
- Wrong external interface. If
externalpoints to an interface without Internet access, the client connects to the proxy but further connections cannot be established. - Port closed in the firewall. You need to open TCP port 1080, and for
udpassociatealso the UDP ports through which Dante sends datagrams. - Client uses SOCKS4. SOCKS4 has no password authentication, so with
socksmethod: usernamesuch clients will be denied. - Configuration errors. After editing it’s useful to check the journal:
journalctl -u danted -n 50. Dante reports the line number with the error.
Advantages and limitations
Advantages:
- proxies any TCP and UDP traffic, not only web;
- low resource usage and runs even on the smallest VPS;
- flexible access rules by address, users and SOCKS commands;
- long history and stable operation;
- free license, packages in major distributions.
Limitations:
- no HTTP-proxy features: caching, filtering by page URLs, TLS termination — for that you need Squid or Nginx;
- SOCKS5 password is not encrypted, protect the channel separately;
- configuration only via a text file, no GUI;
- no built-in per-user traffic accounting — only connection logs.
When to choose Dante
Dante is suitable when you need a reliable SOCKS5 proxy with authentication and clear access rules — for applications that need egress via a specific address, for access to services with IP whitelists, or for directing container traffic via tun2socks. If you need an HTTP proxy, traffic accounting and per-user limits in one program, 3proxy may be more convenient; if you need web traffic filtering and reports on visited sites — Squid.
// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related