// Engineering Log

Proxy Servers: Part 4 — Dante

Published on 2026-09-21

Dante — a free SOCKS proxy server from Inferno Nettverk. It implements the SOCKS4, SOCKS4a and SOCKS5 protocols (RFC 1928) and is distributed under the BSD/CMU license. The latest version is 1.4.4, released in December 2024. In Debian and Ubuntu the server is installed from the dante-server package, the service itself is called danted.

How SOCKS differs from an HTTP proxy

An HTTP proxy parses HTTP protocol requests: it sees the page address, headers, can cache responses and filter content. A SOCKS proxy operates at a lower level: the client asks it to connect to a given address and port, after which the proxy simply forwards bytes in both directions without inspecting their meaning. Therefore any TCP traffic can be passed through SOCKS — SSH, mail protocols, databases, messengers — and SOCKS5 also supports UDP.

Protocol versions differ in capabilities:

  • SOCKS4 — TCP only, no password authentication, destination is given as an IP address;
  • SOCKS4a — same, but allows passing a hostname to be resolved by the proxy;
  • SOCKS5 — TCP and UDP, IPv6, username/password authentication.

What Dante is used for

  • Single egress point. Application traffic from an internal network goes to the Internet through one server, from a single address and under a single set of rules.
  • Access to resources with IP whitelists. If an external service accepts only from a specific address, run Dante on a machine with that address.
  • Egress through another server or another country. The destination server sees the proxy address, not the client. This is used for checking regional versions of sites and working with services accessible only from certain countries.
  • Access control. Dante rules define which addresses can connect to the proxy and where traffic through it is allowed to go.
  • Proxying all traffic of a system or container. Applications that don’t support SOCKS natively can be sent through a proxy using tun2socks — described in the articles for a container and for the whole system.

Installation

On Debian and Ubuntu:

bash
sudo apt update
sudo apt install dante-server

Configuration is located in /etc/danted.conf. Immediately after installation the service may not start — the default file doesn’t specify interfaces. That’s normal: you need to write the configuration first.

Working configuration with password

Below is a SOCKS5 proxy configuration that accepts connections on port 1080 and allows only users with a password. Replace the external interface name (eth0) with yours — it is shown by ip -br addr.

logoutput: syslog

internal: eth0 port = 1080
external: eth0

clientmethod: none
socksmethod: username

user.privileged: root
user.notprivileged: nobody

client pass {
    from: 0.0.0.0/0 to: 0.0.0.0/0
    log: error connect disconnect
}

socks pass {
    from: 0.0.0.0/0 to: 0.0.0.0/0
    command: bind connect udpassociate
    log: error connect disconnect
}

What’s happening here:

  • internal — the address and port on which Dante accepts client connections;
  • external — the interface from which the proxy establishes connections to target servers;
  • clientmethod — check at the TCP connection level, before the SOCKS session begins; none means nothing is checked at this stage;
  • socksmethod: username — username and password check within SOCKS5. Dante verifies them against the system user database, so it needs root privileges to read the passwords at startup (user.privileged), while doing the main work as an unprivileged user (user.notprivileged);
  • client pass — who is allowed to connect to the proxy;
  • socks pass — which SOCKS commands and to where are allowed: connect — normal TCP connection, bind — incoming connections (needed, for example, for active FTP), udpassociate — UDP association.

Rules are checked top to bottom; the first matching one applies. If none match, access is denied.

A proxy user is created as a regular system account without login shell:

bash
sudo useradd -r -M -s /usr/sbin/nologin proxyuser
sudo passwd proxyuser

Start and check:

bash
sudo systemctl restart danted
sudo systemctl status danted
curl -x socks5h://proxyuser:PASSWORD@192.0.2.10:1080 https://ifconfig.me

The socks5h prefix means the site name is resolved by the proxy, not the client. The command should output the external address of the server running Dante.

Client connections

  • Browser. In Firefox a SOCKS proxy is set in Network settings: host, port 1080, SOCKS v5 type and the checkbox “Proxy DNS when using SOCKS v5” (send DNS through the proxy). Chromium and Chromium-based browsers use system settings or the launch parameter --proxy-server="socks5://192.0.2.10:1080"; they don’t support passwords for SOCKS, so for them the proxy is usually limited by source addresses.
  • Console programs. Many utilities, including curl, understand the environment variable ALL_PROXY=socks5h://proxyuser:PASSWORD@192.0.2.10:1080.
  • SSH. Connecting to a server through a SOCKS proxy is set in ~/.ssh/config with ProxyCommand nc -X 5 -x 192.0.2.10:1080 %h %p (requires OpenBSD netcat). This method does not transmit a password, so it’s suitable for proxies restricted by source addresses.
  • Applications without proxy support are directed to SOCKS via tun2socks or proxychains.

Restricting access by address

If the proxy is needed only for office employees or only for your other servers, restrict the source in client pass:

client pass {
    from: 198.51.100.0/24 to: 0.0.0.0/0
    log: error
}

You can also forbid access to internal networks in socks pass so that the proxy cannot be used to reach your internal infrastructure. A blocking rule should be placed above an allowing rule:

socks block {
    from: 0.0.0.0/0 to: 10.0.0.0/8
    log: connect error
}

Common mistakes

  • Open proxy. A configuration without a password and with from: 0.0.0.0/0 is quickly found by scanners and used to send spam and launch attacks from your address. Either enable socksmethod: username, or restrict sources by address — preferably both.
  • Password transmitted in clear text. That’s how SOCKS5 works: username and password go over the network unencrypted. Dante’s documentation warns about this explicitly. If clients connect over the Internet, run SOCKS inside an SSH tunnel or WireGuard.
  • Wrong external interface. If external points to an interface without Internet access, the client connects to the proxy but further connections cannot be established.
  • Port closed in the firewall. You need to open TCP port 1080, and for udpassociate also the UDP ports through which Dante sends datagrams.
  • Client uses SOCKS4. SOCKS4 has no password authentication, so with socksmethod: username such clients will be denied.
  • Configuration errors. After editing it’s useful to check the journal: journalctl -u danted -n 50. Dante reports the line number with the error.

Advantages and limitations

Advantages:

  • proxies any TCP and UDP traffic, not only web;
  • low resource usage and runs even on the smallest VPS;
  • flexible access rules by address, users and SOCKS commands;
  • long history and stable operation;
  • free license, packages in major distributions.

Limitations:

  • no HTTP-proxy features: caching, filtering by page URLs, TLS termination — for that you need Squid or Nginx;
  • SOCKS5 password is not encrypted, protect the channel separately;
  • configuration only via a text file, no GUI;
  • no built-in per-user traffic accounting — only connection logs.

When to choose Dante

Dante is suitable when you need a reliable SOCKS5 proxy with authentication and clear access rules — for applications that need egress via a specific address, for access to services with IP whitelists, or for directing container traffic via tun2socks. If you need an HTTP proxy, traffic accounting and per-user limits in one program, 3proxy may be more convenient; if you need web traffic filtering and reports on visited sites — Squid.

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply