// Engineering Log
Proxy Servers: Part 5 — 3proxy
Published on 2026-09-21
// Fast route
This article belongs to the topic Networking and routing.
3proxy — a free open-source proxy server that combines HTTP proxy, SOCKS proxy, mail and FTP proxies, port forwarding and a caching DNS in a single small program. The author is Vladimir Dubrovin, known by the nickname 3APA3A; the program’s name is associated with that nickname. The project has been developed since 2000; version 1.0.0 was released in August 2026. 3proxy runs on Linux, BSD, macOS and Windows.
What services are available in 3proxy
Each service is started with a separate command in the configuration file. According to the documentation (man 3proxy.cfg) the following are available:
proxy— HTTP and HTTPS proxy (default port 3128); HTTPS is handled with CONNECT without decryption;socks— SOCKS4, SOCKS4.5 and SOCKS5 (default port 1080);pop3pandsmtpp— proxies for receiving and sending mail;ftppr— FTP proxy;tcppmandudppm— forwarding of TCP and UDP ports to another address;dnspr— caching DNS proxy; works only together with thenserverandnscachecommands;tlspr— TLS proxy;admin— web interface for viewing statistics and configuration;auto— a service that detects the client protocol automatically.
The main difference from Dante is that 3proxy provides not only SOCKS but also HTTP proxy, traffic accounting, quotas and per-user rate limits. This makes it convenient for a small office or for sharing proxies with several clients from a single server.
Installation
For Linux the project publishes deb packages for Ubuntu 22.04 and newer and for Debian 12 and newer — for x86-64, ARM64 and 32-bit ARM processors. They can be downloaded from the releases page on GitHub or by adding the signed apt repository https://3proxy.org/repo/. The repository has two channels: current — the current 1.x branch, and lts — the 0.9 long-term support branch.
After installation the configuration is located at /etc/3proxy/3proxy.cfg. To add users a script add3proxyuser is included:
sudo add3proxyuser ivan 'ComplexPassword'The script is designed for the standard package configuration where the user list is stored in a separate file. In the example below users are placed directly in the configuration for clarity. The service is managed via systemd: sudo systemctl enable --now 3proxy.
Example configuration
Below is a configuration for a small office: HTTP proxy and SOCKS5 with passwords, denial of access to private networks through the proxy, daily log rotation and a speed limit for one user.
nserver 1.1.1.1
nserver 8.8.8.8
nscache 65536
log /var/log/3proxy/3proxy.log D
rotate 30
users ivan:CL:IvanPassword olga:CL:OlgaPassword
auth strong
deny * * 10.0.0.0/8,172.16.0.0/12,192.168.0.0/16
allow ivan,olga
bandlimin 10000000 olga
proxy -p3128
flush
auth strong
allow ivan
socks -p1080How to read this:
nserverandnscache— DNS servers through which 3proxy resolves names, and the size of the response cache;log ... Dandrotate 30— a log with daily rotation, keeping 30 archived files;users— users and passwords. TypeCLmeans password in cleartext; in production it is better to store a hash, typeCR(for example,ivan:CR:$1$...— such a hash is produced byopenssl passwd -1);auth strong— login only by username and password. Other options:iponly— only by client address,none— without authentication,cache— remember successful authentication;denyandallow— access rules. Their fields are in the order: users, client addresses, destination addresses, ports, operations, days of week, time of day. An asterisk means “any”. Rules are checked top to bottom, so the denial for private networks is placed first;bandlimin 10000000 olga— incoming bandwidth limit for user olga to 10 Mbps;proxy -p3128— start the HTTP proxy with the current set of rules;flush— reset rules: everything below applies only to the following services. Here the SOCKS proxy is available only to user ivan.
The order in the file matters: a service gets the rules that were declared above it and after the last flush.
Rules can also be restricted by time. For example, to allow access only on weekdays during working hours:
allow * 198.51.100.0/24 * * * 1-5 09:00:00-18:00:00Traffic accounting per user
Counters allow limiting the traffic volume, for example 5 GB per day for each user. The counter command sets the file where 3proxy stores accumulated values, and countin — the limit itself in megabytes:
counter /var/lib/3proxy/3proxy.counters
countin 1 D 5000 ivan
countin 2 D 5000 olgaThe first number in countin is the record number in the counter file, the letter is the period (H — hour, D — day, W — week, M — month), then the limit and the list of users. When the limit is exhausted, the user will be denied until the end of the period. These lines, like access rules, must be placed above the service they apply to.
Proxy chains
3proxy can send connections not directly, but via an upstream proxy. The parent command supplements the last allow rule:
allow *
parent 1000 socks5 203.0.113.5 1080 user password
proxy -p3128Here clients connect to the HTTP proxy on port 3128, and 3proxy sends their connections further through a SOCKS5 proxy at 203.0.113.5. The number 1000 is a weight: if several parent entries with weights summing to 1000 are specified, 3proxy will choose between them randomly. This allows distributing load across several exit servers.
Verification
sudo systemctl restart 3proxy
curl -x http://ivan:IvanPassword@192.0.2.10:3128 https://ifconfig.me
curl -x socks5h://ivan:IvanPassword@192.0.2.10:1080 https://ifconfig.meBoth commands should output the external address of the server running 3proxy.
Other useful features
- Port forwarding. The command
tcppm 8080 10.0.0.5 80accepts connections on port 8080 and forwards them to port 80 of an internal server — useful when you need to quickly expose a single service. - Anonymous HTTP proxy. The
-aflag for theproxyservice removes headers from requests by which the target server could learn the client’s address. - Traffic accounting and quotas. The commands
counter,countinandcountoutmaintain counters and limit a user’s traffic for an hour, day, week or month. Thebandliminandbandlimoutcommands limit bandwidth. - Privilege dropping. The
setuidandsetgidcommands switch the process from root to an unprivileged user after services are started, andchrootlocks it in a separate directory.
Common mistakes
- Rules declared after the service. If
allowis below theproxyline, it does not apply to that service. - Forgotten
flush. Without it the second service inherits all rules from the first, making access broader or narrower than intended. - Open proxy. A configuration with
auth noneand without client address restrictions is quickly found by scanners. Always restrict access by password or client addresses. - Passwords in cleartext. Type
CLis convenient for testing, but in production store hashes. - Password transmitted without encryption. In HTTP proxy with Basic authentication and in SOCKS5 the username and password are sent over the network in clear. When connecting over the internet, protect the channel with a tunnel.
Advantages and limitations
Advantages:
- many services in one small program;
- low resource usage;
- flexible rules by users, addresses, ports and time;
- built-in traffic counters and rate limiting;
- works on Linux, BSD, macOS and Windows.
Limitations:
- no full web-page caching like Squid;
- not suitable as a reverse proxy or load balancer in front of web services — use Nginx or HAProxy for that;
- configuration only via a text file, and the order of lines matters, which initially leads to mistakes;
- for some specialized functions other programs are more feature-rich: for example, Dante has more detailed SOCKS rules.
When to choose 3proxy
3proxy is suitable when you need to share HTTP and SOCKS proxies from one server to multiple users, account for their traffic and limit their bandwidth or volume. For a single-purpose SOCKS5 setup Dante is simpler; for web traffic filtering and reports on visited sites use Squid.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Networking and routing
MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.
Typical tasks behind this topic
- Set up VPN and secure access to office or cloud
- Fix routing, DNS, or unstable connectivity
- Configure MikroTik, firewall, and external links
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related