Skip to main content

How to set up a SOCKS5 proxy via SSH on a Mac

By Lucas Russo, developer of SSHive · Updated

Route browser traffic through a server you control, encrypted from your Mac all the way to it, out of reach of the hotel network. No VPN subscription.

Estimated time: 3 minutes

SSH's -D flag turns the connection into a SOCKS5 proxy: your browser sends its traffic to localhost:1080, SSH carries it through the encrypted connection, and the server makes the real request. Websites see the server's IP address, and the network you sit on, a hotel or café Wi-Fi, sees a single encrypted SSH stream. With OpenSSH it is one command, ssh -D 1080 user@server, and it costs nothing. In SSHive the SOCKS5 port is a Pro feature of the Mac app, and it starts with the profile. Any server you reach over SSH will do: a home server, a small VPS, a Raspberry Pi at home. It is the dynamic sibling of the tunnels in the SSH tunnel guide.

Step-by-step

  1. Pick (or create) the SSH profile to go out through

    Any server you reach over SSH works: a home server, a small VPS, a Raspberry Pi at home. For browsing speed, pick one close to where you want to appear from. Check that the remote sshd_config has AllowTcpForwarding yes (usually the default). In SSHive: Sidebar › + (or right-click an existing profile › Edit) › fill in name, host, port, user and authentication.
  2. Expand "Advanced options" and set the SOCKS5 port (Pro)

    In the profile dialog, click Advanced options and scroll to SOCKS5 Proxy (-D). It is a single field, the SOCKS port (placeholder 1080). Type 1080, or any port from 1024 up, and save. In the free version the field is greyed out with a PRO badge and clicking it opens the upgrade window; editing the profile by hand does not get around the limit.
  3. Connect: the proxy starts on 127.0.0.1:1080

    Double-click the profile. The SSH session connects and the SOCKS5 listener starts on 127.0.0.1:1080. The status bar shows the ⇄ indicator; click it to see the SOCKS tunnel in the Tunnel Status panel with its live state. To check from Terminal, lsof -i :1080 shows SSHive listening. To stop, disconnect the SSH session: the listener closes with it, with nothing to clean up.
  4. Point your browser or macOS at the proxy

    Firefox: Settings › Network Settings › Manual proxy configuration › SOCKS Host 127.0.0.1, Port 1080, SOCKS v5, with "Proxy DNS when using SOCKS v5" ticked. Chrome has no setting of its own; launch it with --proxy-server=socks5://127.0.0.1:1080. For Safari: System Settings › Network › your interface › Proxies › SOCKS proxy. Then visit any "what is my IP" page: it should now show the server's address. Only apps that honour a SOCKS proxy use it; everything else still goes out directly.

Frequently asked questions

Is SOCKS5 over SSH safe enough on hotel Wi-Fi?+
For browser traffic, yes: the SSH tunnel encrypts everything between your Mac and your server, and the hotel network only sees one encrypted SSH stream. What the server sends on afterwards uses HTTPS or not, depending on the site, so SSH alone does not encrypt all the way to every website. Turn on your browser's HTTPS-only mode as well.
How does SOCKS5 over SSH compare to a real VPN?+
SOCKS5 works per app (the browser, a chat client), while a VPN covers the whole system. ssh -D costs nothing with OpenSSH; in SSHive it is a Pro feature, on the Mac only. The SOCKS proxy of OpenSSH relays TCP connections, not UDP, so it suits browsing, not games or calls: for everything at once, use a VPN. On iPhone and iPad, SSHive has a VPN client (IKEv2, IPSec, OpenVPN) instead.

Related SSHive features

SSH Tunnels

Local, remote & SOCKS5 proxy

SSH Terminal

GPU-accelerated terminal

Try SSHive Free for macOS

Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.

Download SSHive Free