How to set up a SOCKS5 proxy via SSH on a Mac
By Lucas Russo, developer of SSHive · Updated
Route browser traffic through a server you control, encrypted from your Mac all the way to it, out of reach of the hotel network. No VPN subscription.
SSH's -D flag turns the connection into a SOCKS5 proxy: your browser sends its traffic to localhost:1080, SSH carries it through the encrypted connection, and the server makes the real request. Websites see the server's IP address, and the network you sit on, a hotel or café Wi-Fi, sees a single encrypted SSH stream. With OpenSSH it is one command, ssh -D 1080 user@server, and it costs nothing. In SSHive the SOCKS5 port is a Pro feature of the Mac app, and it starts with the profile. Any server you reach over SSH will do: a home server, a small VPS, a Raspberry Pi at home. It is the dynamic sibling of the tunnels in the SSH tunnel guide.
Step-by-step
Pick (or create) the SSH profile to go out through
Any server you reach over SSH works: a home server, a small VPS, a Raspberry Pi at home. For browsing speed, pick one close to where you want to appear from. Check that the remotesshd_confighasAllowTcpForwarding yes(usually the default). In SSHive: Sidebar › + (or right-click an existing profile › Edit) › fill in name, host, port, user and authentication.Expand "Advanced options" and set the SOCKS5 port (Pro)
In the profile dialog, click Advanced options and scroll to SOCKS5 Proxy (-D). It is a single field, the SOCKS port (placeholder1080). Type1080, or any port from 1024 up, and save. In the free version the field is greyed out with a PRO badge and clicking it opens the upgrade window; editing the profile by hand does not get around the limit.Connect: the proxy starts on 127.0.0.1:1080
Double-click the profile. The SSH session connects and the SOCKS5 listener starts on127.0.0.1:1080. The status bar shows the ⇄ indicator; click it to see the SOCKS tunnel in the Tunnel Status panel with its live state. To check from Terminal,lsof -i :1080shows SSHive listening. To stop, disconnect the SSH session: the listener closes with it, with nothing to clean up.Point your browser or macOS at the proxy
Firefox: Settings › Network Settings › Manual proxy configuration › SOCKS Host127.0.0.1, Port1080, SOCKS v5, with "Proxy DNS when using SOCKS v5" ticked. Chrome has no setting of its own; launch it with--proxy-server=socks5://127.0.0.1:1080. For Safari: System Settings › Network › your interface › Proxies › SOCKS proxy. Then visit any "what is my IP" page: it should now show the server's address. Only apps that honour a SOCKS proxy use it; everything else still goes out directly.
Frequently asked questions
Is SOCKS5 over SSH safe enough on hotel Wi-Fi?+
How does SOCKS5 over SSH compare to a real VPN?+
ssh -D costs nothing with OpenSSH; in SSHive it is a Pro feature, on the Mac only. The SOCKS proxy of OpenSSH relays TCP connections, not UDP, so it suits browsing, not games or calls: for everything at once, use a VPN. On iPhone and iPad, SSHive has a VPN client (IKEv2, IPSec, OpenVPN) instead.Related SSHive features
SSH Tunnels
Local, remote & SOCKS5 proxy
SSH Terminal
GPU-accelerated terminal
Try SSHive Free for macOS
Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.
Download SSHive Free