What a proxy server does and why you might build one

A proxy server sits between your device and the internet, forwarding your requests to websites and sending their responses back to you. When you build your own instead of using a public one, you control who can use it, what traffic it handles, and where the data goes. This matters if you're running a business network, testing software, caching content to save bandwidth, or filtering traffic on your own infrastructure.

The setup process depends on what you're trying to do. A simple forward proxy that masks your IP address is different from a reverse proxy that sits in front of a web server and handles incoming traffic. This guide covers the most common scenario: setting up a forward proxy on a server you control, which routes outgoing requests from your network or devices.

Key Takeaways

  • You need a server (cloud instance, dedicated machine, or VPS) running Linux or Windows, plus proxy software like Squid, Tinyproxy, or mitmproxy.
  • The basic setup involves installing the software, editing its configuration file to set ports and access rules, and starting the service.
  • You then point your devices or applications to your proxy's IP address and port number, which you define in the config file.
  • Testing your proxy with a simple curl command or browser settings confirms traffic is routing through it before you put it into production.
  • Firewalls, authentication, and logging are optional but recommended if your proxy handles sensitive traffic or multiple users.

Choosing proxy software for your setup

Squid is the most widely used open-source proxy. It runs on Linux and handles high traffic, caching, and complex access control rules. If you're new to proxies, Squid's learning curve is steep — its configuration file has hundreds of options — but it's battle-tested in enterprise networks.

Tinyproxy is smaller and simpler. It installs faster, uses less memory, and works well for small networks or testing. Its configuration file is readable and has fewer options, making it a better starting point if you just need basic forwarding.

mitmproxy is designed for developers who need to inspect and modify traffic. It includes a command-line tool and a web interface, making it useful for debugging applications or testing how software handles network requests. It's not ideal for production traffic filtering, but it's excellent for development.

For a reverse proxy (sitting in front of a web server), Nginx and Apache are standard choices. Both are web servers that can also act as proxies, forwarding requests to backend servers. This guide focuses on forward proxies, but the installation and configuration concepts overlap.

Setting up Squid on a Linux server

Start with a Linux server — a cloud instance from AWS, DigitalOcean, Linode, or any provider works. SSH into the server and update your package manager. On Ubuntu or Debian, run sudo apt update and sudo apt upgrade. On CentOS or RHEL, use sudo yum update.

Install Squid with sudo apt install squid (Ubuntu/Debian) or sudo yum install squid (CentOS/RHEL). The installation creates a default configuration file at /etc/squid/squid.conf. Before editing it, back it up: sudo cp /etc/squid/squid.conf /etc/squid/squid.conf.backup.

Open the config file with a text editor: sudo nano /etc/squid/squid.conf. Find the line that says http_port 3128 — this is the port Squid listens on. You can change it to any unused port above 1024 (ports below 1024 require root access). For this example, keep it at 3128. Find the line http_access deny all and add this line above it: http_access allow localhost. This lets your local machine use the proxy. To allow other machines, add http_access allow 192.168.1.0/24 (replace with your network's IP range) before the deny line.

Save the file (Ctrl+O, then Enter in nano, then Ctrl+X to exit). Test the configuration with sudo squid -k check. If it returns no errors, start Squid: sudo systemctl start squid. Enable it to start on boot with sudo systemctl enable squid. Verify it's running: sudo systemctl status squid.

Configuring access and testing your proxy

Your proxy is now listening on port 3128. To test it from another machine on your network, use curl: curl -x http://your-server-ip:3128 http://example.com. Replace your-server-ip with your server's actual IP address. If the command returns the HTML of example.com, your proxy is working.

To use the proxy in a web browser, go to your browser's settings. In Firefox, navigate to Settings > Network Settings > Manual proxy configuration, and enter your server's IP in the HTTP Proxy field with port 3128. In Chrome, this varies by operating system — on Windows, go to Settings > Advanced > System > Open proxy settings, and on macOS, go to System Preferences > Network > Advanced > Proxies.

If the test fails, check your firewall. The server's firewall must allow inbound traffic on port 3128. On a Linux server with UFW, run sudo ufw allow 3128. On a cloud provider, check the security group or firewall rules in the provider's console. Your local network firewall may also block the connection if you're testing from outside your network.

Once testing works, you can refine access rules. In Squid's config, you can define access control lists (ACLs) to allow or deny traffic by source IP, destination domain, or time of day. For example, add acl work_hours time MTWHF 09:00-17:00 to define work hours, then http_access allow work_hours to restrict proxy use to those times. These rules go in the config file before the final http_access deny all line.

Adding authentication and logging

If multiple people use your proxy, add authentication so only authorized users can access it. Squid supports basic authentication using a password file. First, install the htpasswd utility: sudo apt install apache2-utils. Create a password file: sudo htpasswd -c /etc/squid/passwd username. Replace username with an actual username. The command prompts you for a password.

In your Squid config file, add these lines before the http_access allow rules:

auth_param basic program /usr/lib/squid/basic_ncsa_auth /etc/squid/passwd acl authenticated proxy_auth REQUIRED http_access allow authenticated

Restart Squid: sudo systemctl restart squid. Now when a device connects, it must provide the username and password you created.

Squid logs all traffic to /var/log/squid/access.log by default. View recent activity with sudo tail -f /var/log/squid/access.log. Each line shows the timestamp, source IP, destination domain, response code, and bytes transferred. If you need to keep logs longer or analyze them, configure log rotation in /etc/logrotate.d/squid or send logs to a centralized logging system.

Setting up Tinyproxy for simpler needs

If Squid feels too complex, Tinyproxy is faster to deploy. Install it with sudo apt install tinyproxy (Ubuntu/Debian) or sudo yum install tinyproxy (CentOS/RHEL). The config file is at /etc/tinyproxy/tinyproxy.conf.

Open it with sudo nano /etc/tinyproxy/tinyproxy.conf. Find the line Port 8888 and change it if you want a different port. Find the section with Allow and Deny directives. By default, Allow 127.0.0.1 allows only localhost. Add Allow 192.168.1.0/24 to allow your local network, or comment out the Allow line and add Deny 0.0.0.0/0 to deny all, then add specific Allow lines for networks you trust.

Start Tinyproxy: sudo systemctl start tinyproxy. Enable it on boot: sudo systemctl enable tinyproxy. Test it the same way as Squid: curl -x http://your-server-ip:8888 http://example.com. Tinyproxy logs to /var/log/tinyproxy/tinyproxy.log.

Securing your proxy from abuse

An open proxy on the internet can be abused by spammers and attackers to hide their traffic. If your proxy is accessible from outside your network, restrict it immediately. In your firewall, allow port 3128 (or whatever port you chose) only from specific IP addresses or your internal network. On a cloud provider, use security groups to limit inbound traffic.

Enable authentication as described above — this prevents random internet users from using your proxy. Monitor your logs regularly for unusual traffic patterns. A sudden spike in requests to unfamiliar domains or a high volume of traffic from a single source can indicate abuse.

If you're running the proxy on a public cloud instance, consider using a VPN or SSH tunnel to access it instead of exposing the port directly. This adds a layer of encryption and authentication before traffic even reaches the proxy.

Frequently Asked Questions

Can I use a proxy server to hide my IP address from websites?

Yes, but only partially. Websites see your proxy's IP, not your own. However, your internet service provider and the proxy operator can still see your real IP. If you're building your own proxy, you control the logs, so you know what traffic passed through. For stronger anonymity, a VPN or Tor is more appropriate.

What's the difference between a forward proxy and a reverse proxy?

A forward proxy (what this guide covers) sits between clients and the internet, forwarding outgoing requests. A reverse proxy sits between the internet and your servers, forwarding incoming requests to backend machines. Reverse proxies are common for load balancing and caching. The software and setup differ, though tools like Nginx and Apache can do both.

How much does it cost to run a proxy server?

If you already own a server, the software is free. If you're renting a cloud instance, costs depend on the provider and instance size. A small instance on DigitalOcean or Linode costs $4 to $6 per month. Bandwidth charges vary — some providers include bandwidth in the monthly fee, others charge per gigabyte. Check your provider's pricing before deploying.

Can I use a proxy to bypass website restrictions?

Technically yes, but many websites detect and block proxy traffic. Some terms of service forbid proxy use. If you're trying to bypass restrictions imposed by your employer or school, the proxy may be detected and you could face consequences. Understand the rules where you're using it.

What happens if my proxy server goes down?

Devices configured to use it will fail to connect to the internet until the proxy is back online or you reconfigure them to connect directly. For critical networks, set up monitoring (tools like Nagios or Prometheus) to alert you if the proxy stops responding, and consider running a backup proxy that devices can fall back to.