Skip to content


Folders and files

Last commit message
Last commit date

Latest commit



30 Commits

Repository files navigation


Proxy program using socks5 to create tunnel between client application and your internal net host. For example, it's useful for connecting the transmission on your host NAS by transmission-remote-gui on anywhere, as shown below:

--- client ---+------- server -------+------- local ------------------

client <--[socks5]--> depot-server <---> depot-local <--[localhost]--> app

Once the socks connection is established, the reqeust of client must be sent to address via this connection and it will be transferred to app eventually. It seems client is communicating with app directly.


  • Web interface to wathch status of connections.
  • Socks5 connection (username/no-username)



  • control connection
    • connect server and local
    • send socks request from server to local
    • send alive message from local to server
  • socks connection
    • connect client and server
    • send socks request from client to server
    • for pipe
  • tunnel connection
    • connect server and local
    • for pipe
  • app connection
    • connect local and app
    • for pipe


  1. Server listens on the control port and socks port.
   | C |
   | S |
  1. Local connects to the control port, and establish a control connection by handshaking. Local will wait for socks request on this connection. l->c: "hello server" c->l: "hello local"
   | C |
      +-+      handshake      +-+
      +-+      [ctrlConn]     +-+
   | S |
  1. Server listens on the tunnel port, and waits for socks request.
   | C |
      +-+                     +-+
      +-+      [ctrlConn]     +-+
   | S |
   | T |
  1. Client connects to the socks port and establish an socks connection after handshaking and authenticating.
                           | C |
                              +-+                     +-+
                              +-+      [ctrlConn]     +-+
                           | S |
    +-+  handshake/auth   +-+
    +-+   [socksConn]     +-+
                           | T |
  1. Client sends the socks request to server. Server validates the request and send it to local via control connection.
                           | C |
                              +-+   2.socks request   +-+
                              +-+     [ctrlConn]      +-+
                           | S |
    +-+  1.socks request  +-+
    +-+   [socksConn]     +-+
                           | T |
  1. Local parses the socks request and open an app connection to the target host:port (i.e. app). After that, local sends success reply to server, and server sends reply to client.
                           | C |
                              +-+     2.reply         +-+
                              +-+     [ctrlConn]      +-+
                           +---+                      +-+   1.connect   +-+
                           | S |                      |b|<------------->|a|
                           +---+                      +-+   [appConn]   +-+
    +-+    3.reply        +-+
    +-+   [socksConn]     +-+
                           | T |
  1. Local connects to the tunnel port of server and establishs the tunnel connection by sending the socks request back as a handshake.
                           | C |
                              +-+                     +-+
                              +-+     [ctrlConn]      +-+
                           +---+                      +-+               +-+
                           | S |                      |b|<------------->|a|
                           +---+                      +-+   [appConn]   +-+
    +-+                   +-+
    +-+   [socksConn]     +-+
                           | T |
						      +-+  connect/handshake  +-+
						      +-+     [tunnelConn]    +-+
  1. At this time, all necessary connetions are already established. Pipe them together (s&t, d&b) and the connection between client and app will work well. Client can communicate with app with socket r.
                           | C |
                              +-+       alive         +-+
                              +-+      [ctrlConn]     +-+
                           | S |                        
    +-+                   +-+ +-+                   +-+ +-+                +-+
    +-+   [socksConn]     +-+ +-+     [tunnelConn]  +-+ +-+    [appConn]   +-+
                           | T |

The final pipeline is:

         socksConn <--> tunnelConn <--> appConn

The ctrlConn is used by local to send alive message. And once local exits, this connection would be closed. In the other hand, once server exits, local should close all connections and try to connect to control port of server again and again.


  • local should try to connect to server repeatly and send heartbeat message to server after connecting.
  • provide methods to watch the status of server and local.
  • how to handle multiple socks reqeusts?


See the LICENSE file.