How to Use the Brook Proxy Tool: Complete TLS + WebSocket Setup Guide
Run brook wsserver on your VPS to auto-obtain a Let's Encrypt certificate and create a WebSocket tunnel, then connect with brook wsclient locally to expose a SOCKS5 proxy at 127.0.0.1:2080.
The Brook proxy tool is a lightweight, cross-platform proxy solution designed for bypassing network restrictions through TLS-encrypted WebSocket tunnels. According to the bannedbook/fanqiang repository, Brook's architecture separates cleanly into a server component that terminates TLS and a client component that exposes a local SOCKS5 interface. This guide walks through deploying Brook using the TLS + WebSocket mode documented in the official tutorials.
Brook Architecture Overview
Brook operates in a client-server model optimized for circumvention scenarios:
- Server (
brook wsserver): Handles TLS termination, automatically provisions free certificates from Let's Encrypt, and bridges traffic via WebSocket - Client (
brook wsclient): Connects to the remotewss://endpoint and forwards to a local SOCKS5 listener
The implementation requires no external web server for basic operation—Brook manages certificate lifecycle and HTTPS listeners internally.
Server Setup: Deploying Brook wsserver
The server configuration uses a single static binary with automatic TLS provisioning.
Installation and Launch
From v2ss/Brook之TLS+WebSocket翻墙教程.md (lines 51-55), the standard server deployment follows this pattern:
# Download the Brook binary (v20200201 release shown)
wget https://github.com/txthinking/brook/releases/download/v20200201/brook
chmod +x brook
# Start the wsserver with your domain and password
setsid ./brook wsserver --domain www.mydomain.com -p yourPassword
Key parameters:
--domain: Your fully-qualified domain name (must resolve to this server's IP)-p: Authentication password for client connectionssetsid: Ensures the process continues after logout
The server automatically:
- Listens on port 80 (HTTP-01 challenge) and port 443 (TLS)
- Requests and provisions a Let's Encrypt certificate
- Stores certificates in a
.letsencryptdirectory - Creates the
wss://WebSocket endpoint at/ws
TLS Certificate Management
If your domain or DNS configuration changes, you must regenerate certificates. Per line 58 of the tutorial:
# Remove cached certificates and restart
rm -rf .letsencrypt
setsid ./brook wsserver --domain www.mydomain.com -p yourPassword
Critical requirement: Both server and client must maintain synchronized system clocks. TLS validation will fail if time drift exceeds acceptable thresholds (line 79).
Client Setup: Connecting with Brook wsclient
The Windows client documented in v2ss/Brook之TLS+WebSocket翻墙教程.md (lines 73-76) creates a local SOCKS5 proxy that applications can route through.
Windows Client Configuration
:: Download the Windows binary (386 architecture example)
curl -L -o brook_windows_386.exe https://github.com/txthinking/brook/releases/download/v20200201/brook_windows_386.exe
:: Start the client SOCKS5 listener
brook_windows_386.exe wsclient -l 127.0.0.1:2080 -i 127.0.0.1 -s wss://www.mydomain.com:443 -p yourPassword
Parameter breakdown:
-l 127.0.0.1:2080: Local SOCKS5 listen address (default port 2080)-i 127.0.0.1: Local interface binding-s wss://www.mydomain.com:443: Remote server endpoint (must match server domain)-p yourPassword: Authentication password (must match server)
Once running, configure any SOCKS5-capable application to use 127.0.0.1:2080 as its proxy.
Advanced Deployment Options
The bannedbook/fanqiang repository extends the base Brook setup with two additional architectural patterns:
TLS + WebSocket + Web Server
Hides the Brook endpoint behind a standard web server (nginx/Apache/Caddy) to blend proxy traffic with normal HTTPS requests. Reference: v2ss/Brook之TLS+WebSocket+Web翻墙教程.md
TLS + WebSocket + CDN
Routes traffic through a CDN edge network for additional resilience and IP masking. Reference: v2ss/Brook之TLS+WebSocket+CDN翻墙教程.md
Both patterns use the same core wsserver/wsclient commands but add reverse proxy layers.
File Reference Map
| Path | Purpose |
|---|---|
v2ss/Brook之TLS+WebSocket翻墙教程.md |
Primary tutorial with server/client commands and TLS tips |
v2ss/Brook之TLS+WebSocket+Web翻墙教程.md |
Web server obfuscation layer |
v2ss/Brook之TLS+WebSocket+CDN翻墙教程.md |
CDN integration for resilience |
v2ss/images/config.ini |
Example configuration referencing Brook executable |
Summary
- Brook proxy tool deployment requires matching server (
wsserver) and client (wsclient) commands with TLS + WebSocket mode - Server auto-provisions Let's Encrypt certificates; delete
.letsencryptto regenerate after DNS changes - Client exposes 127.0.0.1:2080 SOCKS5 proxy for application routing
- Time synchronization is mandatory on both endpoints for TLS validation
- Advanced concealment available via web server or CDN layering per repository tutorials
Frequently Asked Questions
What port does Brook use for the WebSocket tunnel?
Brook wsserver uses port 80 for initial Let's Encrypt HTTP-01 validation and port 443 for the encrypted wss:// WebSocket tunnel. The client connects to port 443 by default.
Does Brook require a separate web server like nginx?
No. The basic Brook TLS + WebSocket mode runs standalone. However, bannedbook/fanqiang provides optional tutorials for adding nginx or other web servers if you need traffic obfuscation.
Why is my Brook client failing to connect with TLS errors?
The most common cause is clock skew. Both server and client system clocks must stay synchronized. Run ntpdate or enable NTP services on both machines before retrying.
Can I use Brook with mobile applications?
Yes. Applications that support SOCKS5 proxy configuration can route through the local Brook client listener. Some mobile platforms may require third-party proxy management apps to enable system-wide SOCKS5 routing.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →