How to Set Up OpenFlux as a SOCKS5 Proxy: Complete Configuration Guide

OpenFlux provides a built-in SOCKS5 server that forwards client connections through any supported transport layer, allowing you to tunnel application traffic via Oneme, Yandex, or Encrypted transports using standard SOCKS5 proxy settings.

Setting up OpenFlux as a SOCKS5 proxy transforms the tool into a transparent traffic forwarder that applications can use without modification. According to the p1neappleXpress/OpenFlux source code, the implementation resides in socks5/socks5.go and exposes a clean API for binding to network interfaces while leveraging pluggable transport layers.

Understanding the SOCKS5 Server Architecture

The SOCKS5 implementation in OpenFlux follows a standard server lifecycle pattern. At its core, the socks5.NewSOCKS5Server function constructs a SOCKS5Server instance that accepts two parameters: a listening address and a Dialer interface implementation.

The Dialer interface requires a single method:

DialTCP(string) (net.Conn, error)

Any transport that satisfies this interface—whether Oneme, Yandex, or Encrypted—can be plugged into the SOCKS5 server. This architecture decouples the proxy protocol handling from the underlying tunneling mechanism, allowing you to switch transports without changing proxy client configurations.

Step-by-Step Setup Guide

Clone and Build the Binary

Start by cloning the repository and compiling the main binary:

git clone https://github.com/p1neappleXpress/OpenFlux.git
cd OpenFlux
go build -o openflux ./main.go

The resulting openflux binary contains the SOCKS5 server logic and all transport implementations.

Select a Transport Layer

OpenFlux supports multiple transport backends located in the transport/ directory. Choose based on your infrastructure requirements:

Each transport implements the Dialer interface and handles the actual remote connection establishment.

Launch the SOCKS5 Proxy

Start the proxy using the -socks5 flag to specify the binding address. The following command starts a SOCKS5 listener on port 1080 using the Encrypted transport:

./openflux -mode client -transport encrypted -socks5 :1080

Replace encrypted with oneme or yandex as needed, and append any transport-specific flags (such as API keys) required by your chosen backend.

Verify the Connection

Confirm the server is listening on the specified interface:

netstat -ltnp | grep 1080

# or

lsof -i :1080

Configure your applications to use SOCKS5 proxy 127.0.0.1:1080. All TCP connections will now traverse the selected OpenFlux transport.

Programmatic Implementation

For custom integrations, instantiate the server directly in Go code rather than using the CLI:

package main

import (
    "github.com/p1neappleXpress/OpenFlux/socks5"
    "github.com/p1neappleXpress/OpenFlux/transport/encrypted"
)

func main() {
    // Initialize the transport (implements Dialer interface)
    tun := encrypted.NewTransport()
    
    // Create SOCKS5 server on localhost:1080
    srv := socks5.NewSOCKS5Server(":1080", tun)
    
    // Bind synchronously to catch address-in-use errors early
    if err := srv.Bind(); err != nil {
        panic(err)
    }
    
    // Start the accept loop (blocks until Close() is called)
    if err := srv.Start(); err != nil {
        panic(err)
    }
}

This pattern mirrors the implementation found in main.go, where the -socks5 flag triggers similar initialization logic.

How the SOCKS5 Server Handles Traffic

The server lifecycle defined in socks5/socks5.go follows six distinct phases:

  1. Construction – NewSOCKS5Server(addr, dialer) stores the listener address and transport dialer.

  2. Binding – Bind() opens the TCP listener immediately, returning synchronous errors if the port is unavailable.

  3. Accept Loop – Start() runs a continuous loop calling listener.Accept(), spawning goroutines for each client connection.

  4. Handshake Parsing – handleConnection parses the SOCKS5 protocol, extracts the target address (IPv4, IPv6, or domain name), and validates the request.

  5. Tunnel Establishment – The server calls dialer.DialTCP(targetAddr) to create the remote connection through the selected transport layer.

  6. Bidirectional Relay – Two goroutines run io.Copy loops to shuttle data between the client and the tunneled remote endpoint until either side disconnects.

Graceful shutdown is handled by Close(), which closes the listener and aborts the accept loop.

Summary

  • OpenFlux exposes a production-ready SOCKS5 server via socks5.NewSOCKS5Server in socks5/socks5.go.
  • The server requires any transport implementing the Dialer interface with a DialTCP method.
  • Launch via CLI using -socks5 :1080 or programmatically using the Go API.
  • Supported transports include Encrypted, Oneme, and Yandex, each located in the transport/ directory.
  • The implementation handles SOCKS5 handshakes, address resolution, and bidirectional traffic copying through goroutines.

Frequently Asked Questions

What transport options does OpenFlux support for SOCKS5 proxy mode?

OpenFlux supports three primary transports that implement the Dialer interface: Encrypted (transport/encrypted.go), Oneme (transport/oneme/max_transport.go), and Yandex (transport/yandex/yandex.go). Each transport handles the underlying tunnel establishment differently while presenting the same interface to the SOCKS5 server.

How do I change the default SOCKS5 port in OpenFlux?

Pass the desired address to the -socks5 flag when starting the binary. For example, use -socks5 0.0.0.0:2080 to bind to port 2080 on all interfaces, or -socks5 127.0.0.1:9150 for localhost-only access on port 9150. When using the Go API, pass the address string as the first argument to socks5.NewSOCKS5Server.

Can I use OpenFlux as a SOCKS5 proxy on mobile devices?

Yes. The repository includes an iOS Packet Tunnel Provider in the ios-app/ directory that connects to the same SOCKS5 server implementation. Build the iOS app according to the instructions in that folder to use OpenFlux tunneling on iOS devices; the SOCKS5 server itself runs on your backend infrastructure while the mobile client connects to it.

How does OpenFlux handle authentication for the SOCKS5 proxy?

The current implementation in socks5/socks5.go focuses on the CONNECT command and transparent forwarding. According to the source code analysis, the server parses the SOCKS5 handshake and immediately proceeds to tunnel establishment using the provided Dialer. For deployments requiring username/password or GSSAPI authentication, you would need to extend the handleConnection logic in socks5/socks5.go to implement the authentication subnegotiation phase before calling dialer.DialTCP.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →