How to Set Up OpenFlux as a SOCKS5 Proxy: Complete Configuration Guide
OpenFlux provides a built-in SOCKS5 server that forwards client connections through any supported transport layer, allowing you to tunnel application traffic via Oneme, Yandex, or Encrypted transports using standard SOCKS5 proxy settings.
Setting up OpenFlux as a SOCKS5 proxy transforms the tool into a transparent traffic forwarder that applications can use without modification. According to the p1neappleXpress/OpenFlux source code, the implementation resides in socks5/socks5.go and exposes a clean API for binding to network interfaces while leveraging pluggable transport layers.
Understanding the SOCKS5 Server Architecture
The SOCKS5 implementation in OpenFlux follows a standard server lifecycle pattern. At its core, the socks5.NewSOCKS5Server function constructs a SOCKS5Server instance that accepts two parameters: a listening address and a Dialer interface implementation.
The Dialer interface requires a single method:
DialTCP(string) (net.Conn, error)
Any transport that satisfies this interface—whether Oneme, Yandex, or Encrypted—can be plugged into the SOCKS5 server. This architecture decouples the proxy protocol handling from the underlying tunneling mechanism, allowing you to switch transports without changing proxy client configurations.
Step-by-Step Setup Guide
Clone and Build the Binary
Start by cloning the repository and compiling the main binary:
git clone https://github.com/p1neappleXpress/OpenFlux.git
cd OpenFlux
go build -o openflux ./main.go
The resulting openflux binary contains the SOCKS5 server logic and all transport implementations.
Select a Transport Layer
OpenFlux supports multiple transport backends located in the transport/ directory. Choose based on your infrastructure requirements:
- Encrypted: Built-in secure tunneling (good for testing)
- Oneme: Uses the Oneme transport protocol (
transport/oneme/max_transport.go) - Yandex: Alternative backend via
transport/yandex/yandex.go
Each transport implements the Dialer interface and handles the actual remote connection establishment.
Launch the SOCKS5 Proxy
Start the proxy using the -socks5 flag to specify the binding address. The following command starts a SOCKS5 listener on port 1080 using the Encrypted transport:
./openflux -mode client -transport encrypted -socks5 :1080
Replace encrypted with oneme or yandex as needed, and append any transport-specific flags (such as API keys) required by your chosen backend.
Verify the Connection
Confirm the server is listening on the specified interface:
netstat -ltnp | grep 1080
# or
lsof -i :1080
Configure your applications to use SOCKS5 proxy 127.0.0.1:1080. All TCP connections will now traverse the selected OpenFlux transport.
Programmatic Implementation
For custom integrations, instantiate the server directly in Go code rather than using the CLI:
package main
import (
"github.com/p1neappleXpress/OpenFlux/socks5"
"github.com/p1neappleXpress/OpenFlux/transport/encrypted"
)
func main() {
// Initialize the transport (implements Dialer interface)
tun := encrypted.NewTransport()
// Create SOCKS5 server on localhost:1080
srv := socks5.NewSOCKS5Server(":1080", tun)
// Bind synchronously to catch address-in-use errors early
if err := srv.Bind(); err != nil {
panic(err)
}
// Start the accept loop (blocks until Close() is called)
if err := srv.Start(); err != nil {
panic(err)
}
}
This pattern mirrors the implementation found in main.go, where the -socks5 flag triggers similar initialization logic.
How the SOCKS5 Server Handles Traffic
The server lifecycle defined in socks5/socks5.go follows six distinct phases:
-
Construction –
NewSOCKS5Server(addr, dialer)stores the listener address and transport dialer. -
Binding –
Bind()opens the TCP listener immediately, returning synchronous errors if the port is unavailable. -
Accept Loop –
Start()runs a continuous loop callinglistener.Accept(), spawning goroutines for each client connection. -
Handshake Parsing –
handleConnectionparses the SOCKS5 protocol, extracts the target address (IPv4, IPv6, or domain name), and validates the request. -
Tunnel Establishment – The server calls
dialer.DialTCP(targetAddr)to create the remote connection through the selected transport layer. -
Bidirectional Relay – Two goroutines run
io.Copyloops to shuttle data between the client and the tunneled remote endpoint until either side disconnects.
Graceful shutdown is handled by Close(), which closes the listener and aborts the accept loop.
Summary
- OpenFlux exposes a production-ready SOCKS5 server via
socks5.NewSOCKS5Serverinsocks5/socks5.go. - The server requires any transport implementing the
Dialerinterface with aDialTCPmethod. - Launch via CLI using
-socks5 :1080or programmatically using the Go API. - Supported transports include Encrypted, Oneme, and Yandex, each located in the
transport/directory. - The implementation handles SOCKS5 handshakes, address resolution, and bidirectional traffic copying through goroutines.
Frequently Asked Questions
What transport options does OpenFlux support for SOCKS5 proxy mode?
OpenFlux supports three primary transports that implement the Dialer interface: Encrypted (transport/encrypted.go), Oneme (transport/oneme/max_transport.go), and Yandex (transport/yandex/yandex.go). Each transport handles the underlying tunnel establishment differently while presenting the same interface to the SOCKS5 server.
How do I change the default SOCKS5 port in OpenFlux?
Pass the desired address to the -socks5 flag when starting the binary. For example, use -socks5 0.0.0.0:2080 to bind to port 2080 on all interfaces, or -socks5 127.0.0.1:9150 for localhost-only access on port 9150. When using the Go API, pass the address string as the first argument to socks5.NewSOCKS5Server.
Can I use OpenFlux as a SOCKS5 proxy on mobile devices?
Yes. The repository includes an iOS Packet Tunnel Provider in the ios-app/ directory that connects to the same SOCKS5 server implementation. Build the iOS app according to the instructions in that folder to use OpenFlux tunneling on iOS devices; the SOCKS5 server itself runs on your backend infrastructure while the mobile client connects to it.
How does OpenFlux handle authentication for the SOCKS5 proxy?
The current implementation in socks5/socks5.go focuses on the CONNECT command and transparent forwarding. According to the source code analysis, the server parses the SOCKS5 handshake and immediately proceeds to tunnel establishment using the provided Dialer. For deployments requiring username/password or GSSAPI authentication, you would need to extend the handleConnection logic in socks5/socks5.go to implement the authentication subnegotiation phase before calling dialer.DialTCP.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →