Simple guide to setting up your own proxy server (http/https)
A proxy server can be really helpful in situations wherein you need to access a geo-locked web resource (website, API etc.). Once you are able to provision a VPS in the same geography as your target system, proxy servers such as Squid can allow you to hop via the proxy and access your target system.
Resource requirements
Assuming that you are using the proxy server for personal use only, a Linux VM with a modest 512 MB of RAM would be more than sufficient. A simple VPS such as this will cost you somewhere around $5/month. Ensure that the geographical location for this VPS/VM is as close to the target system
Setting up your VPS
Once you have your VM provisioned, you will need to install Squid.
The following instructions assume that you have a basic knowledge of Linux
- SSH into your VM & install Squid (no need for
sudoif your user has the required system-level permissions):
sudo apt update
sudo apt install squid
- Edit
/etc/squid/squid.conf, delete everything inside, and paste the following clean, secure setup. Review and change as necessary :
# ----------------------------------------------------
# AUTHENTICATION
# ----------------------------------------------------
auth_param basic program /usr/lib/squid/basic_ncsa_auth /etc/squid/passwords
auth_param basic children 5
auth_param basic realm My Private VPS Proxy
auth_param basic credentialsttl 2 hours
acl authenticated_users proxy_auth REQUIRED
# ----------------------------------------------------
# ACCESS CONTROL LISTS (ACLs)
# ----------------------------------------------------
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 443 # https
acl CONNECT method CONNECT
# ----------------------------------------------------
# SECURITY RULES (Order matters!)
# ----------------------------------------------------
# Deny requests to certain unsafe ports
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
# Only allow cachemgr access from localhost
http_access allow localhost manager
http_access deny manager
# ALLOW your authenticated users, deny everything else
http_access allow authenticated_users
http_access allow localhost
http_access deny all
# ----------------------------------------------------
# NETWORK SETTINGS
# ----------------------------------------------------
# Obfuscate the default 3128 port to prevent basic automated
bots. Change http_port to a random number
http_port 44321
# ----------------------------------------------------
# PERFORMANCE & PRIVACY
# ----------------------------------------------------
# Disable local caching if you have a low-spec VPS to save RAM/Disk
cache deny all
# Hide your original home/office IP from websites you visit (Anonymity)
forwarded_for off
request_header_access X-Forwarded-For deny all
request_header_access Via deny all
# Core settings
coredump_dir /var/spool/squid
Verify the changes for errors:
sudo squid -k parseInstall Apache utilities (which includes the htpasswd tool):
sudo apt install apache2-utils -yCreate the password file and add your desired user (replace your_username with whatever name you want):
sudo htpasswd -c /etc/squid/passwords your_usernameStart and enable the service to run on boot:
sudo systemctl start squid
sudo systemctl enable squid
If any issue, restart squid
sudo systemctl restart squidOnce done, edit your VPS firewall to allow http_port ingress over TCP (port 44321 in the sample squid.conf script).
Setting up your system to use the proxy server
MacOS
- Open
System Settings -> Networkand select currently connected network. - Select
Detailsand configure your proxy settings underProxies -> Secure web proxy (HTTPS).- Enable
Proxy server requires password - Enter the credentials for your proxy server (the username/password set via
htpasswd)
- Enable
All set! I hope you found this guide useful.