A SOCKS5 proxy deployed into your VPC with CloudFormation. Reach any private host and port without a static map. The initial password is the instance ID, and the first SSH login must replace it.
This CloudFormation product launches a SOCKS5 proxy in a public subnet of your VPC. Developers point their tools at one endpoint. Each connection names the private host and port, so a new IP address, DNS name, or port does not require a configuration change or a reboot.
The image contains no password. The initial SOCKS5 username is socks. The initial password is the EC2 instance ID. It is created on first boot and is not returned in stack outputs. SSH password login is disabled. Sign in with the EC2 key pair you selected. That first interactive login must replace the instance ID with a new SOCKS5 password. The instance ID stops working as a password after the change.
TCP CONNECT and UDP ASSOCIATE are both supported. Domain names are resolved inside the VPC, so private DNS names work when clients send the hostname to the proxy. The proxy dials targets from its private address. Source and destination check stays enabled.
Inbound SSH and SOCKS are limited to the CIDR you enter when you launch the stack. There is no default that opens those ports to the internet. On each private target, allow inbound traffic from the proxy security group printed in the stack outputs.
Example, after you have replaced the initial password:
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
You pay one usage-based rate for the SOCKS5 Proxy Server, billed hourly on a t3.small instance. There is a single pricing dimension, so no tiers or size choices to compare. The software fee accrues for each hour the instance runs, and separate AWS infrastructure charges may apply. This proxy deploys in a public subnet of your VPC and lets developers reach private IPs, DNS names, or ports from one endpoint. Pricing scales only with runtime hours.
Top-of-mind questions for buyers
What resources do I get with the t3.small hourly rate?
The rate runs the proxy on one t3.small instance in a public subnet of your VPC. You pay the software fee for each hour the instance runs. Separate AWS infrastructure charges for the instance and network apply on top of the software fee.
Am I charged when the proxy instance is stopped?
The software fee meters running time only, so a fully stopped instance stops accruing that fee. Charges resume when the instance runs again. Underlying AWS storage or other resource fees may still apply while the instance is stopped, since those are separate from the software fee.
Do I pay more for reaching more private hosts through the proxy?
No. Cost scales only with runtime hours on the t3.small instance. Developers name the private host and port on each request, so you reach any private IP, DNS name, or port from one endpoint. The number of destinations you connect to does not change the hourly fee.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Deploys one t3.small instance in a public subnet you choose. The image contains no password. The initial SOCKS5 password is the EC2 instance ID and is not a stack output. SSH password login is disabled. The first interactive SSH login must replace that password. Inbound TCP 22, TCP 1080, and UDP 1080 are limited to the CIDR you provide. The stack outputs SocksUsername and ProxyAddress when the proxy is listening.
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Version release notes
The initial SOCKS5 password is the EC2 instance ID. It is created on first boot and is not stored in the image. The first SSH login must replace it. The instance ID stops working as a password after that change. SSH password login is disabled.
Additional details
Usage instructions
Template components
CloudFormation template
Usage instructions
Launch the CloudFormation stack in a public subnet of the VPC you need to reach. Select an EC2 key pair. Enter a developer CIDR for RemoteAccessCidr. Do not use 0.0.0.0/0.
Wait until the stack status is CREATE_COMPLETE. The stack finishes only after the proxy is listening.
Open the stack outputs. SocksUsername is socks. ProxyAddress is the public host and port 1080. The initial SOCKS5 password is the EC2 instance ID from the EC2 console. It is not a stack output.
SSH to the instance as ubuntu with your key pair. The first interactive login must replace the instance ID with a SOCKS5 password of at least 16 characters. The instance ID stops working as a password after that change. Non-interactive SSH does not change the password.
On each private target, allow inbound traffic from the SecurityGroupId output.
Point clients at the proxy and send hostnames to it. Example: curl -U socks:NEW_PASSWORD --socks5-hostname PROXY_ADDRESS http://10.0.1.20:8080/
Our team is happy to assist with deployment and configuration issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Anonymous HTTP/SOCKS4/SOCKS5 Proxy Server on Linux for internet access, with a Web Interface and RADIUS accounting and authentication by username and password. When deploying this proxy server via a CloudFormation template, a configuration with two Elastic IPs is being created, allowing for IP address rotation.
This is an easy-to use and effective proxy server to bypass regional internet restrictions. Based on Xray, it uses the modern, lightweight, and efficient VLESS protocol together with the REALITY traffic obfuscation technology, masking traffic as regular HTTPS and making it difficult for deep packet inspection (DPI) systems to detect, ensuring high performance and censorship bypass. This technology is currently considered the most effective solution for bypassing internet censorship in countries where authorities restrict the use of the internet.
This is a repackaged open source software product wherein additional charges apply for a Linux web security console. A production NGINX reverse proxy that assesses its own security, explains what it finds, and fixes what is wrong without breaking what is working. Nginx can be used for web serving, reverse proxying, caching, load balancing, media streaming, & more.
Nginx is an open-source web server that is mainly used as a reverse proxy or HTTP cache. This product has charges associated with it for seller support and pre-installed MySQL database ready to install out of the box.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.