# Proxy for Tor bridge

**URL:** https://forum.torproject.org/t/proxy-for-tor-bridge/8602
**Category:** Relay Operator
**Tags:** tor
**Created:** [August 2, 2023, 3:44pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602 "2023-08-02T15:44:05Z")
**Posts on this page:** 17
**Page:** 1

<div class="post-metadata">

### Author: ![hack3rcon](https://forum.torproject.org/user_avatar/forum.torproject.org/hack3rcon/32/3606_2.png) [@hack3rcon](https://forum.torproject.org/u/hack3rcon)
#### Post date: [August 2, 2023, 3:44pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/1 "2023-08-02T15:44:05Z")

</div>

Hello,  
How can I put a Tor bridge behind a proxy, so that it is not directly connected to the Internet? Something like a reverse proxy that is used for websites.

Thank you.

---

<div class="post-metadata">

### Author: ![hack3rcon](https://forum.torproject.org/user_avatar/forum.torproject.org/hack3rcon/32/3606_2.png) [@hack3rcon](https://forum.torproject.org/u/hack3rcon)
#### Post date: [August 7, 2023, 11:53am UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/2 "2023-08-07T11:53:19Z")

</div>

Hello,  
Should I use port forwarding technique?

Thank you.

---

<div class="post-metadata">

### Author: ![WofWca](https://forum.torproject.org/user_avatar/forum.torproject.org/wofwca/32/2302_2.png) [@WofWca](https://forum.torproject.org/u/WofWca)
#### Post date: [August 12, 2023, 2:40pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/3 "2023-08-12T14:40:27Z")

</div>

Is this an attempt to achieve this?:

> [@How to set the username and password to use Tor?](https://forum.torproject.org/t/how-to-set-the-username-and-password-to-use-tor/8381):
>
> Hello, If someone has the IP address and port of my Tor server, they can connect to it and get services. How can I authenticate it? Thank you.

> [@hack3rcon](#):
>
> so that it is not directly connected to the Internet?

By this you mean that it’s not reachable from the outside, or that the Tor bridge itself cannot initiate outgoing connections? If it’s the former, then there are two ways:

- just ensure that your firewall blocks incoming connections to the bridge’s port (`ORPort`, `ServerTransportListenAddr`), and set up a reverse proxy on an open port.
- Set up listen address of the bridge to be `localhost` (I think the params are `ORPort` and `ServerTransportListenAddr`, although you probably won’t need obfuscation anyway in this case, and set up a reverse proxy on an open port.

Related: `man tor`: `ORPort`: `NoListen` and `NoAdvertise` flags, and `BridgeDistribution none`.

Is this what you’re asking?

---

<div class="post-metadata">

### Author: ![hack3rcon](https://forum.torproject.org/user_avatar/forum.torproject.org/hack3rcon/32/3606_2.png) [@hack3rcon](https://forum.torproject.org/u/hack3rcon)
#### Post date: [August 19, 2023, 7:58pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/4 "2023-08-19T19:58:25Z")

</div>

Hello,  
Not really.  
I mean the following plan:

```auto
Tor Server (Proxy or Bridge) ---> Proxy ---> Internet
```

How to setup a reverse proxy for an open port?

---

<div class="post-metadata">

### Author: ![capole](https://forum.torproject.org/letter_avatar_proxy/v4/letter/c/f6c823/32.png) [@capole](https://forum.torproject.org/u/capole)
#### Post date: [August 22, 2023, 12:24pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/5 "2023-08-22T12:24:21Z")

</div>

To be honest I wonder if that would be possible by setting up Nginx Proxy Manager or Traefik. Maybe it is possible by setting up a configuration with `NoAdvertise` and `NoListen`?

That would be a cool little project to try, ngl. I don’t really see any benefit from doing that other than learning how it would work, though.

---

<div class="post-metadata">

### Author: ![WofWca](https://forum.torproject.org/user_avatar/forum.torproject.org/wofwca/32/2302_2.png) [@WofWca](https://forum.torproject.org/u/WofWca)
#### Post date: [August 22, 2023, 5:54pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/6 "2023-08-22T17:54:00Z")

</div>

> [@hack3rcon](#):
>
> I mean the following plan:
> 
> ```auto
> Tor Server (Proxy or Bridge) ---> Proxy ---> Internet
> 
> ```

Then I think you got to use `Socks5Proxy`:

> [@How to set the username and password to use Tor?](https://forum.torproject.org/t/how-to-set-the-username-and-password-to-use-tor/8381/9):
>
> Socks5Proxy host[:port] Tor will make all OR connections through the SOCKS 5 proxy at host:port (or host:1080 if port is not specified). Socks5ProxyUsername username Socks5ProxyPassword password If defined, authenticate to the SOCKS 5 server using username and password in accordance to RFC 1929. Both username and password must be between 1 and 255 characters. These are used, when your Tor needs to connect through a proxy to reach the internet - not for Tor to provide a SOCKS-proxy.

Is it still not it? I don’t understand why you call it a reverse proxy. Isn’t it a regular proxy?

---

<div class="post-metadata">

### Author: ![esev](https://forum.torproject.org/letter_avatar_proxy/v4/letter/e/aeb1de/32.png) [@esev](https://forum.torproject.org/u/esev)
#### Post date: [August 23, 2023, 11:19am UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/7 "2023-08-23T11:19:29Z")

</div>

There are two conflicting things here:

1. The direction of the arrows indicates a connection is being made from a Tor Server to the internet. In that case this would be a forward proxy.
2. The words “reverse proxy” and “open port” indicate that a connection is coming from the internet and going to the Tor Server.

Could you clarify a bit more?

---

<div class="post-metadata">

### Author: ![esev](https://forum.torproject.org/letter_avatar_proxy/v4/letter/e/aeb1de/32.png) [@esev](https://forum.torproject.org/u/esev)
#### Post date: [August 23, 2023, 11:19am UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/8 "2023-08-23T11:19:36Z")

</div>

> [@capole](#):
>
> To be honest I wonder if that would be possible by setting up Nginx Proxy Manager or Traefik.

This would be a perfect scenario for a WebTunnel bridge. I am running one of these with Traefik today. I use a higher-priority Traefik router rule for the WebTunnel path. If someone visits www.domain.tld they get the normal website. If Tor visits www.domain.tld/TOR\_WEBTUNNEL\_PATH it connects to the bridge.

I have tested, and this also works with CF tunnels.

```auto
  nginx:
    image: nginx
    labels:
      - traefik.enable=true
      - traefik.http.routers.nginx.entrypoints=https-443
      - traefik.http.routers.nginx.rule=Host(`www.${DOMAIN}`)
      - traefik.http.services.nginx.loadbalancer.server.port=80
    volumes:
      - /archive/www/private:/usr/share/nginx/html:ro
    restart: unless-stopped
    networks:
      frontend:

  tor:
    image: thetorproject/webtunnel-bridge:latest
    entrypoint: ["/usr/sbin/tor", "-f", "/etc/tor/torrc"]
    security_opt:
      - apparmor=docker-tor
    mem_limit: 512m
    memswap_limit: 512m
    labels:
      - traefik.enable=true
      - traefik.http.routers.tor-webtunnel.entrypoints=https-443
      - traefik.http.routers.tor-webtunnel.rule=Host(`www.${DOMAIN}`) && PathPrefix(`/${TOR_WEBTUNNEL_PATH}`)
      - traefik.http.routers.tor-webtunnel.priority=999
      - traefik.http.services.tor-webtunnel.loadbalancer.server.port=8080
    volumes:
      - /etc/timezone:/etc/timezone:ro
      - /etc/localtime:/etc/localtime:ro
      - ${DEV_PATH}/tor/torrc:/etc/tor/torrc:ro
      - ${CONFIG_PATH}/tor:/var/lib/tor
    restart: unless-stopped
    networks:
      tor:

```

---

<div class="post-metadata">

### Author: ![hack3rcon](https://forum.torproject.org/user_avatar/forum.torproject.org/hack3rcon/32/3606_2.png) [@hack3rcon](https://forum.torproject.org/u/hack3rcon)
#### Post date: [August 29, 2023, 11:52am UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/9 "2023-08-29T11:52:54Z")

</div>

Hello,  
Thank you so much for your reply.  
1- When you set up a Tor bridge, then connections from the Internet come to the Tor server. Isn’t it?

2- I just want to hide my Tor server behind another server. Instead of connecting directly to the Tor bridge server, clients connect to another server that sends clients’ requests to the main Tor server.

---

<div class="post-metadata">

### Author: ![hack3rcon](https://forum.torproject.org/user_avatar/forum.torproject.org/hack3rcon/32/3606_2.png) [@hack3rcon](https://forum.torproject.org/u/hack3rcon)
#### Post date: [August 29, 2023, 11:52am UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/10 "2023-08-29T11:52:57Z")

</div>

Hello,  
I mean the following plan:

```auto
Tor Server (Proxy or Bridge) ---> Proxy ---> Internet

```

Can using `HTTPSProxy host[:port]` statement in the Tor bridge configuration solve the problem?

---

<div class="post-metadata">

### Author: ![hack3rcon](https://forum.torproject.org/user_avatar/forum.torproject.org/hack3rcon/32/3606_2.png) [@hack3rcon](https://forum.torproject.org/u/hack3rcon)
#### Post date: [September 6, 2023, 1:03pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/11 "2023-09-06T13:03:49Z")

</div>

Hello,  
Thank you so much for your reply.  
I’m sorry if I couldn’t express my meaning correctly. I want to put the Tor server behind another server to increase its security. It means that the Tor server should not be directly connected to the Internet.

```auto
Tor Server (Proxy or Bridge) ---> Intermediate Server ---> Internet
```

How should the settings of this intermediate server be? Clients must connect to this intermediate server to use Tor.

---

<div class="post-metadata">

### Author: ![boldsuck](https://forum.torproject.org/user_avatar/forum.torproject.org/boldsuck/32/1370_2.png) [@boldsuck](https://forum.torproject.org/u/boldsuck)
#### Post date: [September 6, 2023, 8:23pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/12 "2023-09-06T20:23:18Z")

</div>

> [@hack3rcon](#):
>
> `Tor Server (Proxy or Bridge) ---> Intermediate Server ---> Internet`

I can’t follow that. A typical tor cirquit with a Tor bridge is constructed like this to reach a page on the clearnet. Hidden services in the Tor network not considered.  
(The connection is encrypted from the browser to the exit)

Tor Browser\<-\>OBFS4 Proxy\<-\>OBFS4 Proxy\<-\>Tor Bridge\<-\>Tor Middle Router\<-\>Tor Exit Router\<-\>Internet

---

<div class="post-metadata">

### Author: ![hack3rcon](https://forum.torproject.org/user_avatar/forum.torproject.org/hack3rcon/32/3606_2.png) [@hack3rcon](https://forum.torproject.org/u/hack3rcon)
#### Post date: [September 7, 2023, 1:37pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/13 "2023-09-07T13:37:48Z")

</div>

Hello,  
Thanks again.  
Why does this `Intermediate Server` make the Tor not work properly? Tor is not only directly connected to the Internet. Something like an http proxy (\*\* TinyProxy\*\*).

---

<div class="post-metadata">

### Author: ![WofWca](https://forum.torproject.org/user_avatar/forum.torproject.org/wofwca/32/2302_2.png) [@WofWca](https://forum.torproject.org/u/WofWca)
#### Post date: [September 8, 2023, 1:33pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/14 "2023-09-08T13:33:04Z")

</div>

Are you sure that [my first reply](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/3) is not what you want?

> [@hack3rcon](#):
>
> How to setup a reverse proxy for an open port?

I might have used the wrong term here? Not sure.  
You can set up `sshd` on the server, then connect to it from your PC with `ssh -L any_local_port:localhost:tor_bridge_port`. This way, connections to `localport` on your local machine will be forwarded to `torport` of the server.

If it’s still not it, I think you need to better explain how threats that you are to protect yourself from would work, and how exactly you would use your setup.

---

<div class="post-metadata">

### Author: ![hack3rcon](https://forum.torproject.org/user_avatar/forum.torproject.org/hack3rcon/32/3606_2.png) [@hack3rcon](https://forum.torproject.org/u/hack3rcon)
#### Post date: [September 8, 2023, 2:37pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/15 "2023-09-08T14:37:56Z")

</div>

Hello,  
Thanks again.  
I want my Tor Proxy Server or Tor Bridge not directly accessing the Internet, but connecting to another server and getting the internet there. When you launch an Apache reverse proxy server, then you hide your real Apache web server behind another server. I want to do the same with the Tor. How should this Intermediate server be configured? Should I install the **TinyProxy** or **Squid-cache** on it, then use the **HTTPProxy host[:port]** statement in the Tor configuration to use the internet of that intermediate server?

---

<div class="post-metadata">

### Author: ![boldsuck](https://forum.torproject.org/user_avatar/forum.torproject.org/boldsuck/32/1370_2.png) [@boldsuck](https://forum.torproject.org/u/boldsuck)
#### Post date: [September 8, 2023, 7:18pm UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/16 "2023-09-08T19:18:36Z")

</div>

> [@hack3rcon](#):
>
> I want my Tor Proxy Server or Tor Bridge not directly accessing the Internet,

That doesn’t make any sense at all. A Tor bridge must be accessible **from** the Internet, otherwise it won’t work. Outgoing traffic is not filtered on relays anyway. You have the option to configure a private hidden bridge and only give the bridgeline to certain people.

A Tor proxy (or several) runs on your localhost or on a device (gateway-Router, raspberry) for network-wide access and TorBrowser, $client-software connect to it.

I think you’re looking for ‘How to setup Tor as transparent proxy for my network’  
Have you ever looked at all the config options in` man torrc` especially SocksPort & TransPort?

---

<div class="post-metadata">

### Author: ![hack3rcon](https://forum.torproject.org/user_avatar/forum.torproject.org/hack3rcon/32/3606_2.png) [@hack3rcon](https://forum.torproject.org/u/hack3rcon)
#### Post date: [September 11, 2023, 10:11am UTC](https://forum.torproject.org/t/proxy-for-tor-bridge/8602/17 "2023-09-11T10:11:48Z")

</div>

Hello,  
Thanks again.  
My Tor proxy configuration is:

```auto
SocksPort 172.21.50.61:9050
SocksPolicy accept 172.21.50.0/25
RunAsDaemon 1
DataDirectory /var/lib/tor

```

Clients connect to my server’s IP address and receive service. I have placed this server behind an HTTP server. what’s wrong?
