SOCKS proxy with tun2proxy | tun2socks fails with Connection refused (os error 111)
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 42/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- docker, go
- Domain
- networking
Research direction
Reproduce the setup with the urnetwork proxy, the tun2proxy container, and the Alpine container, then start with tun2proxy/tun2socks UDP DNS handling. Compare the failing DNS path with the working Firefox SOCKS5 path and inspect the reported connection-refused behavior. Done means DNS queries and TCP connections from the attached container are routed successfully through the SOCKS5 proxy.
Written by the indexing model from the issue text.
Description
Summary
When passing a working SOCKS5 proxy (from urnetwork) into tun2proxy or tun2socks, all outbound DNS requests fail with Connection refused (os error 111). The same proxy works fine when tested directly in Firefox.
Steps to Reproduce
1.) Start the urnetwork proxy:
go run . --user-auth <redacted> --password <redacted> --country "United States"
2.) Verify proxy works in Firefox:
Configure Firefox to use 127.0.0.1:9999 as SOCKS5 proxy
Browsing works as expected
3.) Run tun2proxy container:
docker run -it --rm --name tun2proxy --privileged \
ghcr.io/tun2proxy/tun2proxy-ubuntu:latest \
--proxy socks5://127.0.0.1:9999
4.) Connect another container through it:
docker run -it --rm --network=container:tun2proxy alpine sh
5.) Inside the Alpine container:
apk update
Actual Behavior
- Package fetch fails with DNS resolution errors:
WARNING: updating and opening https://dl-cdn.alpinelinux.org/... temporary error (try again later)
- tun2proxy logs show repeated UDP DNS attempts ending in connection refused:
[INFO tun2proxy] Beginning #0 UDP 10.0.0.33:46259 -> 8.8.8.8:53
[INFO tun2proxy] Ending #0 UDP 10.0.0.33:46259 -> 8.8.8.8:53 with "Connection refused (os error 111)"
- No corresponding traffic appears in the urnetwork proxy logs.
Expected Behavior
- DNS queries and TCP connections should be tunneled through the SOCKS5 proxy, allowing the Alpine container to resolve and fetch packages.
Notes
- Direct SOCKS5 usage in Firefox works fine → proxy itself is healthy.
- Failure only occurs when traffic is routed through tun2proxy / tun2socks.
- Issue seems specific to UDP (DNS) handling.
- Dominant language
- Go
- Stars
- 9
- Forks
- 10
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from urnetwork/proxy
Similar issues
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
AOSSIE-Org/DebateAI#611 ·
Maintainers usually reply within 3 days
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
MHSanaei/3x-ui#6737 · 1 comment ·
Maintainers usually reply within 1 day
-
terraform-provider
Difficulty 2/5 1-3 hours Newbie friendliness 73/100
ClickHouse/terraform-provider-clickhousedbops#281 ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
open-telemetry/opentelemetry-go-compile-instrumentation#1450 ·
Maintainers usually reply within 2 days