Skip to content

Forward Proxy on Debian 13 (Linode) ​

Referred from this official doc.

By default, a Linode server within a VPC cannot access other networks, or the internet. However, you'll need internet access to download and install software packages (for example, updating apt packages).

To achieve this, you need to either enable NAT or send traffic to a forward proxy, which acts as a gateway between the VPC and the public internet. NAT allows the server to present a public IP address to the wider network while using a VPC-based address inside the private network. A proxy, on the other hand, is a general term for any intermediate device or application lying between a client and the target server.

Using the forward proxy is recommended, as it greatly enhances security by hiding the original addressing information. To the destination server, the request appears to come directly from the forward proxy; the private IP addresses of servers inside the VPC are never exposed.

NOTE

This setup uses a Public Subnet, so the proxy server can access the internet. The other servers in your VPC (like your database) will remain safely in a Private Subnet and route their outbound traffic through this proxy.

NOTE

You can follow the steps in this guide as written, but replace the following placeholders with your own names:

  • <Forward Proxy Server IP Address>: Your Linode's Public IP Address
  • non_root: Your non-root username

You should also update the IP addresses and subnet IP ranges, to match your VPC settings.

Launch a Linode (Debian) for Forward Proxy ​

ParameterValue
Regionin-maa (Chennai)
OSDebian (Debian 13 as of 22-Feb-2026)
PlanNanode 1 GB (Shared CPU)
LabelGive your preferred label (Label can't have spaces)
Root PasswordCreate a Strong Password and store it somewhere safe
SSH KeysYou can add an existing SSH key or add this later when you deploy a new server
Disk EncryptionEnable
VPCSelect the VPC your other servers use (or create one if this is your first server)
SubnetSelect a different subnet under the same VPC
Auto-assign a VPC IPv4Enable
Allow public IPv4 accessEnable
Network Interface TypeLinode Interfaces
VPC Interface FirewallCreate and assign a Firewall (that allows all outbound and no inbound - configured later in this guide)
BackupsDisable

Upgrade Packages ​

TIP

Use the LISH Console to connect to the Linode server. The firewall blocks all inbound traffic until you configure it, so you can't SSH in from your local machine yet.

Upgrade the packages on the server:

shell
sudo apt update && sudo apt upgrade -y

Set Timezone ​

Install all locales first to disable locale warnings:

shell
sudo apt install locales-all

All new Linode servers are set to UTC time by default. To change it to IST, use:

shell
timedatectl set-timezone 'Asia/Kolkata'

Confirm the date by running the date command in the terminal.

Configure Firewall ​

Add the following inbound rules to the Forward Proxy Firewall to explicitly allow the necessary internal and administrative connections:

Rule PurposeLabelProtocolPortsIP / NetmaskAction
Allow ICMP (ping) traffic from other serversChoose a labelICMPLeave blankPrivate subnet IP range (Ex: 10.0.0.0/24)Accept
Allow proxy traffic from other serversChoose a labelTCPCustom (8080)Private subnet IP range (Ex: 10.0.0.0/24)Accept
Allow SSH connections from admin systemsChoose a labelTCPSSH (22)Admin system's IP address (use /32)Accept

Disable Root Login ​

IMPORTANT

The LISH Console does not use SSH, so PermitRootLogin no and PasswordAuthentication no do not apply to it. Anyone with access to your Linode account can reach a root login prompt through LISH using the root password. Your Linode account credentials and 2FA are therefore the real security perimeter for this server - enable 2FA and store the root password in a password manager.

First, create a limited user account:

shell
adduser non_root
# You'll be prompted to provide password

Add the new user to the sudo group for administrative privileges:

shell
adduser non_root sudo

Exit the session and SSH back into the server as your new user (from local Mac machine):

shell
exit
ssh non_root@<Forward Proxy Server IP Address>

Create an SSH directory and add the public key of your local Mac machine to the authorized keys file:

shell
mkdir ~/.ssh && chmod 700 ~/.ssh && vi ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys

Disable Root login and Password Authentication:

shell
sudo vi /etc/ssh/sshd_config
# Set `PermitRootLogin` to `no`
# Set `PasswordAuthentication` to `no`
# Set `AddressFamily` to `inet` (to disable IPv6 connections)

Validate the configuration before restarting, and keep your current session open in case something is wrong:

shell
sudo sshd -t

Finally, restart the SSH service to apply the changes:

shell
sudo systemctl restart ssh

TIP

On Debian 13, SSH is socket-activated and the unit is named ssh. If you changed the listening address or port, also restart ssh.socket.

Install and Configure Apache ​

Install Apache package:

shell
sudo apt install apache2 -y

Enable the Apache modules that provide the forward proxy functionality:

shell
sudo a2enmod proxy proxy_http proxy_connect

Create and edit an Apache configuration file to store the forward proxy settings:

shell
sudo vi /etc/apache2/sites-available/fwd-proxy.conf

Use following config. Be sure to change the IP addresses to match your VPC setup, where 10.0.2.2 represents the Proxy Server's Private IP and 10.0.0.0/24 represents the private subnet IP range of the servers that will use the proxy.

AllowCONNECT 443 is required for HTTPS: Debian's proxy_connect module ships with AllowCONNECT 0, which blocks every HTTPS tunnel with a 403 until you allow the port here:

apache
Listen 10.0.2.2:8080
<VirtualHost *:8080>
    ServerAdmin webmaster@localhost
    DocumentRoot /var/www/html
    ErrorLog ${APACHE_LOG_DIR}/fwd-proxy-error.log
    CustomLog ${APACHE_LOG_DIR}/fwd-proxy-access.log combined
    ProxyRequests On
    ProxyVia On
    AllowCONNECT 443
    <Proxy "*">
        Require ip 10.0.0.0/24
    </Proxy>
</VirtualHost>

Set the owner of the file to root:root and set the correct file permissions:

shell
sudo chown root:root /etc/apache2/sites-available/fwd-proxy.conf
sudo chmod 0644 /etc/apache2/sites-available/fwd-proxy.conf

Enable the Apache configuration file that was created in a previous step:

shell
sudo a2ensite fwd-proxy

Nothing in this setup uses Apache's default site, so disable it and stop Apache from listening on port 80. This keeps the public IP from serving anything even if the firewall is ever misconfigured:

shell
sudo a2dissite 000-default
sudo sed -i 's/^Listen 80$/# Listen 80/' /etc/apache2/ports.conf

Check the configuration for errors, then restart the Apache server to activate it:

shell
sudo apache2ctl configtest
sudo systemctl restart apache2

Confirm that Apache is only listening on the proxy port:

shell
# Should only show 10.0.2.2:8080
sudo ss -tlnp | grep apache2

Test connectivity ​

Connect to another Linode, preferably a server in a private subnet, using Launch LISH Console link.

Add the following lines to the apt proxy configuration so both http:// and https:// sources go through the proxy:

shell
sudo tee /etc/apt/apt.conf.d/proxy.conf > /dev/null <<EOF
Acquire::http::Proxy "http://10.0.2.2:8080";
Acquire::https::Proxy "http://10.0.2.2:8080";
EOF

Test connectivity through forward proxy using:

shell
sudo apt update && sudo apt upgrade -y

To transmit curl requests, append the --proxy parameter to the request. Test both HTTP and HTTPS:

shell
# Should return the HTML content
curl --proxy 10.0.2.2:8080 http://www.google.com

# Should also return the HTML content (a "CONNECT tunnel failed, response 403" error means AllowCONNECT is missing)
curl --proxy 10.0.2.2:8080 https://www.google.com

At this point, you have a working Forward Proxy server.