McProxy commands
With the plugin, use /mcproxy in game or mcproxy in the console. With standalone, type the command straight into the console.
The command list
status | Listener, connections and traffic |
|---|---|
connections | Who is connected, where to, and their traffic |
info | The SOCKS5 and HTTP/HTTPS settings to give your client |
setport <port> | Move the proxy to another allocated port |
setpublicip <ip|none> | The public IP told to UDP clients, for NAT, Docker and panels |
udp <on|off> | Turn UDP relaying on or off |
newpassword | Replace the password with a new random one. It is saved to the config file, never shown. |
enable / disable | Start or stop the proxy |
reload | Apply edits you made to the config file by hand |
help | Show the command list |
Changes are saved to the config file and applied immediately. They close open proxy connections, so clients have to reconnect. In game, the commands need the mcproxy.admin permission, which operators have by default.
Standalone also has stop, and its setport and setpublicip accept auto. On Pterodactyl the port comes from the panel, so change the primary allocation there instead of using setport.
The config file
You rarely need to edit it by hand, but everything is in one file: plugins/MCProxy/config.yml for the plugin, mcproxy.properties for standalone. The settings are the same in both. After editing, run reload.
| Setting | Default | What it does |
|---|---|---|
listen.port | 1080 plugin auto standalone | Port the proxy listens on, for TCP and UDP. |
listen.bind-address | 0.0.0.0 | Local interface to bind. Leave it alone on panel and container hosting. |
udp.enabled | true | SOCKS5 UDP relaying. Turn it off on hosts that only allow TCP. |
udp.advertised-address | empty plugin auto standalone | Public IP told to UDP clients. Set it behind NAT or Docker. |
authentication.username | mcproxy | Login name for SOCKS5 and HTTP. |
authentication.password | generated | Written on first start. Must be at least 16 characters. |
limits.max-connections | 64 | Connections allowed at the same time. |
limits.max-connections-per-ip | 8 | Connections allowed from one client IP. |
limits.idle-timeout-seconds | 300 | Closes a connection after this long with no traffic in either direction. |
access.allowed-client-cidrs | empty | Client IPs allowed to connect. Empty means anyone with the login. |
access.allow-private-destinations | false | Lets clients reach loopback and LAN addresses. Leave it off unless you need it. |
access.allowed-destination-ports | empty | Destination ports clients may use, for TCP and UDP. Empty means any. |
The full default config.yml for the plugin
# Allocate/forward this port for TCP AND UDP through your host/firewall.
# TCP automatically accepts SOCKS5, HTTP forwarding and HTTPS CONNECT tunnels.
# HTTP Proxy-Authorization uses the same username/password as SOCKS5.
# After editing, run /mcproxy reload (or mcproxy reload in the console).
# This applies all settings and restarts proxy connections without restarting Minecraft.
# Common settings can also be changed without editing: see /mcproxy help
# (setport, setpublicip, udp, newpassword, enable, disable). Those commands rewrite this file.
enabled: true
listen:
# Bind to local interfaces, NOT your public NAT address or a Minecraft SRV name.
# Keep 0.0.0.0 on Pterodactyl/Pelican and other container or panel hosting.
bind-address: '0.0.0.0'
port: 1080
udp:
# UDP ASSOCIATE shares listen.port's number. Disable for hosts allowing TCP only.
enabled: true
# Empty = the TCP connection's local server address. Behind NAT/containers, set
# the numeric public IP that clients can reach (not a domain or 0.0.0.0).
advertised-address: ''
# 0 = listen.port. Override only if external UDP forwarding uses another port.
advertised-port: 0
max-destinations-per-association: 64
queue-packets: 32
authentication:
username: 'mcproxy'
# A random password is written here when the config is first created, and again
# by /mcproxy newpassword. It is never printed; read it from this file.
# Authentication is mandatory. Existing empty passwords are rejected.
password: ''
limits:
max-connections: 64
max-connections-per-ip: 8
handshake-timeout-seconds: 10
connect-timeout-seconds: 10
# Time with no traffic in EITHER direction, including stalled writes.
idle-timeout-seconds: 300
access:
# Empty = any source IP with valid credentials. Example: ['203.0.113.5/32']
allowed-client-cidrs: []
# False blocks loopback, LAN, link-local, multicast and reserved destinations.
# Set true only if authenticated clients need to reach internal services.
allow-private-destinations: false
# Applies to TCP AND UDP destinations. Empty = any port. Example: [53, 80, 443]
allowed-destination-ports: []
The full default mcproxy.properties for standalone
# MCProxy Standalone. Edit this file and enter "reload" in the console.
# TCP automatically accepts SOCKS5, HTTP forwarding and HTTPS CONNECT tunnels.
# HTTP Proxy-Authorization uses the same username/password as SOCKS5.
# Pterodactyl's SERVER_PORT always wins. Otherwise auto reads server.properties,
# then defaults to 1080. Outside Pterodactyl you can set an explicit port here.
enabled=true
listen.bind-address=0.0.0.0
listen.port=auto
# Both protocols use the same port. Only a local UDP bind failure triggers fallback;
# an upstream firewall blocking UDP cannot be detected from inside the container.
udp.enabled=true
udp.fallback-to-tcp=true
# auto: MCPROXY_PUBLIC_IP, public SERVER_IP, HTTPS public IPv4 lookup, local address.
# Set a numeric IP here if your inbound allocation differs from outbound public IP.
udp.advertised-address=auto
udp.discover-public-ip=true
udp.advertised-port=0
udp.max-destinations-per-association=64
udp.queue-packets=32
authentication.username=mcproxy
# Generated once on first startup. Passwords are never printed in the console.
authentication.password=(generated on first start)
limits.max-connections=64
limits.max-connections-per-ip=8
limits.handshake-timeout-seconds=10
limits.connect-timeout-seconds=10
limits.idle-timeout-seconds=300
# Comma-separated values; empty means unrestricted authenticated clients/ports.
access.allowed-client-cidrs=
access.allow-private-destinations=false
access.allowed-destination-ports=