Tutorial8 October 20266 min read

BiglyBT proxy settings: SOCKS5, the peer-source trap, and the NAT warning

BiglyBT proxy settings: the exact SOCKS5 options, the peer sources and DHT plugin that leak your address, why you will see a NAT warning, and the meter check.

BiglyBT proxy settings are under Tools > Options > Connection > Proxy Options, shown in advanced mode. Tick tracker proxying, tick "I have a SOCKS proxy", tick peer proxying, choose SOCKS version 5 and enter your login. Then close two side doors the BiglyBT wiki warns about: extra peer sources and the Mainline DHT plugin. Expect a "NAT problem" warning afterwards; behind a proxy it is normal.

BiglyBT documents its proxy behaviour more plainly than any other client we looked at, so this page can quote it rather than guess.

Do you need the proxy at all?

For most of what BiglyBT is used for, no. Long-term seeding of open-source distributions, fetching an Internet Archive collection or a research dataset: all of that works without a proxy, and any file with an HTTP mirror is cheaper to fetch directly than through a metered one.

Use a proxy when you want BiglyBT's connections to leave from an address other than your own while the rest of the computer stays put. Keep to content you may share. Sharing files without the right to is not allowed on ProxyPanda, and our acceptable use policy puts staying within the law on you. Peer-to-peer traffic for lawful content is fine on our residential proxies and on dedicated ISP or datacenter IPs with no traffic cap. If what worries you is copyright enforcement, BiglyBT's own wiki covers VPN setups, and we say more about that at the end.

What a proxy will not do in BiglyBT

These come from BiglyBT's wiki page "Proxies and VPNs" and from our own product. Read them before ticking anything.

  • An HTTP proxy covers trackers and HTTP seeds only. The wiki: "HTTP proxying does NOT affect normal peer-to-peer connections". For peers you need SOCKS.
  • SOCKS carries outgoing connections only. BiglyBT "does not support incoming TCP connections", and the wiki adds that "you will appear to have a 'NAT problem'". That warning is expected, and port forwarding will not clear it.
  • UDP is limited, and on our side absent. BiglyBT "supports SOCKS 5 UDP associations for tracker announces and scrapes but not for peer connections." We have not verified a UDP relay on our gateways, so treat our SOCKS5 as TCP only: UDP tracker announces should not be expected to work through us. HTTP vs SOCKS5 has the background.
  • No encryption. A proxy relays connections. The SOCKS5 password itself crosses the network in plain text.
  • Two-way traffic. Every piece you download, and every piece you upload while seeding, crosses the proxy. How each direction counts on your plan is under metering.

Setting it up, with BiglyBT's own labels

The labels in quotes come from BiglyBT's message bundle in its source, so they should match your screen word for word. The current release is 4.1.0.0.

  1. Switch the options to advanced mode, then open Tools > Options > Connection > Proxy Options.
  2. Tick "Enable proxying of tracker communications [restart required]".
  3. Tick "I have a SOCKS proxy". Leave it unticked only if you mean to configure an HTTP proxy, which covers trackers and HTTP seeds and nothing else.
  4. Enter the host and port from your service page. On ISP and datacenter proxies, switch the proxy to SOCKS5 in the dashboard first; the port may differ.
  5. Set "SOCKS version" to 5 and fill in "Username" and "Password". With your address on the IP allowlist, you can leave the login empty.
  6. Tick "Enable proxying of peer communications (outgoing connections only) [restart required]".
  7. Tick "Prevent local DNS lookups", so hostnames are not resolved by your own resolver.
  8. If you use BiglyBT's Tor or I2P helper plugins, decide on "Disable plugin proxies (e.g. Tor/I2P Helper plugins) when a SOCKS server is configured". Those networks are not ours, and this page does not cover them.
  9. Restart BiglyBT. Two of the options above say so in their labels.

Tracker and peer proxying are separate boxes on purpose. Tracker proxying alone hides your address from the tracker operator, and from nobody in the swarm, so tick both.

Close the side doors: peer sources and the DHT plugin

This is the step that is easiest to miss, and BiglyBT's wiki is direct about it. To stop your public address leaking, "Look for the 'Peer Sources' section and deselect everything apart from the first one, 'from a tracker'. Also ensure that you haven't got the 'Mainline DHT Plugin' installed".

So, in your options:

  • Find Peer Sources and leave only "from a tracker" selected.
  • Check your installed plugins, and remove the Mainline DHT Plugin if it is there.

The cost is fewer ways to find peers. For torrents with working trackers, which includes almost every distribution and open-data release, that is rarely a problem.

Test SOCKS first, then check the meter

BiglyBT has a Test SOCKS button next to the proxy settings. Use it before you start a torrent; a failure there is quicker to fix than a stalled download. You can also confirm the proxy from a terminal on the same machine:

curl -s -x socks5h://USERNAME:PASSWORD@HOST:PORT https://api.ipify.org

Then the real check, which shows whether BiglyBT's peer traffic is going through:

  1. Note the traffic figure for your service in the dashboard (where to find it).
  2. Run a small lawful torrent and note how much BiglyBT says it downloaded and uploaded.
  3. Wait a few minutes, since dashboard figures update regularly rather than live, and compare.

About the same means peers are proxied. Barely moved means they are not, and the usual cause is step 6 left unticked. A little more on the dashboard than in BiglyBT is protocol overhead and discarded data. How to check your proxy provider's meter covers it in more depth.

Keeping a long seed affordable

BiglyBT suits people who seed for months, and on a metered proxy that adds up. A torrent you download once and seed back to a ratio of 1.0 moves its whole size in each direction. The proxy settings apply to the whole client, so run torrents that do not need a separate address with the proxy off, and cap upload speed or set a stop ratio while it is on. A static ISP or datacenter IP suits a client that runs for weeks, and a dedicated one with no traffic cap takes the per-gigabyte cost out of long seeding, because it is billed per IP for its term. Residential stays metered. See the pricing page for rates.

If a VPN is the better fit

If your goal is the whole machine leaving from another address, or the threat you care about is copyright enforcement, a VPN is the more suitable tool, and BiglyBT's wiki explains how to tie the client to one. It describes setting "Bind to local IP address or interface" to the VPN's interface and ticking "Enforce IP bindings even when interfaces are not available", so the client stops rather than falling back to your normal connection. We do not sell VPNs; proxy vs VPN is our plain comparison.

Quick answers

Does BiglyBT support SOCKS5 with a username and password? Yes. The SOCKS options include "SOCKS version", "Username" and "Password".

Why does BiglyBT say I have a NAT problem after I set a proxy? Because proxied peers cannot connect in. The wiki says to expect it.

Does an HTTP proxy hide my IP from peers in BiglyBT? No. It covers tracker communication and HTTP seeds only.

Is BiglyBT the same as Vuze? It is a fork of the same code, maintained by two of the original developers. Our Vuze page explains why we point Vuze users here.

Next step

Set the proxy, press Test SOCKS, run one small torrent, and compare the meter. If the numbers do not line up, bring both figures to Discord and we will look at them with you.

Got a follow-up question?

Ask it in Discord. The answer helps whoever reads the thread next.

Join the Discorddiscord.gg/proxypanda
Start with $5Ask in Discord