Tutorial

How to Set Up a Proxy on Fedora

Fedora keeps a proxy in five places. Each step for GNOME, the terminal, dnf and sudo, tested on Fedora 44 with real screenshots.

HProxy Team··Updated October 3, 2026·15 min read
HProxy.Tutorial

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.44/GB, pay as you go.

See plans & pricing→

Fedora keeps a proxy setting in five places, and each one reaches a different set of programs. Set it in GNOME and Firefox follows, while sudo dnf upgrade can still go straight out. Pick the place that reaches the program you care about, then prove it with one command.

This page does not repeat other guides. On 3 October 2026 we installed Fedora 44, released on 28 April 2026, and ran every step on it against three test proxies that log each request they receive. Every screenshot below is the real screen, every terminal picture is the real output, and every error message is the one Fedora printed. Two things work differently on Fedora than on Debian, and this page points them out where they matter.

Where you set itWhat it reachesWhat it leaves out
GNOME Settings, Network, ProxyFirefox on its default setting, Chromium, Chrome, GNOME's appsTerminals, dnf, sudo
export in a terminalcurl, wget, dnf and podman started in that terminalOther terminals, anything under sudo
/etc/environmentThe next login, and on Fedora also commands under sudoTerminals already open
dnf config-manager setopt proxy=dnf, with sudo or as rootEverything that is not dnf
/etc/sudoers.d/Your exported names, carried into sudoUsers outside the wheel group
Who follows which setting on Fedora

Follow the desktop setting

  • Firefox

    on its default, Use system proxy settings (measured on Firefox 157)

  • Chromium and Chrome

    read GNOME's setting when they run in GNOME

  • GNOME's own apps

    the ones that use the network connection

Read their own setting

  • dnf

    proxy= in /etc/dnf/dnf.conf, else https_proxy

  • curl, wget, podman

    http_proxy and https_proxy, in lower case

  • Anything run with sudo

    starts with a short list of variables, no proxy

Source: Our Fedora 44 test machine, 3 October 2026; dnf5.conf(5), the sudoers and curl manuals, Chromium's Linux proxy notes

What you need before you start

One proxy line, four parts

198.51.100.7Host:8080Port:hp_ir4k2Username:9fa2c1Password
  • 198.51.100.7:8080:hp_ir4k2:9fa2c1host:port:user:passMost proxy tools and checkers
  • hp_ir4k2:9fa2c1@198.51.100.7:8080user:pass@host:portcurl, requests, most HTTP clients
  • http://hp_ir4k2:9fa2c1@198.51.100.7:8080http://user:pass@host:portAnything taking a full proxy URL

GNOME takes the host and the port. dnf takes all four, either as separate options or in one address. Values shown are examples.

  • A proxy address as host:port, plus a user name and password if the proxy needs a login. If your provider sent the four values in another order, the proxy format guide sorts them out.
  • A terminal. Every step except the desktop one works on Fedora Server too.
  • Root rights for steps 4 and 5: an account in the wheel group, which Fedora lets use sudo.
  • For a first test, any HTTP entry from our free proxy list will do. Free entries come and go, so test one first; the check further down shows how.
Our free proxy list filtered to HTTP on 2 October 2026: 8,276 entries, each row with its address and port, country, anonymity, uptime, speed and a Copy button.
Captured on 2 October 2026 at hproxy.com/free-proxy-list/http. The address and port of a row are the host:port the steps below ask for.

Step 1: the desktop (GNOME)

Fedora Workstation runs GNOME, version 50 in Fedora 44. The proxy sits on the Network page of Settings:

GNOME Settings 50 on Fedora 44 with the Network page open: mark 1 on Network in the sidebar, mark 2 on the row Proxy, which reads Off.
Our Fedora 44 test machine, 3 October 2026: (1) Network, (2) the Proxy row.
  1. Open Settings and choose Network (1).
  2. Click the Proxy row (2).
  3. Turn on Network Proxy (3).
  4. Set Configuration to Manual (4).
  5. Under HTTP Proxy, put the proxy's address into URL and its port into Port (5), then the same under HTTPS Proxy (6). For a SOCKS proxy, fill in SOCKS Host instead.
  6. Press Save (7) at the top. Nothing changes until you do; afterwards the Network page shows the row as Manual.
The GNOME Proxy page on Fedora 44 filled in: Network Proxy on, Configuration Manual, HTTP and HTTPS each with the URL 198.51.100.7 and the Port 8080, and Save at the top, numbered 3 to 7.
The same window after steps 3 to 6, with the example address 198.51.100.7. The HTTP port starts at 8080 and the HTTPS port at 0, so check both before you save.

The page has no field for a user name or password, and it is for desktop apps only: dnf, curl and wget never read it.

Firefox

Firefox follows this setting out of the box. A new Firefox 157 profile on our machine opened its Connection Settings on Use system proxy settings, and with GNOME pointed at our test proxy, its page load went through that proxy. To check yours, open Firefox's settings, choose Privacy and security (1), and under Proxy settings press Configure proxy (2):

Firefox 157 settings on Fedora 44: mark 1 on Privacy and security, mark 2 on Configure proxy under Proxy settings.
Firefox 157 on our Fedora 44 test machine. Typing proxy into Find in Settings leads to the same place.
Firefox's Connection Settings dialog on Fedora with Use system proxy settings selected, marked 3.
(3) Where a new profile starts on Fedora. Connections to localhost, 127.0.0.1/8 and ::1 are never proxied.

If your proxy needs a login, Firefox asks for it when it first connects; our Debian test shows that prompt. Chromium and Chrome read GNOME's setting the same way when they run in GNOME.

Step 2: set the proxy for this terminal

export http_proxy="http://user:pass@host:port" https_proxy="http://user:pass@host:port" no_proxy="localhost,127.0.0.1,::1"

Both names start with http://, the one for HTTPS too, because they name the proxy, and the proxy itself speaks plain HTTP. Write them in lower case: with only the upper-case HTTP_PROXY set, curl 8.18 on our Fedora machine went straight to the site, exactly as the curl manual says. Write the port every time; without one, curl assumes 1080.

The setting lives until you close the terminal. The Linux page has the details per tool for curl, wget, git and pip.

Step 3: make it permanent

For yourself, add the same line to the end of ~/.bashrc. For every user, put the names into /etc/environment, one plain NAME=value line each:

http_proxy=http://user:pass@host:port
https_proxy=http://user:pass@host:port
no_proxy=localhost,127.0.0.1,::1

The file is read at login, so log out and back in. Here Fedora differs from Debian: its sudo runs the system-auth login stack, which loads pam_env, so these names also reach commands you run with sudo. We checked it twice, once without and once with a real password prompt:

Terminal on Fedora 44: /etc/environment holds the proxy names; after a login env shows them; sudo env shows them too; with the password typed at a real prompt, sudo env still shows them.
(1) Under sudo the names are still there. (2) The same with a typed password. On Debian 13 sudo drops them.

/etc/environment can be read by every user on the machine. On a shared computer, keep a password out of it.

Step 4: give dnf its proxy

Fedora's package tool is dnf 5 (dnf points to it). It has its own proxy option, and one command sets it, no editor needed:

sudo dnf config-manager setopt proxy=http://host:port
Terminal on Fedora 44: dnf config-manager setopt writes proxy=http://127.0.0.1:8888 into /etc/dnf/dnf.conf, dnf makecache then goes through the test proxy, and config-manager unsetopt removes the line again.
(1) The line lands in /etc/dnf/dnf.conf. (2) dnf's next run went through the proxy. (3) unsetopt removes it.

If you prefer the file, the same line works appended to /etc/dnf/dnf.conf, which on a fresh Fedora 44 holds only [main]:

echo 'proxy=http://host:port' | sudo tee -a /etc/dnf/dnf.conf
dnf --dump-main-config | grep '^proxy'

The second command shows what dnf will use. dnf reads http_proxy and https_proxy from the environment only while its own proxy option is empty; once the option is set, it wins.

A proxy with a user name and password

dnf has two more options for the login, and they are the easy way: the password goes in exactly as it is, characters like @ included.

proxy=http://host:port
proxy_username=user
proxy_password=pass

Inside the address, a password character like @ must be encoded (%40), or dnf cannot read the address at all:

Terminal on Fedora 44: proxy_username and proxy_password with an @ in the password work; the same password written plainly into the proxy address fails with Curl error (5) Unsupported proxy syntax, Bad hostname; written as %40 it works; a wrong password fails with Curl error (56) CONNECT tunnel failed, response 407.
(1) The options take the password as it is. (2) A plain @ in the address breaks it. (3) %40 works. (4) A wrong password: the 407 message.

/etc/dnf/dnf.conf can be read by every user, so a password in it is readable too. You can make it private with sudo chmod 600 /etc/dnf/dnf.conf, and sudo dnf keeps working. The price: dnf commands run without sudo, like dnf repolist or dnf search, then stop with Permission denied. A private file in /etc/dnf/libdnf5.conf.d/ behaves the same way. On a computer only you use, the default is fine; on a shared one, make it private and use sudo for dnf.

Terminal on Fedora 44: dnf.conf is mode 644 and a normal user can read the proxy password; after chmod 600 dnf as root still works, the normal user cannot read the file, and dnf repolist as that user fails with Permission denied.
(1) Any user can read the password. (2) After chmod 600 they cannot. (3) But dnf run without sudo stops too.

A proxy for one dnf command

--setopt sets the option for one run only, which also works the other way round: with nothing after the equals sign, dnf skips a configured proxy, for example one that is down while you need a package now.

sudo dnf --setopt=proxy=http://host:port install curl
sudo dnf --setopt=proxy= upgrade
Terminal on Fedora 44: dnf --setopt=proxy= pointing at the test proxy sends its request there; then with a dead proxy on port 3128 in dnf.conf, dnf --setopt=proxy= with no value still succeeds.
(1) One run through the proxy. (2) dnf.conf now points at a dead proxy. (3) --setopt=proxy= skipped it, and the run still worked.

Step 5: carry exported names into sudo

sudo runs every command in a minimal environment, and Fedora's /etc/sudoers keeps a short list of display, language and terminal names, no proxy names. So a proxy you exported in your shell does not reach sudo dnf:

Terminal on Fedora 44: env shows http_proxy and https_proxy, sudo env shows nothing, sudo dnf makecache runs, and the test proxy received 0 requests.
(1) sudo shows no proxy names. (2) dnf went straight out: 0 requests at the proxy.

The dnf option from step 4 is the cleaner fix for dnf. For every command under sudo, add one line with visudo:

sudo visudo -f /etc/sudoers.d/proxy
Defaults:%wheel env_keep += "http_proxy https_proxy ftp_proxy all_proxy no_proxy"
Terminal on Fedora 44: /etc/sudoers contains no proxy line, the env_keep line for the wheel group is written to /etc/sudoers.d/proxy and checked by visudo, sudo env now shows both proxy names, and sudo dnf goes through the test proxy.
(1) Fedora's sudoers has no proxy line. (2) visudo accepts the new file. (3) sudo keeps the names. (4) dnf under sudo goes through the proxy.

Do not let the last line of Fedora's /etc/sudoers fool you: #includedir /etc/sudoers.d looks like a comment, but the # is part of the directive, the spelling sudo used before version 1.9.1. Files in /etc/sudoers.d/ are read.

A SOCKS5 proxy

dnf and curl both take socks5h://, a SOCKS5 proxy that also resolves the host names:

sudo dnf config-manager setopt proxy=socks5h://host:port
curl -x socks5h://user:pass@host:port https://fedoraproject.org/
Terminal on Fedora 44: dnf.conf with proxy=socks5h, dnf makecache succeeding, curl through socks5h answering 200, and the SOCKS5 test proxy recording two connections.
(1) dnf through our SOCKS5 test proxy. (2) curl through the same proxy.

Other programs on Fedora

wget (on Fedora it is wget2) reads http_proxy and https_proxy, git has its own option, and proxychains-ng sends any program through the proxy:

git config --global http.proxy http://user:pass@host:port
sudo dnf install proxychains-ng

For proxychains-ng, write the proxy into ~/.proxychains/proxychains.conf under [ProxyList], as http host port, and start a program with proxychains4 -q in front of it.

Terminal on Fedora 44: wget with https_proxy, git ls-remote with http.proxy, proxychains4 running curl, and the test proxy's log showing requests to fedoraproject.org and github.com.
(1) wget and proxychains4 reached fedoraproject.org through the proxy. (2) git reached github.com through it.

Podman, Fedora's own container tool, pulls with the proxy variables of the command that starts it:

https_proxy=http://user:pass@host:port podman pull docker.io/library/alpine:latest
Terminal on Fedora 44: podman 5.8.7 pulls alpine with https_proxy set, and the test proxy received CONNECT requests for auth.docker.io, the Docker CDN and registry-1.docker.io.
(1) Every request of the pull went through our test proxy.

Check that it worked

curl -sv -o /dev/null https://fedoraproject.org/ 2>&1 | grep -E 'Uses proxy|CONNECT tunnel'
curl -s https://www.cloudflare.com/cdn-cgi/trace | grep ^ip=
curl -s https://hproxy.com/api/ip/THE_ADDRESS_YOU_JUST_SAW
dnf --dump-main-config | grep '^proxy'
sudo env | grep -i _proxy
Terminal on Fedora 44: curl -v printing Uses proxy env variable https_proxy and CONNECT tunnel established, response 200.
(1) curl took the proxy from https_proxy. (2) The proxy opened the tunnel to the site.

The second line prints the address a site sees; if it is the proxy's address, your traffic goes through the proxy. The third takes that address and returns its country, city, network and AS number. The last two show what dnf will use and what survives sudo. Then paste the entry into our free proxy checker, which reports status, protocol, anonymity, country and latency for every line. Free entries stop answering without notice; when a download has to finish, use a paid proxy instead.

When it does not work: the messages Fedora prints

Every message below is copied from our test machine. dnf's lines are long; the part in square brackets is the one that tells you what happened.

dnf and curl messages on Fedora 44, what they mean, and the fix

What you seeWhat it meansFix
Curl error (7): Could not connect to server ... [Failed to connect to mirrors.fedoraproject.org port 443 via 127.0.0.1 ...]dnf uses a proxy that does not answer at that address and port.dnf --dump-main-config | grep ^proxy, then fix the address or start the proxy.
Curl error (56): Failure when receiving data from the peer ... [CONNECT tunnel failed, response 407]The proxy wants a login, and the one dnf sent was missing or wrong.Check proxy_username and proxy_password.
Curl error (28): Timeout was reached ... [Connection timed out after 30001 milliseconds]The proxy never answered dnf. On our machine: https:// in front of a plain HTTP proxy, six minutes in all.Write http:// in front of the proxy; check host and port.
Curl error (5): Could not resolve proxy name ... [Unsupported proxy syntax in '...': Bad hostname]An unencoded @ or : in the password split the address.Use proxy_password, or write %40 and %3a.
Error in configuration file "/etc/dnf/dnf.conf" Missing '=' on line 4A line in dnf.conf lacks its =.Write proxy=http://host:port.
Missing section header on line 1The proxy line sits above [main].Move it below [main], or use dnf config-manager setopt.
Unable to access configuration file "/etc/dnf/dnf.conf" ... Permission denieddnf.conf was made private and dnf ran without sudo.Run dnf with sudo, or make the file readable again.
curl: (56) CONNECT tunnel failed, response 407The same login problem, in curl.Check the user name and password; encode special characters.

Our Fedora 44 test machine, 3 October 2026

Terminal on Fedora 44: a dead proxy on port 3128 gives Curl error (7) in 0.09 seconds; a proxy line without = gives Missing '=' on line 4; a proxy line above [main] gives Missing section header on line 1.
(1) A dead proxy fails at once. (2) A missing =. (3) The line above [main].

These come up in guides that rank for Fedora and dnf proxy searches. We tried each one on our test machine:

  • https:// in front of an ordinary proxy. dnf kept trying for six minutes and then stopped with the timeout above.
  • The login in front of the scheme, as in user:pass@http://host:port. curl refuses it outright.
  • dnf shell to set the proxy. dnf 5 has no shell; Fedora 44 answers Unknown argument "shell".
  • Editing /etc/yum.conf. On Fedora 44 that file does not exist; yum is only another name for dnf 5, which reads /etc/dnf/dnf.conf.
Terminal on Fedora 44: with https:// in front of the proxy, dnf fails with Curl error (28), Connection timed out after 30001 milliseconds, after a measured 6 minutes.
(1) The message. (2) Six minutes until it came.
Terminal on Fedora 44: curl with user:pass@http://host:port fails with Unsupported proxy syntax, Port number was not a decimal number; the correct http://user:pass@host:port works; dnf shell answers Unknown argument shell for command dnf5.
(1) The login in front of the scheme. (2) The right order. (3) dnf shell no longer exists.

Turning it off again

Each place is separate, and a forgotten one keeps sending traffic to a proxy that no longer exists:

  • In open terminals, run unset http_proxy https_proxy no_proxy, and remove your line from ~/.bashrc.
  • Remove the lines from /etc/environment, then log out and back in.
  • Run sudo dnf config-manager unsetopt proxy, and delete any proxy_username and proxy_password lines from /etc/dnf/dnf.conf.
  • Run sudo rm /etc/sudoers.d/proxy.
  • Switch Network Proxy off in GNOME Settings, or run gsettings set org.gnome.system.proxy mode 'none'.

How we tested

Fedora 44 from the official Fedora image, run on our own workstation in WSL 2 with systemd, dnf 5.4.1, sudo 1.9.17p2 and curl 8.18. Three test proxies ran next to it, each logging every request: tinyproxy as an open HTTP proxy, squid with a user name and a password containing an @, and dante as a SOCKS5 proxy. dnf ran against the fedora repository with --refresh, so each run fetched the repository index through the proxy. GNOME Settings 50.4 and Firefox 157 ran on a virtual screen, with Fedora's default font; the screenshots are that screen, cut to size, with numbers added. Each step started from a clean state, and the proxies' logs, not dnf's own output, decided where the traffic went.

Limits: WSL brings Microsoft's kernel, not a bare-metal install, and the desktop programs ran without a full GNOME session. Fedora's installer and its proxy option were not tested, and neither was the KDE Plasma edition.

Sources

All read on 3 October 2026.

  • Our test run on Fedora 44, 3 October 2026: 21 experiments, the transcripts behind every terminal picture, and the GNOME and Firefox screens.
  • dnf5.conf(5): proxy, proxy_username, proxy_password, proxy_auth_method, and when the curl variables apply (dnf5.readthedocs.io).
  • The sudoers manual: the PAM environment, and #include and #includedir (sudo.ws).
  • Fedora 44's own files as installed: /etc/sudoers, /etc/pam.d/sudo, /etc/pam.d/system-auth and /etc/dnf/dnf.conf.
  • Announcing Fedora Linux 44, 28 April 2026, Fedora Magazine; fedoraproject.org on the Workstation edition and GNOME.
  • Linux Proxy Config, Chromium Docs (chromium.googlesource.com).
  • Connection settings in Firefox, Mozilla Support.
  • The curl man page: http_proxy in lower case, and the --proxy option.

Frequently asked questions

How do I set a proxy on Fedora?
Pick the place that reaches the program you care about. On the desktop, GNOME Settings, Network, Proxy covers Firefox, Chrome and GNOME's own apps. For the open terminal, export http_proxy and https_proxy. For every login, put the same names into /etc/environment. For dnf, run sudo dnf config-manager setopt proxy=http://host:port. To keep exported names under sudo, add a %wheel env_keep line in /etc/sudoers.d/proxy.
How do I set a proxy for dnf?
Run sudo dnf config-manager setopt proxy=http://host:port. On our Fedora 44 test machine this wrote the line into /etc/dnf/dnf.conf by itself, and dnf went through the proxy from then on. sudo dnf config-manager unsetopt proxy removes it again.
How do I give dnf a proxy user name and password?
Use dnf's own options next to the proxy: proxy_username and proxy_password in /etc/dnf/dnf.conf. In our test a password containing @ worked there exactly as typed. Written into the proxy address instead, a plain @ failed with Curl error (5) Unsupported proxy syntax; it has to be %40 there.
Why does sudo dnf ignore my exported proxy?
Because sudo starts every command in a minimal environment and Fedora's /etc/sudoers keeps no proxy names. On our test machine sudo env showed none, and sudo dnf sent nothing to the proxy. Give dnf its own proxy option, or add Defaults:%wheel env_keep += "http_proxy https_proxy ftp_proxy all_proxy no_proxy" to /etc/sudoers.d/proxy with visudo.
Does /etc/environment reach sudo on Fedora?
Yes, on Fedora 44 it does. Fedora's sudo runs the system-auth PAM stack, which loads pam_env, so names from /etc/environment were present under sudo in our test, with and without a password prompt. On Debian they are not.
What does Curl error (56) CONNECT tunnel failed, response 407 mean in dnf?
The proxy wants a login and did not get the right one. Check proxy_username and proxy_password in /etc/dnf/dnf.conf, or the user name and password in the proxy address, where special characters must be encoded.
Why does dnf hang for minutes with my proxy?
Most often the proxy address starts with https:// while the proxy speaks plain HTTP. On our test machine dnf tried for six minutes and stopped with Curl error (28) Timeout was reached. Write http:// in front of the proxy.
What does Curl error (7) Failed to connect via 127.0.0.1 mean in dnf?
Nothing answers at the proxy address and port dnf is using. Check the line with dnf --dump-main-config | grep ^proxy, then fix the address or start the proxy.
How do I use a proxy for one dnf command only?
Add --setopt=proxy=http://host:port to that one command, for example sudo dnf --setopt=proxy=http://host:port install curl. With --setopt=proxy= and nothing after the equals sign, dnf skips a proxy that is configured, for that run only.
Does the GNOME proxy setting cover the terminal on Fedora?
No. Firefox follows it while its own Connection Settings stay on Use system proxy settings, which is where a new Firefox 157 profile on Fedora starts, and Chromium and Chrome read it when they run in GNOME. curl, wget, dnf and podman read environment variables and their own settings instead.
Does Podman use my proxy on Fedora?
It uses the proxy variables of the command that starts it. In our test, podman pull with https_proxy set sent every request to the registry through the proxy.
How do I turn the proxy off again on Fedora?
Each place on its own: unset the variables, remove your lines from ~/.bashrc and /etc/environment, run sudo dnf config-manager unsetopt proxy and remove any proxy_username and proxy_password lines, delete /etc/sudoers.d/proxy, and switch Network Proxy off in GNOME Settings.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires. $0.44/GB is the 2,000 GB+ rate; a single gigabyte is $0.50/GB, with no minimum order.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed