Tutorial

How to Set Up a Proxy on Linux Mint

Set a proxy on Linux Mint 22.3: Cinnamon, MATE and Xfce, the terminal, apt, Update Manager and sudo, and why each one ignores the others.

HProxy Team··Updated October 3, 2026·14 min read
HProxy.Tutorial

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.44/GB, pay as you go.

See plans & pricing→

Linux Mint's proxy setting in Network reaches Firefox and not much else. The terminal, Update Manager, Software Manager and Software Sources each read a different setting, which is why a proxy that works in the browser can leave updates failing. Set the proxy where each program looks, then check it with one command.

Mint is built on Ubuntu, so the basics match our Ubuntu guide. This page covers what Mint adds: three desktops and Mint's own tools. We did not install Mint for this page. Every statement about Mint's tools comes from their source code, in the versions that Linux Mint 22.3 "Zena" ships (released 13 January 2026, supported until April 2029). One test ran on our own workstation.

Where you set itWhat it reachesWhat it leaves out
Network, Proxy (Cinnamon) or Network Proxy (MATE)Firefox on its default setting, Update Manager's changelogsTerminals, apt, Update Manager's updates, Software Sources
A file in /etc/apt/apt.conf.d/apt, Update Manager, Software Manager, SynapticEverything that is not apt
export in a terminalcurl, wget and apt started in that terminalOther terminals, sudo, programs started from the menu
/etc/environmentEvery login, and on Mint 22 also sudoUpdate Manager's installs, Software Sources
/etc/sudoers.d/Your exported names, carried into sudoSoftware Sources
Who follows which setting on Linux Mint 22.3

Follow the desktop setting

  • Firefox

    on its default, Use system proxy settings

  • Update Manager's changelogs

    the only part of it that reads this setting

Read their own setting

  • apt, Update Manager, Software Manager

    Acquire::http::Proxy in /etc/apt/apt.conf.d/

  • curl, wget and other terminal programs

    http_proxy and https_proxy

  • Anything run with sudo

    keeps no exported proxy names

  • Software Sources

    started by pkexec, which passes on no proxy

Source: The source code of Update Manager 7.1.4, aptkit 1.1.2, Software Sources 2.4.3 and cinnamon-control-center 6.6.0, the versions in Linux Mint 22.3; Ubuntu 24.04's sudo; polkit 124

Which Mint tool follows which setting

Mint's own tools reach the internet in four different ways, and each way decides which proxy setting it sees:

Linux Mint 22.3's tools, how they run, and the proxy that reaches them

ToolHow it runsProxy that reaches it
Update Manager: refreshingsudo /usr/bin/mint-refresh-cache, allowed without a passwordapt's file; names from /etc/environment
Update Manager and Software Manager: installingaptkit, a system service that starts with an empty environmentapt's file only
Update Manager: changelogsas youthe desktop setting
Software Sources: mirror test, PPA keyspkexec mintsourcesnone
apt in a terminalas you, or with sudoapt's file; exported names only without sudo

Update Manager 7.1.4, aptkit 1.1.2, Software Sources 2.4.3 and mint-common 2.5.1 (Linux Mint 22.3); polkit 124; D-Bus 1.14

The one setting every package operation reads is apt's own file. That is step 2, and it is the step that fixes Update Manager. The setting in Network is for the browser.

What you need before you start

One proxy line, four parts

198.51.100.7Host:8080Port:hp_ir4k2Username:9fa2c1Password
  • 198.51.100.7:8080:hp_ir4k2:9fa2c1host:port:user:passMost proxy tools and checkers
  • hp_ir4k2:9fa2c1@198.51.100.7:8080user:pass@host:portcurl, requests, most HTTP clients
  • http://hp_ir4k2:9fa2c1@198.51.100.7:8080http://user:pass@host:portAnything taking a full proxy URL

Cinnamon's proxy page takes the host and the port. apt takes all four in one address. Values shown are examples.

  • A proxy address as host:port, plus a user name and password if the proxy needs a login. If your provider sent the four values in another order, the proxy format guide sorts them out.
  • A terminal (Menu, then Terminal) and the password of your account. Mint's first user is in the sudo group, which may run commands as root.
  • For a first test, any HTTP entry from our free proxy list will do. Free entries come and go, so test one first; the check further down shows how.
Our free proxy list filtered to HTTP on 2 October 2026: 8,276 entries, each row with its address and port, country, anonymity, uptime, speed and a Copy button.
Captured on 2 October 2026 at hproxy.com/free-proxy-list/http. The address and port of a row are the host:port the steps below ask for.

Step 1: the desktop setting (for the browser)

Cinnamon

Open System Settings, choose Network, and choose Proxy in the list on the left. Then:

  1. Set Method to Manual (1).
  2. Put the proxy's address into HTTP Proxy and its port into the box next to it (2).
  3. Do the same for HTTPS Proxy (3). For a SOCKS proxy, fill in Socks Host instead.
Cinnamon's proxy page on Linux Mint 22.3
System SettingsLinux Mint 22.3 Cinnamon

NetworkProxy

Proxy

  • MethodManual
  • HTTP Proxy198.51.100.7 8080
  • HTTPS Proxy198.51.100.7 8080
  • FTP Proxy  0
  • Socks Host  0
  • Ignore Hostslocalhost, 127.0.0.0/8, ::1
Source: Drawn from the layout file of cinnamon-control-center 6.6.0, the version in Linux Mint 22.3, not a screenshot. The port boxes have no label of their own.

There is no Save or Apply button: the page stores each change as you type. It has no field for a user name or password either; Firefox asks for the login when it first connects. Firefox follows this setting while its own connection settings stay on Use system proxy settings, its default. Automatic takes the address of a PAC file in Configuration URL.

MATE

Open Control Center and choose Network Proxy. Pick Manual proxy configuration, fill in HTTP proxy and Secure HTTP proxy, each with its Port. For a proxy with a login, press Details, tick Use authentication and fill in Username and Password. MATE writes the same setting as Cinnamon, so the rest of this page applies unchanged.

Xfce

Mint's Xfce edition has no proxy dialog. Xfce's settings manager has dialogs for accessibility, appearance, colour, display, keyboard, file types and mouse, and none for a proxy. Set Firefox's proxy in its own Network Settings (Manual proxy configuration), and use steps 2 and 3 for everything else.

Step 2: apt, Update Manager and Software Manager

One line in a file of its own gives the proxy to apt, and through apt to Update Manager, Software Manager and Synaptic:

echo 'Acquire::http::Proxy "http://user:pass@host:port/";' | sudo tee /etc/apt/apt.conf.d/99proxy
apt-config dump | grep -i proxy

The second command shows what apt will use. Four details:

  • One line covers https sources too. apt 2.8, the version in Mint 22, looks up Acquire::https::Proxy for an https source and falls back to the http line when there is none. Mint 22.3's default sources are plain http anyway: packages.linuxmint.com, archive.ubuntu.com and security.ubuntu.com.
  • Encode special characters in the login. @ becomes %40 and : becomes %3A, or apt cannot read the address; our Debian test shows the error.
  • The file name matters. A name without an extension, or ending in .conf, is read; a file such as proxy.txt is skipped.
  • The variables count only without this file. apt reads http_proxy and https_proxy from its environment only while no Acquire proxy is set.

This file is what fixes Update Manager. In Mint 22.3, Update Manager refreshes its package lists by running sudo /usr/bin/mint-refresh-cache, and installs updates through aptkit, Mint's package service. aptkit runs as root and starts with an empty environment, so apt's own files are the only proxy it ever sees. Software Manager installs through the same aptkit.

Step 3: the terminal and every login

For the terminal you have open:

export http_proxy="http://user:pass@host:port" https_proxy="http://user:pass@host:port" no_proxy="localhost,127.0.0.1,::1"

Both names start with http://, the one for HTTPS too: they name the proxy, and the proxy itself speaks plain HTTP. For yourself for good, add that line to the end of ~/.bashrc. For every user, put the names into /etc/environment, one plain NAME=value line each:

http_proxy=http://user:pass@host:port
https_proxy=http://user:pass@host:port
no_proxy=localhost,127.0.0.1,::1

Then log out and back in, because /etc/environment is read at login. Several guides say to run source /etc/environment instead. For a file of plain NAME=value lines, that sets the names in your shell but not in the programs you start from it, as our test shows:

Terminal on our workstation with bash 5.2: a file with two plain proxy lines is sourced; echo in the shell prints the proxy, but a program started from it prints nothing; after set -a, source and set +a, the program prints the proxy.
(1) The shell has the proxy. (2) A program started from it does not. (3) With set -a around source, it does. Same bash 5.2 as Mint 22.

set -a; source /etc/environment; set +a works for the shell you are in. Logging in again is simpler, and it covers every program.

On Mint 22, /etc/environment also reaches commands you run with sudo, Update Manager's refresh included (step 4 explains why). It does not reach aptkit's installs or Software Sources, which is one more reason to set apt's file from step 2. /etc/environment can be read by every user, so on a shared computer, keep a password out of it.

Step 4: sudo

sudo runs every command in a minimal environment, so a proxy you only exported does not reach sudo apt or anything else run with sudo. Names from /etc/environment do: Mint ships no sudo of its own and uses Ubuntu's, whose login file /etc/pam.d/sudo loads pam_env with readenv=1, the module that reads /etc/environment.

What sudo does with your proxy on Linux Mint 22
  1. export in your shellhttp_proxy is set
  2. sudoenv_reset, no proxy names kept
  3. the commandfinds no proxy in its environment

The default

  1. /etc/environmenttwo plain lines
  2. sudopam_env readenv=1 loads them
  3. the commandhas http_proxy and https_proxy

Ubuntu's sudo, as used by Mint 22

  1. export in your shellhttp_proxy is set
  2. sudoenv_keep for %sudo passes it on
  3. the commandhas the proxy

With the line in /etc/sudoers.d/proxy

Source: Ubuntu 24.04's sudo package (1.9.15p5-3ubuntu5.24.04.3): /etc/pam.d/sudo and /etc/sudoers; sudoers(5)

Ubuntu's own /etc/sudoers already carries the line that keeps your exported proxy names, switched off with a #. Rather than edit that file, put the line into a file of its own:

sudo visudo -f /etc/sudoers.d/proxy
Defaults:%sudo env_keep += "http_proxy https_proxy ftp_proxy all_proxy no_proxy"

For a single command, sudo -E keeps your whole environment. Mint's rule for the sudo group allows it, because a rule whose command is ALL implies the SETENV tag (sudoers manual). On LMDE 7, which uses Debian's sudo, /etc/environment does not reach sudo at all; our Debian guide shows that run.

Software Sources and its "Unreachable" mirrors

Software Sources starts with pkexec mintsources. pkexec, the tool that runs it as root, passes on only language, terminal and display names, and no proxy. So its mirror speed test connects without your proxy, and on a network where only the proxy gets out, every mirror ends up marked Unreachable. Its downloads of PPA signing keys look for http_proxy too, and find none.

That label is not apt's view: apt still downloads through the file from step 2. Pick a mirror by its name, or keep the default, and refresh in Update Manager.

The next Mint release

Update Manager 7.1.5, built for the release after 22.3, copies the desktop proxy into its own environment when it starts, but only when Method is Manual. Its refresh and its installs still run through sudo and aptkit, so apt's file from step 2 stays the step that matters.

Check that it worked

apt-config dump | grep -i proxy
sudo apt update
curl -s https://www.cloudflare.com/cdn-cgi/trace | grep ^ip=
curl -s https://hproxy.com/api/ip/THE_ADDRESS_YOU_JUST_SAW
sudo env | grep -i _proxy
gsettings get org.gnome.system.proxy mode

The first two show which proxy apt uses and whether it gets through. The third prints the address a site sees; if it is the proxy's address, your traffic goes through the proxy. The fourth takes that address and returns its country, city, network and AS number. The last two show what survives sudo and what the desktop setting is. Then paste the entry into our free proxy checker, which reports status, protocol, anonymity, country and latency for every line. Free entries stop answering without notice; for daily work, use a paid proxy instead.

When it does not work

apt 2.8's source code holds the same messages that apt printed in our Debian test, so on Mint 22 they read the same:

apt's messages and Mint's symptoms, what they mean, and the fix

What you seeWhat it meansFix
Could not connect to 127.0.0.1:3128 (127.0.0.1). - connect (111: Connection refused)apt uses a proxy that is not running at that address.apt-config dump | grep -i proxy, then fix or delete that line.
Invalid response from proxy: HTTP/1.1 407 Proxy Authentication Requiredapt reached the proxy, but the login was missing or wrong.Check the user name and password; encode @ as %40.
Temporary failure resolving '...'The name in the address does not resolve.Check the proxy's host name, or write its IP address.
Could not wait for server fd - select (11: Resource temporarily unavailable)The proxy address starts with https://, but the proxy speaks plain HTTP.Write http:// in front of the proxy.
N: Ignoring file 'proxy.txt' in directory '/etc/apt/apt.conf.d/' as it has an invalid filename extensionapt skipped your file because of its name.Rename it to 99proxy.
E: Syntax error /etc/apt/apt.conf.d/99proxy:1: Extra junk at end of fileThe line lacks its closing ;.End the line with ";.
Update Manager refreshes, but installing failsThe proxy is only in /etc/environment, which aptkit never reads.Add apt's file from step 2.
Every mirror in Software Sources says UnreachableSoftware Sources runs without a proxy.Pick a mirror by name; apt is not affected.

apt 2.8.3's source and our Debian 13 run; Update Manager 7.1.4, aptkit 1.1.2 and Software Sources 2.4.3

These come up in the pages that rank for "linux mint proxy settings":

  • An "Apply System-Wide" button. Cinnamon 6.6's proxy page has none, and it writes your own settings, not a system-wide store. The button belonged to GNOME 2's proxy dialog, which Mint 11 used; a 2012 question on Super User mentions it.
  • A switch at the top of the proxy page. Cinnamon's code hides it; the page works through Method.
  • "Use authentication" in Cinnamon. Only MATE's dialog has a login.
  • https:// in front of the proxy, in /etc/environment or in apt's file. On our Debian test, apt waited six minutes with it and then failed.
  • source /etc/environment to apply or to remove a proxy. It does neither for the programs you start, as the test above shows.
  • Three lines in /etc/apt/apt.conf with https:// and ftp://. One http:// line in /etc/apt/apt.conf.d/ covers it.

Turning it off again

Each place is separate, and a forgotten one keeps sending traffic to a proxy that no longer exists:

  • In Network, Proxy, set Method to None (Cinnamon), or choose Direct internet connection (MATE).
  • Run sudo rm /etc/apt/apt.conf.d/99proxy.
  • Remove the lines from /etc/environment, then log out and back in.
  • In open terminals, run unset http_proxy https_proxy no_proxy, and remove your line from ~/.bashrc.
  • Run sudo rm /etc/sudoers.d/proxy if you made it.

How we wrote this

We did not install Linux Mint for this page. We read the source code of the versions Linux Mint 22.3 ships, taken from Mint's own package repository: Update Manager 7.1.4, aptkit 1.1.2, Software Sources 2.4.3, mint-common 2.5.1, Software Manager 8.4.0, cinnamon-control-center 6.6.0 and Mint's build of mate-control-center 1.26.1. We also read Ubuntu 24.04's sudo package, apt 2.8.3, polkit 124, the D-Bus 1.14 launch helper and Xfce's settings, plus Update Manager 7.1.5 for the next release.

One test ran on our workstation on 3 October 2026: the source test above, in a clean bash 5.2, the same bash version as Mint 22. The pages that rank for "linux mint proxy settings" were read and checked, and so were real questions from the Linux Mint forums, Super User and Unix & Linux.

Limits: no step on this page was run on Linux Mint itself. Cinnamon's page is drawn from its layout file, not captured, and apt's messages come from its source and our Debian run. LMDE 7 is covered only where it differs. Flatpak downloads in Software Manager are not covered.

Sources

All read on 3 October 2026.

  • Linux Mint: all versions with their base and support dates (linuxmint.com), and the Linux Mint 22.3 release announcement (blog.linuxmint.com).
  • Linux Mint 22.3's repository (packages.linuxmint.com): the package index and the source of Update Manager 7.1.4, aptkit 1.1.2, Software Sources 2.4.3, mint-common 2.5.1, Software Manager 8.4.0 and mate-control-center 1.26.1+mint2.
  • cinnamon-control-center 6.6.0, python3-xapp and Update Manager 7.1.5 (github.com/linuxmint).
  • Ubuntu 24.04's sudo package 1.9.15p5-3ubuntu5.24.04.3 (archive.ubuntu.com).
  • apt 2.8.3 (salsa.debian.org/apt-team/apt), polkit 124 (github.com/polkit-org), D-Bus 1.14 (gitlab.freedesktop.org), xfce4-settings (Xfce).
  • The Bash reference manual: the set builtin, -a (gnu.org).
  • Linux Mint Forums: "How to configure proxy?" (2023) and "How do I configure to use proxy?" (2012); Super User questions 1111538, 453546 and 462740; Unix & Linux question 121079.
  • Our test on our workstation, 3 October 2026, and our Debian 13 run of 3 October 2026.

Frequently asked questions

How do I set a proxy on Linux Mint?
In two places at least. For the browser, open System Settings, Network, Proxy, set Method to Manual and fill in the HTTP and HTTPS lines. For updates and software, put one line into a file in /etc/apt/apt.conf.d/: Acquire::http::Proxy "http://host:port/"; That file is what apt, Update Manager and Software Manager read. For the terminal, export http_proxy and https_proxy, or put them into /etc/environment.
Why does Update Manager not use my proxy?
Because the proxy in Network settings is not the one it downloads packages with. In Linux Mint 22.3, Update Manager reads the desktop proxy only to fetch changelogs. It refreshes through sudo and installs through aptkit, a system service, and both download with apt, which reads its own proxy file. Add Acquire::http::Proxy to a file in /etc/apt/apt.conf.d/ and Update Manager follows.
Where are the proxy settings in Linux Mint Cinnamon?
System Settings, Network, then Proxy in the list on the left. Set Method to Manual and fill in HTTP Proxy and HTTPS Proxy, each with its port. The page has no login fields and no Save button; each change is stored at once.
Does Linux Mint Xfce have proxy settings?
No. Xfce's settings have no proxy dialog. Set the proxy for apt in a file in /etc/apt/apt.conf.d/, for terminal programs in /etc/environment, and in Firefox under its own Network Settings.
How do I give the proxy a user name and password on Linux Mint?
Write them into the address in apt's file: Acquire::http::Proxy "http://user:pass@host:port/"; and encode special characters, @ as %40 and : as %3A. MATE's Network Proxy dialog has a login under Details; Cinnamon's has none, and Firefox asks for the login itself.
Does /etc/environment reach sudo on Linux Mint?
On Mint 22, yes. Mint uses Ubuntu's sudo, whose PAM file loads /etc/environment for every sudo command. On LMDE 7, which uses Debian's sudo, it does not. A proxy you only exported in a terminal never reaches sudo on either.
Why does Software Sources show every mirror as Unreachable?
Behind a proxy-only network that is expected. Software Sources starts through pkexec, which passes on language, terminal and display names and no proxy, so its speed test connects without the proxy and fails. Pick a mirror by name; apt still downloads through its own proxy file.
Why does source /etc/environment not apply the proxy?
Because /etc/environment holds plain NAME=value lines. Sourced in bash, they become variables of that shell only, and programs started from it do not see them. In our test a program started after source printed nothing; with set -a around source it printed the proxy. Log out and back in instead.
Do I need both Acquire::http::Proxy and Acquire::https::Proxy?
No. apt 2.8, the version in Mint 22, uses the http line for https sources when no https line exists, and Mint 22.3's default sources are plain http anyway. Add an https line only to send https sources through a different proxy.
What does Could not connect to 127.0.0.1:3128 mean in apt?
apt uses a proxy that does not answer at that address and port. apt-config dump | grep -i proxy shows which line apt took; fix the address, or remove the old file in /etc/apt/apt.conf.d/.
Is LMDE different?
In two ways. LMDE 7 is built on Debian 13, so its sudo does not load /etc/environment, and its apt is version 3.0. apt's proxy file works the same way. Our Debian guide covers the details.
How do I turn the proxy off again on Linux Mint?
Each place on its own: set Method to None in Network, Proxy; delete the file in /etc/apt/apt.conf.d/; remove the lines from /etc/environment and log out and back in; unset the variables in open terminals; and delete /etc/sudoers.d/proxy if you made one.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires. $0.44/GB is the 2,000 GB+ rate; a single gigabyte is $0.50/GB, with no minimum order.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed