This guide covers all configuration options for the Tor VPN System.
The system uses custom Tor configuration files located at:
~/.tor_config/torrc or ~/.tor/torrc~/Library/Application Support/Tor/torrc%APPDATA%\tor\torrc/etc/tor/torrc/usr/local/etc/tor/torrcC:\Tor\torrcConfiguration files should have restricted permissions:
# torrc file
chmod 600 ~/.tor_config/torrc
# Configuration directory
chmod 700 ~/.tor_config
Permissions breakdown:
600 - Owner read/write only700 - Owner read/write/execute onlyDefault: 9051
Tor control interface port for Stem API communication.
ControlPort 9051
Default: 9050
SOCKS5 proxy port for applications.
SocksPort 9050
Default: 9040
Transparent proxy port for system-wide traffic routing.
TransPort 9040
Default: 5353
DNS resolver port for DNS through Tor.
DNSPort 5353
Hashed password for control port authentication.
HashedControlPassword 16:B76A6ED6F4E32AB16028702348A5E765C6A53BCE1F82E467C614392ECD
Generate hashed password:
tor --hash-password "your_password"
Enable cookie-based authentication.
CookieAuthentication 1
Cookie file location: /run/tor/control.authcookie or /var/lib/tor/control_auth_cookie
Tor data storage directory.
DataDirectory /var/lib/tor
Virtual address network for transparent proxy.
VirtualAddrNetworkIPv4 10.192.0.0/10
Automap .onion addresses to virtual addresses.
AutomapHostsOnResolve 1
Specify exit nodes by country code.
ExitNodes {us}
ExitNodes {us},{de},{gb}
Exclude specific countries from exit nodes.
ExcludeNodes {cn},{ru}
Strictly use specified exit nodes (no fallback).
StrictNodes 1
Log notice file /var/log/tor/notices.log
Log warn file /var/log/tor/warnings.log
Log debug file /var/log/tor/debug.log
Log levels:
debug - Detailed debugging informationinfo - General informational messagesnotice - Normal but significant conditionswarn - Warning messageserr - Error conditionsGenerate hashed password:
:::bash
tor --hash-password "your_secure_password"
Add to torrc:
HashedControlPassword 16:YOUR_HASHED_PASSWORD
Use in Python:
:::python
from stem.control import Controller
with Controller.from_port(port=9051) as controller:
controller.authenticate(password="your_plain_password")
Enable in torrc:
CookieAuthentication 1
Ensure cookie file exists:
:::bash
ls -la /run/tor/control.authcookie
Use in Python:
:::python
from stem.control import Controller
with Controller.from_port(port=9051) as controller:
controller.authenticate(cookie_path="/run/tor/control.authcookie")
# Remove authentication parameters from torrc
# Only use in trusted environments
| File | Default Location |
|---|---|
| torrc | /etc/tor/torrc or ~/.tor_config/torrc |
| Data directory | /var/lib/tor |
| Log directory | /var/log/tor |
| Auth cookie | /run/tor/control.authcookie |
| File | Default Location |
|---|---|
| torrc | /usr/local/etc/tor/torrc or ~/Library/Application Support/Tor/torrc |
| Data directory | ~/Library/Application Support/Tor |
| Log directory | ~/Library/Logs/Tor |
| Auth cookie | /var/run/tor/control.authcookie |
| File | Default Location |
|---|---|
| torrc | C:\Tor\torrc or %APPDATA%\tor\torrc |
| Data directory | %APPDATA%\tor |
| Log directory | %APPDATA%\tor\logs |
| Auth cookie | %APPDATA%\tor\data\control_auth_cookie |
Set Tor control password via environment variable.
export TOR_PASSWORD="your_secure_password"
Set custom configuration directory.
export TOR_CONFIG_DIR="/custom/config/dir"
Set system proxy environment variables.
export http_proxy="socks5h://127.0.0.1:9050"
export https_proxy="socks5h://127.0.0.1:9050"
export all_proxy="socks5h://127.0.0.1:9050"
ExitNodes {us}
ExitNodes {us},{de},{gb},{nl}
ExcludeNodes {cn},{ru},{kp}
ExitNodes {us}
StrictNodes 1
EntryNodes {us}
GuardLifetime "30 days"
MiddleNodes {de},{nl}
ExitNodes {gb}
ExitPolicy reject *:*
CircuitBuildTimeout 60
NewCircuitPeriod 30
MaxCircuitDirtiness 300
BandwidthRate 1 MB
BandwidthBurst 2 MB
RelayBandwidthRate 100 KB
RelayBandwidthBurst 200 KB
UseBridges 1
Bridge obfs4 192.0.2.1:443 1234567890ABCDEF cert=... iat-date=...
BridgeRelay 1
ServerTransportPlugin obfs4 exec /usr/bin/obfs4proxy managed
HiddenServiceDir /var/lib/tor/hidden_service/
HiddenServicePort 80 127.0.0.1:8080
HiddenServiceDir /var/lib/tor/hidden_service1/
HiddenServicePort 80 127.0.0.1:8080
HiddenServiceDir /var/lib/tor/hidden_service2/
HiddenServicePort 443 127.0.0.1:8443
ControlPort 9051
HashedControlPassword 16:YOUR_HASHED_PASSWORD
SocksPort 9050
DataDirectory /var/lib/tor
ControlPort 9051
HashedControlPassword 16:YOUR_HASHED_PASSWORD
SocksPort 9050
DataDirectory /var/lib/tor
Log notice file /var/log/tor/notices.log
Log warn file /var/log/tor/warnings.log
ControlPort 9051
HashedControlPassword 16:YOUR_HASHED_PASSWORD
SocksPort 9050
TransPort 9040
DNSPort 5353
VirtualAddrNetworkIPv4 10.192.0.0/10
AutomapHostsOnResolve 1
DataDirectory /var/lib/tor
ControlPort 9051
HashedControlPassword 16:YOUR_HASHED_PASSWORD
SocksPort 9050
DataDirectory /var/lib/tor
ExitNodes {us}
StrictNodes 1
ControlPort 9051
HashedControlPassword 16:YOUR_HASHED_PASSWORD
SocksPort 9050
DataDirectory /var/lib/tor
UseBridges 1
Bridge obfs4 192.0.2.1:443 1234567890ABCDEF cert=... iat-date=...
ControlPort 9051
HashedControlPassword 16:YOUR_HASHED_PASSWORD
SocksPort 9050
DataDirectory /var/lib/tor
HiddenServiceDir /var/lib/tor/hidden_service/
HiddenServicePort 80 127.0.0.1:8080
python tor_custom_config.py
This script:
python tor_auto_torrc_config.py
This script:
Create torrc file:
:::bash
nano ~/.tor_config/torrc
Add configuration parameters
Set permissions:
:::bash
chmod 600 ~/.tor_config/torrc
chmod 700 ~/.tor_config
Restart Tor:
:::bash
sudo systemctl restart tor
tor --verify-config -f /path/to/torrc
tor --defaults-torrc /path/to/torrc --verify-config
# Start Tor with custom config
tor -f /path/to/torrc
# Check if Tor is running
ps aux | grep tor
ControlPort 9051
HashedControlPassword 16:YOUR_HASHED_PASSWORD
SocksPort 9050
DataDirectory /var/lib/tor
ExitNodes {us},{de},{nl},{se},{ch}
StrictNodes 1
NewCircuitPeriod 60
MaxCircuitDirtiness 600
ControlPort 9051
HashedControlPassword 16:YOUR_HASHED_PASSWORD
SocksPort 9050
DataDirectory /var/lib/tor
CircuitBuildTimeout 30
NewCircuitPeriod 15
MaxCircuitDirtiness 180
NumEntryGuards 8
ControlPort 9051
HashedControlPassword 16:YOUR_HASHED_PASSWORD
SocksPort 9050
DataDirectory /var/lib/tor
ExitNodes {nl},{de},{gb},{fr}
CircuitBuildTimeout 45
# Backup torrc
cp ~/.tor_config/torrc ~/.tor_config/torrc.backup
# Backup entire config directory
tar -czf tor_config_backup.tar.gz ~/.tor_config/
# Restore torrc
cp ~/.tor_config/torrc.backup ~/.tor_config/torrc
# Restore entire directory
tar -xzf tor_config_backup.tar.gz -C ~/
Check file permissions:
:::bash
ls -la ~/.tor_config/torrc
Validate syntax:
:::bash
tor --verify-config -f ~/.tor_config/torrc
Check Tor logs:
:::bash
tail -f /var/log/tor/notices.log
Verify password hash:
:::bash
tor --hash-password "your_password"
Check torrc authentication settings:
:::bash
cat ~/.tor_config/torrc | grep HashedControlPassword
Try cookie authentication:
:::bash
ls -la /run/tor/control.authcookie
Check what's using the port:
:::bash
netstat -tulnp | grep 9051
Kill conflicting process:
:::bash
kill -9 <pid></pid>
Change port in torrc:
ControlPort 9052
Last Updated: 2024-04-23
Wiki: FAQ
Wiki: Home
Wiki: Installation
Wiki: Security
Wiki: Troubleshooting
Wiki: User Guide