g3proxy
Enterprise-oriented generic forward proxy and TCP/TLS stream proxy
894 stars 81 forks last commit first released Apache-2.0
Actively maintained
Last commit 25 Aug 2026.

g3proxy is an enterprise-oriented generic proxy built in Rust for forwarding and controlling network traffic. It supports multiple proxy modes and is designed for performance, flexible routing policies, and security-focused traffic processing.
Key Features
- HTTP/1 and SOCKS5 forward proxy support
- TCP stream proxying, SNI proxying, and transparent proxying (TPROXY)
- Basic HTTP reverse proxy capabilities
- Proxy chaining with dynamic upstream proxy selection
- Flexible egress routing and customizable selection strategies
- TLS features including interception (MITM), decrypted traffic dumping, and protocol interception (HTTP, IMAP, SMTP)
- ICAP adaptation for integrating with third-party security products
- User authentication, per-user site configuration, and rich ACL/limit rules (ingress/egress/user-level)
- Metrics and observability integrations with detailed per-dimension monitoring
- Graceful reload for configuration changes
Use Cases
- Centralized enterprise forward proxy with policy enforcement and per-user controls
- Security inspection gateway using TLS interception and ICAP-based malware/DLP tooling
- Network traffic routing and failover via proxy chaining and egress selection
Limitations and Considerations
- Reverse proxy and NAT traversal capabilities are described as work-in-progress in the broader G3 project context
- TLS MITM and protocol interception require careful certificate management and may have compliance implications
g3proxy is well suited for organizations that need a fast, configurable proxy with strong access controls and traffic inspection options. Its Rust-based implementation and rich policy/routing features make it a solid foundation for enterprise proxy and security gateway deployments.
Categories:
Tags:
Tech Stack:
Similar to g3proxy

Kong Gateway
Cloud-native API and LLM gateway with extensible plugins
Kong Gateway is a high-performance, cloud-native API gateway for routing, securing, and observing API traffic, with an extensible plugin system and Kubernetes support.
Docker Socket Proxy
Security-enhanced proxy to restrict Docker socket API access
A ACL-based proxy that sits in front of the Docker daemon to block unsafe API endpoints while allowing authorized operations.

Apache HTTP Server
Open-source HTTP server for modern operating systems
Apache HTTP Server (httpd) is a secure, efficient, and extensible web server for hosting websites and web applications on Unix-like systems and Windows.
Squid
Caching proxy server for HTTP, HTTPS, FTP, and more
Squid is a high-performance caching proxy that accelerates web delivery, reduces bandwidth usage, and provides extensive access controls for proxy and reverse-proxy setups.

HAProxy
High-performance reverse proxy and load balancer for TCP and HTTP
HAProxy is a fast, reliable reverse proxy and load balancer for TCP and HTTP applications, providing high availability, TLS termination, health checks, and traffic routing.
GLAuth
Lightweight LDAP authentication server with pluggable backends
GLAuth is a lightweight LDAP/LDAPS authentication server for development, CI, and homelabs, supporting file, S3, SQL, or LDAP proxy backends and optional 2FA.

