VK Retargeting Proxy farm software: a control panel for your mobile proxy farm
Built in-house

ProxyFarm — software to run your mobile proxy farm

Without our software a proxy farm is just a box of modems and an SSH prompt. With it you get a service you run with a mouse: every modem, every proxy and every client in plain sight. The licence is counted per modem.

Supported hardware
Sierra Wireless EM7455 / MC7455 / EM7455B
LTE Cat-6. The whole stack is written for them: session bring-up, rotation, composition switching
ZTE MF289Fsoon
LTE router, Cat-12 — support in progress
Tandem 4GTsoon
LTE router, Cat-6 — support in progress
  • SIM cards on smartphone tariffs work
  • IMEI change
  • TTL and TCP fingerprint (p0f) change
  • VPN on the same modem: VLESS with Reality, and Outline
How a proxy farm works: clients, a mini-PC running ProxyFarm, a USB hub with modems, and carrier networks

Take a walk through the proxy farm control panel

This is not a screenshot — switch the tabs and see how the panel actually works.

admin · admin
Modems online
9/10
Proxies active
9/10
Traffic ↓ total
412 GB
Traffic ↑ total
48 GB
Rotations 24h
391
Traffic over 24 hours ↓ in · ↑ out
Modem signal
port 1 92%
port 2 78%
port 3 64%
port 4 41%
port 5 0%
port 6 88%
port 7 71%
port 8 55%
port 9 83%
port 10 47%
Traffic per proxy
port 1 74.3 GB
port 2 61.8 GB
port 3 58.1 GB
port 4 49.6 GB
port 6 44.2 GB
port 7 38.7 GB
port 8 31.4 GB
port 9 29.8 GB
port 10 24.1 GB
Server load refreshed every 30 seconds
CPU 34%
RAM 9.7/15.6 GB
Swap 0.2/4.0 GB
Disk 48/220 GB
Load average1.24 · 0.98 · 0.87
CPU cores4
CPU temperature52 °C
Uptime27 days 4 hours
  • Shows at a glance what the farm is short of: CPU, memory or disk space.
Box uplink admin only
Mode
DHCP
Interface
enp2s0
Current address
192.168.88.19 / 24
Gateway
192.168.88.1
DHCP Static IP PPPoE L2TP/IPsec
Lock-out protection: if the box stops responding after applying the settings, it reverts to the previous ones by itself in about 20 seconds.
+ Proxy ▦ Tiles ☰ List
PortStatusSignal CarrierIP (CGNAT)IMEIMode ProxyActions
1 connected 92% MegaFon 100.121.159.95 352843055613316 qmi 1081 Manage ⟳ Restart
2 connected 78% MegaFon 10.240.221.169 359289041220118 qmi 1082 Manage ⟳ Restart
3 connected 64% MTS 100.89.55.24 359333072284500 qmi 1083 Manage ⟳ Restart
4 connected 41% Beeline 10.185.173.143 352843052531370 qmi 2084 Manage ⟳ Restart
5 no-sim 0% 352811047793777 qmi 1085 Manage ⟳ Restart
6 connected 88% MegaFon 10.112.123.119 359746041569943 qmi 3086 Manage ⟳ Restart
7 connected 71% MTS 100.70.227.150 352843059416450 qmi 1087 Manage ⟳ Restart
8 connected 55% T2 10.1.76.244 359300044245612 qmi 1088 Manage ⟳ Restart
9 connected 83% MegaFon 100.113.132.236 352811044329773 qmi 2089 Manage ⟳ Restart
10 connected 47% Beeline 10.188.87.66 359746047328534 qmi 1090 Manage ⟳ Restart
PortProtocolAuth ClientQuotaRotation Actions
1081 socks5 / http u1 : •••••• Alpha Media 120 / 500 GB 15 min Link Quota Logs
1082 socks5 / http by IP Alpha Media 340 / 500 GB by link Link Quota Logs
1083 socks5 / http u3 : •••••• Alpha Media 78 / 500 GB 15 min Link Quota Logs
2084 vless by key Beta Traffic 90 / 300 GB manual Link Quota
1085 socks5 / http u5 : •••••• Beta Traffic 0 / 300 GB manual Link Quota Logs
3086 outline by key Beta Traffic 52 / 300 GB 30 min Link Quota
1087 socks5 / http by IP Gamma Agency 210 / 400 GB by link Link Quota Logs
1088 socks5 / http u8 : •••••• Gamma Agency 164 / 400 GB 30 min Link Quota Logs
2089 vless by key Gamma Agency 52 / 400 GB manual Link Quota
1090 socks5 / http u10 : •••••• Alpha Media 96 / 500 GB 15 min Link Quota Logs
NameContactProxies ActivePortal
Alpha Media @alpha_ops 4 218 GB 26 GB yes Link
Beta Traffic @beta_team 3 94 GB 11 GB yes Link
Gamma Agency @gamma_adm 3 100 GB 11 GB yes Link
1 proxy is down: port 5 — SIM not detected. Hub 11-2.4.2, physical port 3.
TimeEvent Where to lookDetails
14:52 Proxy port stuck hub 11-2.4.2, port 3 no IP · 3d
13:18 Modem back hub 7-3.2, port 4 MegaFon · LTE
13:17 Modem dropped hub 7-3.2, port 4 USB disconnect
11:40 Hub revived hub 11-2.4 watchdog revived it
09:05 Modem quarantined hub 7-3.2, port 4 245 drops in 30 min
+ User
LoginRole ActiveCreated Actions
admin administrator yes 12.03.2026 Password Edit
operator operator yes 04.06.2026 Password Edit
audit viewer no 21.07.2026 Password Edit
  • Three roles: the administrator sees everything, the operator works with proxies and clients but not system settings, the viewer only looks.
  • The last administrator cannot be removed or demoted — not even by themselves.
About
Version1.12.21
Device fingerprintc458f7f7…e64c
Licenceactive
Seats (modems)10
Valid until01.09.2026
Copy fingerprint Apply key
Updates
Installed1.12.21
Available1.12.21
Channelstable
Check for updates Install
  • Signature and checksum are verified, the update installs into a separate slot, and any failure rolls back automatically.

Demo data. In your farm these will be your own modems.

What the proxy farm software does

Dashboard

Modems online, active proxies, inbound and outbound traffic, rotations over the last day. A 24-hour traffic chart, per-modem signal and rotation history — all on one screen. The box's own load is right there too: CPU, load average, memory, swap, disk, temperature and uptime, on colour-coded bars, so a shortage of resources shows up before your clients feel it.

Modems

Status, signal level, carrier, IMEI, CGNAT address and operating mode for every modem. Restart, rotate, switch to QMI and assign a port — with buttons, no console.

Proxies

SOCKS5 and HTTP on a single port, plus VLESS and Outline. Authentication by login and password or by IP. A ready-to-use connection string and share link, copied in one click.

IP rotation

On a schedule, via a link from an external system, or by hand from the panel. Every address change lands in the history: time, port, new IP and what triggered it.

Clients and portal

Create clients and give each one a personal portal with their own proxies. Traffic is metered per client: how much came in, how much went out, and where it went.

Quotas and limits

A traffic quota in gigabytes and an expiry date on any protocol. SOCKS5 and HTTP add a speed cap, a concurrent-connection limit and daily, weekly and monthly caps. When the quota runs out the proxy pauses itself.

Event log

Modem drops and recoveries with the exact hub and physical port. Your operator does not see "something broke" — they see where to put their hands.

Watchdogs

The farm repairs itself: it revives latched USB hubs, quarantines a flapping modem before it takes the others down, and surfaces proxy ports that are stuck and never come back.

Device fingerprint (p0f)

TCP fingerprint rewriting inside the kernel: five profiles — Android, Windows, iOS, none, and a mirror of the real client. Profiles were verified against live devices. Mirroring is available for SOCKS5 and HTTP.

Over-the-air updates

A new version installs from the panel with one button. The signature is verified, and if the farm does not come back up the rollback happens on its own.

Per-modem DNS

Every modem uses its own carrier resolver, so lookups never leak around the tunnel and give the farm away.

Runs on your side

The panel lives on the box itself, inside your network. We never see your traffic and keep none of your data.

Proxy farm technical specifications

Everything below comes from the shipping product, not from a roadmap. Where a figure depends on conditions, we say so.

Hardware

Modems
Sierra Wireless EM7455 / MC7455 / EM7455B, LTE Cat-6
SIM cards
Cards on smartphone tariffs work
IMEI change
Supported — the modem presents itself as a different device
TTL change
Changed together with the TCP fingerprint (p0f); for SOCKS5 and HTTP on the fly, without dropping sessions
Coming soon
ZTE MF289F (Cat-12) and Tandem 4GT (Cat-6) LTE routers — support in progress
Modem mode
QMI (raw-ip). A new modem in MBIM is switched over with a button in the panel, ~15 s
USB hub
Cascaded, externally powered — mandatory
Computer
Any x86 mini-PC with USB and wired Ethernet
Operating system
Ubuntu Server 24.04 LTS, installed from a ready-made image
Kernel
6.8 or newer

Capacity

Proven in production
40 modems on a single box
Typical delivery
A 10-port hub
Theoretical ceiling
~150 ports (routing-table numbering limit)
Licence
From 10 seats. A seat is a modem, no matter how many proxies run on it

IP rotation

Mechanism
Airplane mode — a full reconnect to the carrier
Dwell time
12 seconds — tuned so the carrier actually hands out a new address
Modes
Manual · by timer (interval per proxy) · by secret link
Automation
A GET on the link returns old → new; fits scripts and antidetect browsers
Safety
Never more than one rotation at a time on the same modem

Network and DNS

Per-modem DNS
Lookups go through the same modem to the carrier resolver — no leak to the host site
Box uplink
DHCP · static IP · PPPoE · L2TP/IPsec
Network rollback
If connectivity is lost after applying, settings revert automatically in ~20 s
IPv6
Not supported

Access and security

Panel
HTTPS with a certificate generated per box; HTTP is redirected
Address
https://proxyfarm.local:8080 on your local network, by name
Roles
Administrator · operator · viewer
Login protection
5 failures in 10 minutes → 15-minute lockout; passwords stored as PBKDF2-HMAC-SHA256
Isolation
The panel and SSH are blocked on modem interfaces — admin never faces the internet
Audit
Actions are recorded in the database on the box

Updates and licence

Updating
From a button in the panel. There is no automatic check
Update security
Signature and checksum verified; installed into a separate slot with automatic rollback
Data on update
Proxies, clients, counters and configs are left untouched
Without a licence
The panel opens and a key can be activated, but the proxies are stopped
Grace period
7 days after expiry — full functionality with a warning

Protocols

A single modem can run several services at once — for example SOCKS5, VLESS and Outline sharing one IP.

ProtocolDefault portAuthentication
SOCKS5 1080 + hub port number Login and password · by IP · none
HTTP 1080 + hub port number Login and password · by IP · none
VLESS (+ Reality) 2080 + hub port number By key (UUID)
Outline / Shadowsocks 3080 + hub port number By key
  • For VLESS and Outline the panel produces a ready-made link and a QR code the client scans with a phone. Works with v2rayNG, Hiddify and sing-box.
  • Reality disguises VLESS as another site. The masking domain must support TLS 1.3, X25519 and HTTP/2 — not every domain qualifies.
  • Proxy lists export to a text file in four line formats.

How a proxy farm is built

From the client application to the carrier network: where the panel sits, what the proxies run on, and at which point the TCP fingerprint is rewritten.

Diagram of a proxy farm: client, mini-PC running the ProxyFarm panel, USB hub with LTE modems, and carrier networks

TCP fingerprint profiles (p0f)

Rewriting happens inside the kernel, not in the proxy application, and covers the whole connection rather than just its opening. Profiles are taken from real devices and match them byte for byte.

p0f (Passive OS Fingerprinting) means working out the operating system from its networking handwriting. A site does not have to ask you anything: it simply looks at how your machine composes the very first packet of a connection — which values it puts into the TCP/IP headers and in what order it lists the options.

Android, iPhone and Windows each have their own stable handwriting, and a Linux server has one too — recognisable from the first packet. The method is called passive because it needs no JavaScript, no cookies and not a single request to you: looking at what you already sent is enough.

This is why a mobile IP alone no longer suffices. The address says "a phone on a mobile carrier", and the very first packet answers "no, this is a server". Our profiles bring the handwriting in line with whatever the proxy is presenting itself as.

Android Verified against a real Android 13
Windows Verified against a real Windows 11
iOS / macOS Verified against a real iOS 18.7
No rewriting The server fingerprint as it is
Mirror the client Copies your own user fingerprint byte for byte. SOCKS5 and HTTP only

Limits by protocol

CapabilitySOCKS5 / HTTPVLESS / Outline
Traffic quota in GB and expiry date
Traffic accounting and charts
Speed cap
Concurrent-connection limit
Daily, weekly and monthly caps
Connection logs in the panel
  • When the quota runs out or the term ends, the proxy pauses itself — checked every 2 minutes.

Proxy farm software licence pricing

You pay per modem, not per box. The software ships with the farm — the licence covers its use and support.

100 ₽ per modem per month
10 modems minimum package — 1,000 ₽ per month
−10% when paid a year upfront

Examples

FarmMonthlyYearly with discountWithout discount
10 modems 1,000 ₽ / mo 10,800 ₽ / yr 12,000 ₽
20 modems 2,000 ₽ / mo 21,600 ₽ / yr 24,000 ₽
40 modems 4,000 ₽ / mo 43,200 ₽ / yr 48,000 ₽
  • A licence seat is a modem, not a proxy. One modem can run SOCKS5, VLESS and Outline at the same time and still counts as a single seat.
  • Pay monthly or a year upfront. Paying yearly gives a 10% discount.
  • You can grow the farm at any time and only pay for the new modems.
  • After the term ends there is a 7-day grace period: everything keeps working and the panel warns you.

The licence: updates and support

Farm software is not a box you write to a disk once. Carriers change their networks, hardware fails, anti-fraud keeps learning: the product is alive and keeps being worked on, and that is what the licence pays for.

New versions install from the panel with one button

Check and install under "Help". The package is digitally signed, goes into a separate slot, and if the farm does not come back up the rollback to the previous version happens on its own. Proxies, clients, counters and configs are left untouched. There is no automatic check: you update when you decide to, not when we feel like it.

Fixes reach a farm that is already running

The latched-hub watchdog, the flapping-modem quarantine and the dead-proxy-port detector were not in the first release — they were added after those failures showed up on live farms. A box on a valid licence gets things like this with the next version.

We work through failures with you

Write to us on Telegram or by email. The conversation stays concrete: the event log on the box names the exact hub and physical port rather than saying "something broke", and the panel shows load, signal and rotation history per modem.

The farm does not stop the day the term ends

After expiry there is a 7-day grace period: everything keeps working in full and the panel warns you. After that the proxies stop, but the panel still opens and a key can be activated — your data and settings stay where they are.

Why the farm software matters more than the hardware

An operator runs the farm, not an engineer

A mouse instead of SSH and config files. Someone with no Linux background can add modems, hand out proxies and keep an eye on the farm.

You see faults before your client does

The panel surfaces the dropped modem, the latched hub and the dead proxy port by itself. You learn about the problem before a complaint arrives.

You pay per modem, not per box

The licence counts modems and does not care how many proxies you run on them or how much traffic you push. Grow the farm and you only pay for the new modems.

The farm is entirely yours

No dependence on proxy vendors and no sharing IPs with anyone. Location, carriers and SIM cards are your call.

How to deploy a proxy farm and run it

  1. Everything is managed from a web panel in the browser. No console, no SSH: modems, proxies, rotation, limits and clients are all configured with a mouse.
  2. Delivered as a disk image: write a bootable USB stick, install it and power the box on. It personalises itself on first boot — unique hostname, keys, passwords and disk expansion.
  3. No separate server or VPS required. The panel, the agent and the database all live on the box itself.
  4. The panel opens at https://proxyfarm.local:8080 on your local network — no need to know the IP. The certificate is generated individually on every box.
  5. Only the proxy ports are exposed outwards, and you forward those on your own router. The panel and SSH are blocked on the modem interfaces and never face the internet.
  6. If you plan to use the proxies remotely, order a "Static IP" service from your wired ISP.

Proxy farm software: frequently asked questions

What is a proxy farm and why does it need dedicated software?

A proxy farm is a computer with a USB hub and mobile modems that hands out mobile proxies. Without software you run such a farm over SSH and by editing config files: every new proxy, every rotation and every limit is a separate operation in the console. ProxyFarm replaces that with a web panel — modems, proxies, IP rotation, clients and quotas are configured with a mouse, and the state of the farm is visible on one screen.

How much does a proxy farm software licence cost?

100 ₽ per modem per month, with a minimum package of 10 modems — 1,000 ₽ a month. Paying a year upfront gives a 10% discount. A licence seat is a modem, not a proxy: SOCKS5, VLESS and Outline running on the same modem still count as one seat. You can grow the farm at any time and pay only for the new modems.

Which modems does the software support?

Sierra Wireless EM7455, MC7455 and EM7455B — LTE Cat-6. The whole stack is written for them: session bring-up, rotation and composition switching. Support for the ZTE MF289F (Cat-12) and Tandem 4GT (Cat-6) LTE routers is in progress. SIM cards on smartphone tariffs work, IMEI can be changed, and so can the TTL and the TCP fingerprint.

Do I need a separate server or VPS for the control panel?

No. The panel, the agent and the database all live on the box itself. The panel opens at https://proxyfarm.local:8080 on your local network — you never need to know the IP. Only the proxy ports are exposed outwards; the panel and SSH are blocked on the modem interfaces and never face the internet.

How is this different from a home-made farm on 3proxy?

A home-made 3proxy farm means config files, your own rotation scripts and a monitoring setup you have to write and then keep fixing. Here scheduled and link-triggered rotation, traffic quotas, speed and connection caps for SOCKS5 and HTTP, per-client accounting, a modem-drop log naming the exact hub and port, and watchdogs that revive latched USB hubs are all built in and driven from the browser.

Can the software be installed on a farm I already built?

Yes, provided the farm uses supported modems. The software ships as a disk image: write a bootable USB stick, install Ubuntu Server 24.04 LTS onto the box and power it on — it personalises itself from there. Any x86 mini-PC with USB and wired Ethernet will do; the USB hub must be cascaded and externally powered. 40 modems on a single box are proven in production.

Standalone offering

Network fingerprint (p0f) rewriting — available separately from the farm

Sites stopped looking at the IP alone a long time ago. Before a page is served they read how exactly your machine opens the connection — this is what p0f, passive OS fingerprinting, means — and conclude it is a server, not a phone. A mobile IP alone is no longer enough here: it confirms the geography and the carrier, but says nothing about the device behind it.

What our solution does

Rewrites the fingerprint inside the kernel
Not browser headers or the user agent, but the very manner in which a connection is opened. This is the layer browser antidetects cannot cover at all — it sits below them.
Five ready profiles
Android, Windows, iOS / macOS, a no-rewrite mode and a mirror mode. The profile is chosen per proxy, and it can be switched across all of them at once.
Profiles taken from live devices
Not assembled from documentation or copied out of public databases, but measured on real phones and computers and matched byte for byte. That is why they agree with what the receiving side sees.
Mirror mode
The connection adopts the fingerprint of your own user — the person who connected to the proxy. The traffic looks as if they went online directly from their own device. Available for SOCKS5 and HTTP.
Switching without dropping sessions
For SOCKS5 and HTTP the profile changes on the fly: open sessions survive and nothing needs restarting. VLESS and Outline need a brief restart of that modem's VPN daemon.
Covers VPN protocols too
Not proxies alone — VLESS and Outline connections get the selected profile too, any of the ready ones except mirror mode.

How this differs from the usual approaches

Below the browser layer
An antidetect browser edits what the page reports. Our solution edits how the machine itself behaves — and that is checked earlier and does not depend on which software you use.
No software on the client side
Nothing is installed on your users' devices and nothing is asked of them. It all happens at the exit, transparently.
An operational control, not a one-off setup
The profile is an ordinary proxy setting: visible in the interface, changed with a button, applied in bulk. It is a tool you operate, not a config written once.
Deployed on your own infrastructure
The solution is installed separately from the farm — on your servers and with your addresses. We hand it over and set it up; after that it is yours.

How it works inside

The rewriting lives in two places: a program inside the kernel that rewrites the packets, and a rebuilt proxy server that tells the kernel which profile to apply to each connection.

1
A program inside the kernel, on the network hooks
This is eBPF — code loaded into the Linux kernel itself and executed right in the network path. There are two programs: one sits on the interface where your user arrives and captures the fingerprint of their first packet; the other sits on the modem interface and rewrites the outgoing packet to match the chosen profile. Both run inside the kernel, never handing packets to ordinary programs, so they add no per-packet delay — and that is exactly why mirroring a live client is possible at all: both packets are visible at the same moment.
2
A rebuilt 3proxy carrying our patch
The proxy server is built from source with our changes. A -of<N> key appears in the proxy line of the config: having accepted a client, 3proxy tags its own outgoing connection with a service mark, and the kernel reads that mark to know which profile belongs to this particular connection. Client and outgoing connection are tied together by the client's address and port, so neighbouring proxies on the same box never get mixed up.
3
The profile is one digit in the config
-of0 mirrors the real client, -of1 is Android, -of2 is Windows, -of3 is iOS and macOS. Without the key the patch does nothing at all and the server's own fingerprint goes out — a separate, honest "no rewriting" mode.
4
Changing the profile is a one-line edit
In the panel you pick a profile with the mouse; underneath, that same digit changes in the proxy config and the new fingerprint takes effect within seconds — for SOCKS5 and HTTP without dropping open sessions. VLESS and Outline attach to the same kernel machinery at their own point: there the profile applies with a brief restart of that modem's VPN daemon, and client mirroring is not available.
This is what a proxy line with the profile key looks like
socks -p1088 -Dowwan-port8 -of0 -osTCP_NODELAY -ocTCP_NODELAY
  • What gets rewritten: TTL, window size, window scale, the set, order and length of the TCP options, and the behaviour on subsequent packets — not merely the first packet of the connection. That is why neither a repeat connection nor a long session slips past the check.
  • Works for IPv4. Mirroring the client fingerprint is available for SOCKS5 and HTTP.
Discuss a rollout

We will explain what a measurement on your own traffic would show, and demonstrate the result before you buy.

Contacts

For feedback write to Telegram @frigate_admin
Our email support@frigate-proxy.ru
You can also write to the online chat on this page.

Company Details

Website: frigate-proxy.ru

Individual Entrepreneur: Baktasheva Anastasiya Yuryevna

ITN: 563102071671

PSRNSP: 321565800014442

Registered: 26.02.2021, Interdistrict IFTS No. 10 for Orenburg region

Address: 460019, Orenburg, Sharlykskoe sh., 1/2

Phone: +79325409073