How to Fix ERR_SOCKS_CONNECTION_FAILED
Checks that tell a login problem from a wrong port, then fixes for Chrome and for scripts that use SOCKS5.
Updated
TL;DR
ERR_SOCKS_CONNECTION_FAILED (Chromium error -120) means the browser connected to its SOCKS proxy, but the SOCKS handshake or the proxy's own connection to the site failed. If the proxy needs a username and password, the fastest fix is to point Chrome at an HTTP port of the same proxy.
What the error looks like in each client
Chrome shows the code under a generic heading; the curl and Python rows differ by cause.
| Where | What you see |
|---|---|
| Chrome (page heading; the code is printed under it) | This site can't be reached |
| Puppeteer page.goto() | net::ERR_SOCKS_CONNECTION_FAILED at https://example.com |
| curl, proxy needs a login the command did not include | curl: (97) No authentication method was acceptable. |
| curl, wrong username or password | curl: (97) User was rejected by the SOCKS5 server (1 1). |
| curl 8.9 or later, site unreachable (older builds print Can't complete) | curl: (97) cannot complete SOCKS5 connection to example.com. (4) |
| Python requests without PySocks | requests.exceptions.InvalidSchema: Missing dependencies for SOCKS support. |
| Python requests with PySocks, proxy needs a login | (Caused by NewConnectionError("SOCKSConnection(host='example.com', port=80): Failed to establish a new connection: All offered SOCKS5 authentication methods were rejected")) |
Why this happens
Chrome got through to the proxy, but the proxy would not forward its traffic.
Usually the proxy requires a login, but Chrome's SOCKS5 greeting offers only the no-login option, so the proxy turns Chrome away. The same code appears when the proxy answers with an error such as host unreachable.
Diagnose your SOCKS error first
The first three checks need no terminal; checks four and five show what the proxy answered.
Open two or three other sites; if they load, the proxy let Chrome in but could not reach, or refused, the site that failed.
Check the SOCKS5 entry in your extension or system settings; if it holds a username and password, the proxy wants a login Chrome never sent.
Compare the port with your provider's SOCKS5 port range; if it falls in an HTTP range, Chrome is speaking SOCKS5 to an HTTP port.
Paste your proxy into the third card's cURL command and run it; exit 97 means the SOCKS handshake failed, and curl's message names the step.
Record chrome://net-export while you reload; in netlog-viewer.appspot.com, SOCKS_UNEXPECTED_AUTH means the proxy wanted a login, SOCKS_SERVER_ERROR gives its reply code.
Solutions ranked by effectiveness
Work from the top and stop once pages load; the third card is for scripts, not Chrome.
- Most common fix
Use an HTTP port or IP whitelisting
Applies when the SOCKS5 proxy has a username and password and fails in Chrome, Brave, Puppeteer or Selenium. Keep the login and switch to an HTTP port, or whitelist your IP.
Where you entered the SOCKS5 details, change the type to HTTP.
Give it an HTTP port from your dashboard and the same username and password.
For Puppeteer, pass that port in --proxy-server and the login through page.authenticate().
Or click Detect My IP under Whitelisted IPs, then clear the SOCKS5 username and password.
- Check next
Match the port and SOCKS version
Applies when no login is involved and every site fails. Pair the port with the right protocol, and make Chrome send SOCKS5, the only SOCKS version Geonode lists.
Use a SOCKS5 port: Geonode's rotating range is 11000 to 11010, sticky 12000 to 12010.
Write SOCKS5 HOST:PORT in a PAC file, since a plain SOCKS line means SOCKS4.
On Windows, empty the SOCKS field of the system proxy settings.
Use an extension or the --proxy-server="socks5://HOST:PORT" flag in its place.
- For developers
Send the SOCKS5 login from your script
Applies to curl and to Python or Node.js scripts, which can send a SOCKS5 login themselves. The socks5h scheme passes the site name to the proxy instead of looking it up locally.
curl -sS -o /dev/null -w "HTTP %{http_code}\n" \ -x "socks5h://USERNAME:PASSWORD@proxy.geonode.io:11000" \ https://example.com echo "curl exit code: $?"
Stop the SOCKS error from coming back
These habits keep each proxy entry's protocol and port in step, and catch clients that cannot log in.
Store each proxy as a full URL with its scheme, such as socks5://proxy.geonode.io:12000, so protocol and port travel together.
Before moving a setup from HTTP to SOCKS5, confirm every client in it can send a SOCKS5 login.
List requests[socks] in your requirements file, so a new environment keeps SOCKS support.
Related errors
Learn more
FAQ
Approve the IP your browser uses
Once it is on your Geonode whitelist, the browser needs no proxy password.


