Ubuntu proxy settings live in several layers, and each program reads only some of them. The desktop dialog (Settings > Network > Proxy) covers GNOME apps and Chrome; terminal tools read the http_proxy and https_proxy environment variables; apt has its own proxy file; systemd services need their own lines. Set the layers you use, with the host, port and credentials from your ProxyHive order.

Steps checked against the GNOME Settings 46 interface (Ubuntu 24.04) and the Ubuntu Desktop Guide on 2026-09-30. The terminal parts were run in an ubuntu:24.04 container against a local proxy that requires a password.

Before you start

  1. Buy an IP and open the order in the dashboard at https://app.proxyhive.io.
  2. Copy HOST, the HTTP PORT, USERNAME and PASSWORD. Every ISP or datacenter IP is its own endpoint; use the HTTP port for everything below.
  3. For servers and services, consider the order's IP allowlist instead of a password: credentials in config files are readable by anyone with access to them. The authentication and allowlist guide covers the choice.

Ubuntu proxy settings in GNOME

  1. Open Settings and select Network.
  2. Click Proxy.
  3. Turn on Network Proxy and set Configuration to Manual.
  4. Under HTTP Proxy enter HOST in URL and the HTTP port in Port. Do the same under HTTPS Proxy.
  5. Add hosts that should connect directly to Ignored Hosts.
  6. Click Save.

Older releases label this Network proxy with a Method of None, Manual or Automatic, as the Ubuntu Desktop Guide describes. There are no username or password fields. Chrome follows this dialog under GNOME and asks for credentials when the proxy challenges; the Chrome guide has the details.

The same with gsettings

gsettings set org.gnome.system.proxy mode 'manual'
gsettings set org.gnome.system.proxy.http host 'HOST'
gsettings set org.gnome.system.proxy.http port PORT
gsettings set org.gnome.system.proxy.https host 'HOST'
gsettings set org.gnome.system.proxy.https port PORT
gsettings set org.gnome.system.proxy ignore-hosts "['localhost', '127.0.0.0/8', '::1']"
gsettings set org.gnome.system.proxy mode 'none'

The last line switches it off. The schema also has use-authentication, authentication-user and authentication-password keys under org.gnome.system.proxy.http, but the dialog does not expose them and you cannot count on an app reading them.

Set a proxy in the terminal with environment variables

export http_proxy="http://USERNAME:PASSWORD@HOST:PORT"
export https_proxy="$http_proxy"
export no_proxy="localhost,127.0.0.1,::1"
export HTTP_PROXY="$http_proxy" HTTPS_PROXY="$https_proxy" NO_PROXY="$no_proxy"

Set both cases. In our test, curl went through the proxy with https_proxy or HTTPS_PROXY, but ignored an upper-case HTTP_PROXY for an http:// URL and connected directly. URL-encode special characters in the password (@ becomes %40).

To make the variables permanent for every login, put them in /etc/environment as plain NAME="value" lines, with no export and no $variables. They apply from the next login. In our container a fresh login shell picked them up, and so did sudo, which loads the same file; variables you only export in your shell are dropped by sudo.

Ubuntu apt proxy

apt has its own setting and reads it under sudo whatever your environment says. Create /etc/apt/apt.conf.d/95proxy:

Acquire::http::Proxy "http://USERNAME:PASSWORD@HOST:PORT/";
Acquire::https::Proxy "http://USERNAME:PASSWORD@HOST:PORT/";

Then sudo chmod 600 /etc/apt/apt.conf.d/95proxy so other users cannot read the password. With that file, apt-get update in Ubuntu 24.04 fetched every index through our test proxy, and apt-config dump | grep -i proxy shows what apt loaded. A wrong password looks like this:

Err:1 http://archive.ubuntu.com/ubuntu noble InRelease
  407  Proxy Authentication Required [IP: 127.0.0.1 18820]

curl and wget

Both read the variables above; wget also went through the proxy with only https_proxy set. To test one request without touching your environment:

curl -x "http://HOST:PORT" -U "USERNAME:PASSWORD" "https://api.ipify.org?format=json"

The curl guide covers the flags in depth.

systemd service proxy

Services start from systemd, not from a login, so they see neither your shell variables nor /etc/environment. Give each service its own:

sudo systemctl edit myservice.service
[Service]
Environment="HTTP_PROXY=http://HOST:PORT"
Environment="HTTPS_PROXY=http://HOST:PORT"
Environment="NO_PROXY=localhost,127.0.0.1"

Save, then sudo systemctl restart myservice. Pair this with the IP allowlist: systemd's own documentation advises against passing secrets through environment variables. Docker's daemon is a service like this; the Docker guide covers it.

Verify the exit IP

curl -s "https://api.ipify.org?format=json"
env | grep -i _proxy

With the variables set, the first line should print the IP on your order. For a browser, open the same address in Chrome or Firefox. A static datacenter proxy suits a server that needs one fixed exit IP.

Troubleshooting

  • 407 Proxy Authentication Required. Wrong credentials, an unencoded special character, or the order uses the allowlist and this machine's IP is not on it.
  • Works in the terminal, not under sudo. Put the variables in /etc/environment, or use apt's own file.
  • curl skips the proxy for http:// URLs. Only HTTP_PROXY is set; add lower-case http_proxy.
  • A service still goes direct. It needs its own Environment= lines and a restart.

The proxy error codes guide decodes other statuses.