All locations active · 99.99% uptime
Space Strategy · Peer-to-Peer Session

Proxy for Stellaris: Scope, UDP and the Facts About NAT

In a Stellaris setup, the proxy question comes down to two topics: routing download and content traffic, and trying to route the session itself. The first is plain HTTPS work and runs without trouble. The second runs into the transport protocol, NAT behaviour and the client's proxy support. This page separates the two.

Scope of this guide

01
Two separate programsWhy the launcher's requests and the game session are managed separately.
02
UDP ASSOCIATEWhere SOCKS5's UDP promise holds and where it has no practical equivalent.
03
NAT and hole punchingWhat the proxy does and does not do while a peer-to-peer connection is being established.
04
VerificationWhich tests to run once the setup is complete.

Stellaris's network needs are shaped by the nature of the genre: over a long session, state information is synchronised at regular intervals; the volume is small but continuity matters. Mod and content downloads, by contrast, are a single large transfer. These two loads are nothing alike, and the proxy decision has to be made separately for each.

Most setups begin with one wrong assumption: "if I set a proxy on the system, everything will go through it." In reality, game clients open their own sockets and are under no obligation to read the operating system's proxy setting. If what you want to route is session traffic, the decision has to be made at the network layer, not in an application setting.

The sections below first break the traffic into its parts, then show which type of proxy can carry each part, and finally explain how to prove that the setup is working correctly.

The launcher and the game are not part of the same program

The first thing that starts when you click the game shortcut is the launcher. The launcher's job is not to run the game but to prepare the conditions under which it will start: installed add-ons, the active mod list, version information and the content catalogue. All of these are ordinary HTTPS requests and small in volume.

The real download load lies in mod and version content. Mod files come from the store client's workshop infrastructure; a large mod package can run to hundreds of megabytes, and a version update goes well beyond that. When this transfer passes through an exit billed by data transferred, it ends up costing more on the invoice than playing the game does.

Once the game client has started, the launcher's job is done; session traffic is now entirely the responsibility of a different process. That distinction is the foundation of the setup: a rule applied to the launcher does not cover the session, while a layer-level rule written for the session also takes in the launcher. Any change made without knowing which direction you are working in rests on guesswork.

There is also the store client's update service running in the background. It can download even after you close the game; under a system-wide rule, those downloads go through the tunnel as well. In setups that need to protect a quota, scheduling this service's automatic updates makes more difference than the proxy setting does.

DIAGRAMRelative weight of traffic types
Relative weight of traffic typesFive-column chart: launcher, mod download, session setup, in-session synchronisation and notification traffic.DISTRIBUTION6 /100Launcher requestssmall, frequent78 /100Mod and version downloadsheavy in a single burst9 /100Session setupshort handshake22 /100In-session synchronisationcontinuous but light4 /100Notifications and chatnegligible

The columns are not real measurements but representative shares showing the relative weight of the loads within the same setup.

What does SOCKS5 UDP ASSOCIATE promise, and where does it stop?

SOCKS5 is the only widely used proxy protocol that can carry UDP as well as TCP. It does so with the UDP ASSOCIATE command: the client sends an association request to the proxy, the proxy reserves a listening point, and datagrams are relayed through that point. On paper, this means real-time game traffic can also pass through a proxy.

In practice there are two walls. The first is on the service side: a significant share of the SOCKS5 exits on sale never open UDP at all, because it requires keeping state and allocating extra resources. The second is on the client side and is more absolute: for a game client to establish its UDP socket over SOCKS5, it has to support that in its own code. Such support is not a feature you can expect in game clients.

The conclusion is this: UDP ASSOCIATE buying an exit that supports it does not mean the game will use it. If you want the scope to be independent of the client, the answer lies not in the protocol but in the layer. The article on the differences between the two SOCKS versions difference between SOCKS4 and SOCKS5 and, for how the UDP side works, SOCKS5 UDP support goes into detail on the topic.

One more caveat: even when a UDP association is established, an extra header is carried for the datagrams and the path grows longer. So even where it is technically possible, this is not a setup that improves response time. The gain is in scope, not in speed.

DIAGRAMWhich traffic can be carried by which form of proxy?
Which traffic can be carried by which form of proxy?Four-row, four-column heat table: coverability scores for traffic types against proxy forms.INTENSITYHTTP CONNECTSOCKS5 (TCP)SOCKS5 + UDPDevice-wide tunnelLauncher / catalogue95959595Mod and patch downloads90909095Session handshake20455590Peer-to-peer datagram flow003580

The cells are coverability scores (0-100), not a measure of speed; a high value means that traffic can be carried over that path.

Identify the right exit for your Stellaris setup

For download-heavy use, bandwidth is the deciding factor; for long sessions, it is stability — and the two point to different products.

Choose whichever you need from our residential proxies, datacenter proxies, IPv6 and ISP solutions. Every plan comes with unlimited options, 99.9% uptime, rotating proxies, sticky sessions and 24/7 support. Ideal for web scraping, ad verification, SEO monitoring and digital data collection.

ISP ProxyStatic Turkish IPs registered to an ISP

ISP-registered static Türkiye IPs; they combine datacenter speed with the reputation of a real carrier. Ideal for long sessions and low-ping use.

150₺/mo

Starting price for 1 month

500–1000 Mbit130+ SubnetsDDoS Protection
View Plans

PACKAGE CONTENTS

  • Vodafone and Türk Telekom carriers
  • DDoS protection
  • Personalized setup
  • The lowest ping values
  • 500-1000 Mbit down/up speed
  • HTTP & SOCKS5 protocol support
  • Automatic delivery
  • Turkey location

For social media management and anyone who wants long sessions with low ping.

Read product details
Mobile Proxy4G/5G carrier IPs

The most natural mobile traffic, on 4G carrier IPs; high success rates even on the strictest platforms. Ideal for social media and automation work.

239₺/day

Starting daily price

LTE 4G15-40 MbpsDedicated SIM
View Plans

PACKAGE CONTENTS

  • LTE 4G mobile connection
  • Vodafone · Turkcell · Türk Telekom
  • 30 GB quota
  • 15-40 Mbps connection speed
  • Dedicated SIM card infrastructure
  • Username & password or IP:Port
  • IP change link
  • HTTPS / SOCKS5 (UDP)

Ideal for social media and gaming users; a good fit for individuals.

Read product details
Residential ProxyReal home-user IP pool

A real home-user IP pool, for the highest trust and the widest geographic coverage. The right choice for data collection and regional testing.

350₺/30 Days

Starts at 5 GB / 30 days

50K Connections190+ CountriesSticky Session
View Plans

PACKAGE CONTENTS

  • Real residential (home-user) IP pool
  • Rotating and sticky sessions
  • City and state targeting
  • HTTP(S) and SOCKS5 protocols
  • 24/7 priority support
  • Activation in 2 minutes
  • Suitable for social media management
  • Flexible session management

The right choice for data collection, regional testing and multi-account management.

Read product details
IPv6 ProxyA large next-generation IPv6 pool

A large IPv6 pool; an economical solution for high-volume, cost-sensitive projects. Google Ads compatible and future-proof.

100₺/plan

Starts at 100 units (total)

/64 Subnet100-500 MbitNetfactor ISP
View Plans

PACKAGE CONTENTS

  • Netfactor / Turknet ISP infrastructure
  • Google Ads compatible IPv6s
  • /64 subnet options
  • HTTP & HTTP(S) support
  • Automatic delivery
  • Unused (clean) IP pool
  • 100-500 Mbit speed
  • Large IPv6 address pool

For anyone who needs Google Ads compatibility, high-volume use and an economical solution.

Read product details

You can also explore our Rotating Proxy and Datacenter Proxy you can explore our solutions, and to try them out our free proxy list you can use.

Peer-to-peer connections, NAT type and hole punching

In the model where one of the players hosts the session, the connection is established between two home networks. Both sides are behind NAT: the router maps the internal address to an external one and only lets an inbound connection through if a mapping was opened earlier. That is why a handshake method called hole punching is used to connect two NATs: both sides send packets outward at the same time, and matching mappings are created on both routers.

The proxy has no place in this picture. A proxy exit does not preserve the source port behaviour that hole punching requires; what is more, the intervening node establishes the mapping through itself, so the other side sees the exit's address rather than your router's. In most setups the result is that a peer-to-peer session cannot be established over the proxy at all. Why NAT and a proxy do different jobs difference between a proxy and NAT article.

On a line using symmetric NAT or carrier-grade address sharing (CGNAT), the situation is tighter still: inbound connections are not accepted, and you cannot even configure port forwarding on the router. Here the workable solution is not a proxy but asking your ISP for a real public address, or leaving the hosting to a player whose connection allows it.

One more distinction needs clearing up: hole punching is not a way of getting around a security measure but a standard connection-establishment technique in which both sides take part willingly. It is the step needed for routers to recognise the request when two players want to connect to each other. That a proxy does not support this step is not a shortcoming but a natural consequence of its design: the proxy establishes the connection itself on the client's behalf and does not preserve your socket's footprint in the outside world.

Tip

If the session will not establish, separate the variables: first try without the proxy; if that fails, have another player host; if that fails too, look at your router's NAT behaviour. Make the proxy the last step in diagnosis, not the first.

Post-setup verification: what do you prove, and how?

Writing a rule does not show that traffic is actually going through it. The first step in verification is reading the exit address; the second is measuring which processes are covered. These are different questions and call for different tools.

Domain name resolution is what most setups overlook. When using SOCKS5, the client may resolve the target on its own network and hand the proxy only an IP; in that case the server you connect to is visible to your local DNS server, and a delivery node close to you is selected while the connection exits from another country. DNS leak test measures this.

The second check is whether the proxy adds headers to the request. Some exits add the X-Forwarded-For or Via header; that means the other side sees on the very first request that the connection is coming through an intermediate node. Proxy anonymity test reports which headers are being carried.

The third is a resilience check. A game client and a background update service together open more concurrent connections than you would expect; when the ceiling is reached, the symptom is not an error message but a silent drop. What the limit means and how to plan for it concurrent connection limit article.

DIAGRAMPost-setup verification checklist
Post-setup verification checklistFive-item checklist: exit address, DNS resolution, header check, process scope and connection ceiling.CHECKExit address readIs the rule actually being applied?DNS resolution checkedWhere is the domain name resolved?Header scan performedIs the intermediate node adding headers?Process scope measuredWhich program is going out through the tunnel?Connection ceiling testedIs the concurrent limit sufficient?

Do not consider the setup working until all five items pass; each one answers a different question.

Which type of exit, which location?

The choice of type depends on the nature of the work. In download-heavy use the deciding variable is bandwidth; here a datacenter exit is both the fastest and the cheapest option. When an exit close to a home network profile is needed, residential or ISP is preferred, but their bandwidth depends on the line and the cost grows quickly on large transfers.

UsagePrioritySuitable exitCaution
Mod and version downloadsBandwidthDatacenterPlan for speed, not quota
Launcher and catalogue requestsStabilityISPA static address makes diagnosis easier
Work that needs a home profileNetwork typeResidentialSpeed depends on the line
A fixed exit from a corporate networkAuditabilityISP or datacenterFollow your organisation's policy

There is only one rule for the location decision: do not lengthen the path. Keeping the exit close to both you and the target avoids a needless intercontinental detour. If you are connecting from Turkey and playing with a friend in Turkey, an exit on another continent brings nothing but harm.

The degree of sharing matters no less than the type. An exit in a crowded pool behaves erratically at peak hours even when it is the right type. Over a long session that variability shows up as drops that a one-off measurement never reveals.

The address type also determines how easy diagnosis will be. With a static exit, you have fixed the variable when you hit a problem: you can try again from the same address and compare the results. With a setup that hands you a different address from the pool each time, you cannot run the same test twice, because the second attempt goes out over an entirely different path. In a game with long sessions, this is the difference you cannot read from a product's specifications but feel the most in practice.

Symptom and cause: a quick diagnostic table

What you seeLikely causeWhat to try first
The mod list is not updatingThe workshop request falls outside the scopeCheck the store client's network setting
The game opens but the session cannot be joinedThe peer-to-peer handshake cannot be established over the proxyTry the session without the proxy and note the difference
The session establishes but stalls frequentlyThe exit is busy or the path is longTry a closer exit
Download speed is very lowThe residential line cannot carry the transferMove the download out of the tunnel
The connection drops after a whileThe concurrent connection ceiling has been reachedRead the limit in the panel and close background services
A certificate warning appearsAn intercepting point is establishing the TLS session with its own certificateDo not click through the warning on an exit you do not know

The certificate warning is the most serious item on this list. A properly configured HTTPS proxy does not interfere with the TLS session; it only carries encrypted bytes. If you see a warning, your traffic is being decrypted and re-encrypted somewhere; clicking past it in a session that carries account details means handing your credentials to the intervening party in readable form.

The other items all share the same method: one variable at a time. If you change the exit, the protocol and the rule layer together, you will never learn why, whatever the outcome. Writing down what you have tried in a short list keeps you from walking the same path twice.

Latency budget and continuity in long sessions

A proxy adds a stop along the way; the total path grows longer. For that reason, setting up a proxy does not improve the game's latency and in most setups increases it somewhat. In a game with a slow turn tempo, a few tens of milliseconds go unnoticed, but in long sessions the real issue is not latency but continuity: even a brief interruption disrupts synchronisation and can drop you from the session.

Three things affect continuity. The first is the load on the exit: in shared pools, peak hours change the measurement. The second is the session window: if the sticky duration is set shorter than your working session, the address changes without your noticing and the connection drops. The third is the stability of your own home line; a proxy does not fix that, it adds its own share on top.

Do not measure once and leave it at that. Measuring the same exit at different times of day exposes the variable a one-off test hides. If you are planning a long session, take the measurement at the hour the session will start.

Finally, the scope decision bears repeating: what you can expect from a proxy in this game is access and auditability. If you are playing on your own line, from your own country, with players you know, adding a layer in between has no concrete payoff.

Compliance, privacy and cases where a proxy is unnecessary

This page covers access, privacy and network management scenarios. Complying with the terms of use of games and stores is the user's responsibility; no use involving account multiplication, automated play or interference with the game's security measures is described or recommended here.

On the privacy side, what you need to know is clear: a proxy provider cannot read encrypted content, but it can see and log which addresses you connect to. That makes choosing a provider a matter of trust as much as a technical decision. Do not entrust a stream carrying account details to an exit without reading its logging policy.

The cases where a proxy genuinely helps are narrow: using a single auditable address when going out from a corporate or campus network, managing multiple machines through a single exit, recording how a store page looks from another country, or isolating the source of a network problem by changing the path. In most scenarios outside these, the right answer is not to add the layer at all.

Note

If you want to put all the traffic on your device into a single tunnel, the tool you are looking for is probably not a proxy. A proxy covers the application or layer you define; a tunnel that wraps the whole device establishes a separate transport layer and calls for a different configuration logic.

Questions about Stellaris and proxies

01I bought SOCKS5, so why does the game still connect directly?

Because the game client opens its own socket and is under no obligation to read the system proxy setting. Even if your SOCKS5 exit supports UDP ASSOCIATE the client will not route traffic through it unless it uses that command. Widening the scope requires per-application routing or a device-wide tunnel.

02Should I route mod and content downloads through the tunnel as well?

Not if you are on a plan metered by data. Large mod packages and version updates burn through a quota quickly. It is more economical to leave those transfers on your ordinary line and route only the small, frequent requests.

03Can I improve my NAT type with a proxy?

No. NAT behaviour is a matter for your router and your ISP; a proxy inserts a separate node in between and does not preserve the mapping that hole punching requires. If you are behind symmetric NAT or CGNAT, the fix sits on the provider side, not the proxy side.

04Why does my connection drop mid-session?

There are two common causes: the sticky session duration is set shorter than your working session and the address changed without your noticing, or the concurrent connection ceiling has been reached. Both produce silent drops with no error message; you can tell them apart by reading the duration and limit values in the panel.

05Which test proves my setup is working?

A single test is not enough. Reading the exit address shows that the rule is being applied, a DNS test shows where the domain name is resolved, and an anonymity test shows whether the intermediate node is adding headers. Run all three together, with the proxy on and off, and compare the results.

06How does an exit in a distant country affect the gaming experience?

It lengthens the path. If the player on the other end is close to you, a distant exit sends every packet on an unnecessary detour. The rule for choosing a location is simple: keep the exit as close as possible to both you and the other party.

07What can the operator of the exit see in my session?

It cannot read the content; on an encrypted stream it only carries the bytes. However, the addresses you connect to are visible on the exit server and can be logged. That makes the provider's logging policy no less important than its technical specifications.

Further reading

NEXT STEP

Set up a stable exit for long sessions.

Datacenter, ISP and residential options are managed from a single panel with the same access credentials.

FREEPROXY.TR

Looking for a free proxy? You're in the right place

A complete proxy platform where you can browse up-to-date free proxy addresses, compare HTTP and SOCKS proxy types, and check your proxy connections with free tools.