PIA Multi-Hop can help when a network blocks or restricts regular VPN traffic. However, using the Multi-Hop feature can reduce speed and increase latency. Whether you should enable it depends on your network and what you are doing online.
What Is PIA Multi-Hop and How Does It Work?
PIA Multi-Hop routes your internet traffic through an additional proxy server before sending it to a PIA VPN server. Your connection follows this path:
Your device → proxy server → PIA VPN server → internet
The proxy acts as an intermediate stop between your device and the VPN server. Websites and online services still see the IP address of the PIA VPN server, while the network you are using only sees your connection to the proxy. The network does not see the connection to a PIA VPN server.
Due to the additional proxy hop, PIA Multi-Hop is not suitable for activities that require fast speeds or low latency, such as gaming or making video calls. It’s also unsuitable for connections that are already slow or unstable. In such situations, a standard VPN connection is usually sufficient.
Shadowsocks vs. SOCKS5
When you open the Multi-Hop tab, you see two options: Shadowsocks and SOCKS5 Proxy.
Shadowsocks is an encrypted proxy designed to disguise VPN traffic as regular internet traffic. This makes it the better choice when a network blocks or restricts VPN connections. PIA manages the available Shadowsocks servers, and you can let the app select a suitable location automatically.
SOCKS5 routes your connection through a proxy but does not encrypt the connection to that proxy. The PIA VPN tunnel still encrypts your traffic as part of the overall connection, but SOCKS5 does not offer the same obfuscation benefits as Shadowsocks. It also requires you to manually enter a proxy IP address, port, and separate SOCKS5 credentials.
In most cases, Shadowsocks is the more convenient and suitable option. Use SOCKS5 only if you specifically need manual proxy routing and understand its limitations.
How to Enable Multi-Hop with Shadowsocks
- Open the PIA desktop app.
-
Select the three-dot menu in the upper-right corner.
-
Select Settings.
-
Open the Multi-Hop tab.
-
Select the checkbox next to Multi-Hop and Obfuscation.
-
Choose Shadowsocks as the proxy type.
-
Leave the Shadowsocks location set to Auto, or select Edit to choose a location manually.
-
If you clicked Edit, choose one of the available Shadowsocks locations, then click OK.
-
Return to the PIA dashboard and click the arrow to access the server list.
-
Choose your preferred VPN server.
-
Click the power button to connect.
Once connected, the PIA dashboard indicates that Shadowsocks is active.
If the connection is noticeably slow, try another Shadowsocks location or return the setting to Auto.
How to Enable Multi-Hop with SOCKS5
Using SOCKS5 requires separate proxy credentials and the IP address of PIA’s SOCKS5 server. Your SOCKS5 credentials are different from the username and password you use to sign into your PIA account.
Step 1: Generate Your SOCKS5 Credentials
-
Sign in to the PIA Client Control Panel and select Downloads.
-
Scroll to the VPN Settings section.
-
Find SOCKS and select Generate or Regenerate.
-
Copy the generated username and password. You will need them when configuring the PIA app.
Keep these credentials private. Anyone with access to them may be able to use the proxy through your account.
Step 2: Find the SOCKS5 Proxy IP Address
The PIA app requires the proxy server’s IP address rather than its hostname. You’ll need to resolve the following hostname to obtain a current IPv4 address: proxy-nl.privateinternetaccess.com
Follow the instructions for your device below.
Windows
-
Click the Windows Start button and open Command Prompt.
-
Enter the following command and hit Enter: “nslookup proxy-nl.privateinternetaccess.com”
-
Copy one of the IPv4 addresses shown in the results.
macOS
-
In Finder, go to Applications.
-
Find and open Utilities > Terminal.
-
Enter the following command and hit Enter: “host proxy-nl.privateinternetaccess.com”
-
Copy one of the IPv4 addresses shown in the results.
Linux
-
Open Terminal Emulator.
-
Type the following command and hit Enter: “host proxy-nl.privateinternetaccess.com”
-
Copy one of the IPv4 addresses shown in the results.
The returned IP addresses can change, so resolve the hostname again if an address stops working.
Step 3: Configure SOCKS5 in the PIA App
- Open the PIA desktop app.
-
Select the three-dot menu in the upper-right corner.
-
Select Settings.
-
Select the Multi-Hop tab.
-
Select the checkbox next to Multi-Hop and Obfuscation.
-
Choose SOCKS5 Proxy.
-
Enter the proxy IP address you obtained in the previous step.
-
Enter 1080 in the Port field.
-
Enter your generated SOCKS5 username and password.
-
Select OK to save the configuration.
-
Return to the PIA dashboard and click the arrow to access the server list.
-
Choose a VPN server.
-
Select the power button to connect.
Once connected, the dashboard indicates SOCKS5 is active.