Andrew Mercer
on this page

What it is

socat connects two "addresses" (TCP, UDP, Unix sockets, files, pipes, serial ports, TLS, processes) and relays data between them, in both directions. It does what netcat does and much more. Homepage: dest-unreach.org/socat.

The syntax is always socat <address1> <address2>.

Basic examples

# Simple TCP listener echoing to the terminal
socat TCP-LISTEN:1337,reuseaddr,fork STDOUT

# Connect the terminal to a remote TCP port
socat - TCP:example.com:80

# TCP port forward: local 8080 -> internal host 80 (one process per connection)
socat TCP-LISTEN:8080,reuseaddr,fork TCP:192.168.1.10:80

# Expose a Unix socket over TCP (for debugging, not production)
socat TCP-LISTEN:2375,reuseaddr,fork UNIX-CONNECT:/var/run/docker.sock

# Send a file
socat -u FILE:bigfile.tar.gz TCP:receiver:9000
socat -u TCP-LISTEN:9000,reuseaddr OPEN:bigfile.tar.gz,creat

fork handles each connection in a child process so the listener stays up; reuseaddr avoids "address in use" after restarts.

The Docker socket example gives anyone who can reach the port root on the host. Never bind it to a routable address.

TLS

# Generate a throwaway cert
openssl req -x509 -newkey rsa:2048 -nodes -keyout k.pem -out c.pem -days 30 -subj "/CN=localhost"
cat k.pem c.pem > server.pem

socat OPENSSL-LISTEN:4443,cert=server.pem,verify=0,reuseaddr,fork STDOUT
socat - OPENSSL:localhost:4443,verify=0

verify=0 disables certificate checking. Fine for a lab, not for anything real.

Debugging tip

Add -v for a hex/text transcript of the data as it crosses the relay, or -x for hex. Useful for peeking at a protocol between two endpoints you control.