Save 5% every month: use code 5OFFSTORM at checkout
Home / Guides / Backconnect proxy

What is a backconnect proxy and how does it work?

A backconnect proxy is a fixed gateway address that forwards each of your connections out through an IP from a large pool. You set one IP:PORT in your tool and never touch it again; the provider decides which exit IP carries each connection and when to switch. Rotation happens behind the gateway, not in your code.

Updated October 2026Proxy basics

With a classic proxy list you receive, say, 100 IP addresses and your software spreads requests across them. You track which ones are blocked, replace dead ones and write the rotation logic yourself. A backconnect proxy turns that around. You receive a gateway address, the gateway holds the pool, and it connects “back” out to the internet through whichever IP it assigns to your connection.

The term is used loosely. Some providers call any rotating residential product backconnect; others mean the gateway architecture in general. Here it means the architecture: one stable entry point, many changing exit IPs. Storm Proxies delivers its rotating product this way, which is why our gateways are listed as fixed IP:PORTs that never change.

Where people get stuck is the rotation itself: their IP doesn’t change when they expect it to, or it changes in the middle of a login. This page explains how a gateway decides, how per-request and timed rotation differ, and how to pick the right gateway for each job.

Which Storm plan fits

Storm’s rotating proxies are backconnect gateways in front of a pool of 700,000+ datacenter IPs, with three behaviours to choose from: a new IP per connection (Main), every 3 minutes or every 15 minutes. Residential ports are backconnect too, with one home IP per port that changes every 5 minutes. If your task needs the same IP for days, a backconnect gateway is the wrong tool; use private dedicated proxies.

Rotating proxies (from $14/mo): 700,000+ IPs behind fixed gateway IP:PORTs. New IP on every request, or every 3 or 15 minutes. USA, EU, USA+EU or Worldwide. Unlimited bandwidth on every plan.

Get 40 threads for $39/mo See all rotating proxies plans

Before you start

  1. Log in to the member area and copy your gateway IP:PORTs. They never change; the rotation happens on our side.
  2. Add the public IP of the computer or server that will run your tool under Authorized IPs, click Save, and allow up to 15 minutes before testing. Rotating and residential proxies use IP authentication, so there is no username or password.
  3. Count your threads: the tool’s total open connections must stay within your plan (for example 40 threads on the 40-thread plan).

How a request travels through a backconnect gateway

  1. Your tool opens a connection to the gateway

    Your scraper, browser or bot connects to the gateway IP:PORT as if it were an ordinary HTTP proxy. For an HTTPS site, it sends a CONNECT host:443 request asking the proxy to open a tunnel.

  2. The gateway checks who you are

    Before forwarding anything, the gateway decides whether you’re allowed in. Storm rotating and residential gateways do this by your source IP: the connection must come from an address listed under Authorized IPs in the member area.

  3. The gateway assigns an exit IP

    Depending on the gateway’s rule, it picks a fresh IP from the pool (Main), or reuses the IP currently assigned to this gateway for its time window (3-minute, 15-minute, or a residential port’s 5-minute slot).

  4. The request leaves from the exit IP

    The website sees the exit IP, never your own address and never the gateway address. For HTTPS, the gateway only relays encrypted bytes inside the tunnel; it can’t read the page.

  5. The response comes back the same way

    Data returns through the exit IP to the gateway and on to your tool. As long as your tool keeps this connection open, later requests on it leave from the same exit IP.

  6. A new connection can mean a new IP

    When your tool opens another connection, the gateway applies its rule again. On a per-request gateway that new connection gets a different IP; on a timed gateway it gets the same IP until the window ends.

See the rotation for yourself

Each curl call opens a fresh connection, so on the Main gateway you should see a different IP on most lines. Point the same loop at a 15-minute gateway and the IP should stay put.

Five new connections through the Main gateway (macOS / Linux)
for i in 1 2 3 4 5; do
  curl -s -x http://GATEWAY_IP:PORT https://api.ipify.org; echo
done
Same test in Windows PowerShell
1..5 | ForEach-Object {
  curl.exe -s -x http://GATEWAY_IP:PORT https://api.ipify.org; ""
}
Keep-alive pins one exit IP (Python)
import requests

s = requests.Session()                       # one pooled connection to the gateway
s.proxies = {"http": "http://GATEWAY_IP:PORT", "https": "http://GATEWAY_IP:PORT"}
for _ in range(3):
    print(s.get("https://api.ipify.org", timeout=20).text)   # same IP: same tunnel

for _ in range(3):
    print(requests.get("https://api.ipify.org", timeout=20,  # new tunnel each time
                       proxies=s.proxies).text)

Gateway IP:PORT vs a proxy list

Both approaches end with requests leaving from many IPs. The difference is who does the work.

  • Configuration. A list means pasting hundreds of lines into every tool and updating them when IPs are replaced. A gateway is one line, or a few if your plan includes several gateway ports, and it stays the same for the life of the account.
  • Rotation logic. With a list, your code chooses the next IP, retires blocked ones and balances load. With a gateway, the pool is managed for you, and a new connection is all it takes to get another IP.
  • Pool size. A list is limited to the IPs you were given. A gateway draws from the whole pool, which for Storm rotating plans is 700,000+ IPs.
  • Control. A list lets you pin a specific IP to a specific account forever and know exactly which address you’re on. A gateway doesn’t: you can’t choose or keep a particular exit IP beyond the gateway’s window.

That last point is the honest trade-off. If you need to say “account A always uses address X”, you want static IPs, not a backconnect gateway.

Per-request rotation vs timed rotation

Per-request (Storm’s Main gateway) assigns a new exit IP to each new connection. It’s the right choice for collecting data from many pages where no page depends on the previous one: product listings, search result pages, public profiles, price checks. Each connection looks unrelated, so rate limits tied to a single IP matter less.

Note the word connection. A tool that keeps one keep-alive connection or one HTTPS tunnel open will send many requests through it from the same IP. That’s why “my IP doesn’t change” is the most common backconnect support question. The fix is on the client side: open new connections, don’t reuse one.

Timed rotation (Storm’s 3-minute and 15-minute gateways) keeps the same exit IP for a window, then moves to another. Use it for short multi-step flows where the site would be confused by an IP change halfway: logging in and reading a page, filling a form over several screens, keeping a shopping cart. The 3-minute gateway is USA only, uses a mix of IP types and is meant for account registration, social sites and browsing; it isn’t for search-engine scraping. The window is fixed, so plan your flow to fit inside it or to tolerate a switch at the end.

Residential ports work on a schedule too: each port’s IP changes every 5 minutes at fixed times (minute 1, 6, 11, 16 and so on each hour). A connection that is open at that moment can drop, so long-running jobs should reconnect and retry.

Pros and cons of backconnect proxies

What you gain:

  • One stable address to configure, in any tool that accepts an HTTP proxy.
  • Access to a much larger pool than any list you could manage by hand.
  • No rotation code, no dead-IP cleanup, no reloading lists when IPs change.
  • Retries become simple: a failed request retried on a new connection usually leaves from a different IP.

What you give up:

  • You can’t choose a specific exit IP or keep it beyond the gateway’s window.
  • You can’t predict which IP comes next, so you can’t whitelist exit IPs on the target side.
  • Mid-session switches can break logins if you pick a per-request gateway for a stateful task.
  • Some checkers that test proxies by sending the same request twice get confused by the changing IP. ScrapeBox’s built-in proxy checker, for example, isn’t compatible with Storm gateways, although the gateways themselves work in ScrapeBox. Test in a browser instead.

How many gateways and threads you get

A gateway port is not the same as a thread. On Storm rotating plans, the number of gateway ports depends on the plan, and the thread count is the total number of connections you may have open across all of them at once. Spreading 40 workers over two gateway ports still means 40 threads, not 80.

On residential, each port is a gateway with its own exit IP, and it accepts up to 50 threads that all share that IP. If you want 10 different home IPs active together, you need 10 ports. For the full breakdown of threads, ports and requests per second, see proxy threads explained.

Choosing the right Storm gateway

  • Scraping many independent pages: Main gateway, rotating plan.
  • Search engines: Main gateway, and no more than a quarter of your threads (10 on a 40-thread plan).
  • Short logged-in flows, sign-ups, social browsing: 3-minute gateway (USA) or 15-minute gateway.
  • Sites that expect home connections: a residential port, one IP for 5 minutes at a time.
  • Accounts that must keep one IP for weeks: not a backconnect job. Use dedicated or social proxies.

Setting a gateway up in code is covered in the Python requests guide and the cURL guide.

Common errors and fixes

The IP never changes on the Main gatewayYour tool reuses one connection or tunnel (keep-alive, a shared session, a browser). Open a new connection per request, or send Connection: close.
Login drops after a few minutesYou’re on a per-request gateway, or your flow runs past the timed window. Use the 15-minute gateway and keep the flow inside the window, or switch to a dedicated IP.
Connection resets on residential at regular timesThe port rotated its IP at the 5-minute mark and the open connection was closed. Catch the error, reconnect and retry the request.
Every connection is reset as soon as it opensThe connecting IP isn’t on your Authorized IPs list, or it was added less than 15 minutes ago. The gateway accepts the connection and resets it rather than sending a 407. Check your public IP and the member area. “Connection refused” is different: check the port for a typo.
Proxy checker reports the gateway as deadSome checkers expect the same IP on every check. Try a real request in a browser or with curl -x instead.
Searches return CAPTCHAs quicklyToo many search-engine threads, or the wrong gateway. Use Main and keep search traffic to a quarter of your threads with backoff between queries.

FAQ

Is a backconnect proxy the same as a rotating proxy?

Nearly always in practice. Backconnect describes the setup (one gateway, many exit IPs); rotating describes the behaviour (the exit IP changes). Most rotating proxies today are delivered through a backconnect gateway.

Are backconnect proxies residential or datacenter?

Either. The gateway is just the access method. Storm’s rotating plans put datacenter IPs behind the gateway, and the residential plans put home IPs behind theirs.

Do Storm gateway addresses ever change?

No. The gateway IP:PORTs in your member area are fixed. Only the exit IPs behind them rotate, so you configure each tool once.

Can I force a new IP on a Storm gateway whenever I want?

On the Main rotating gateway, yes: open a new connection. On the 3- and 15-minute gateways and on residential ports, the IP changes on its own schedule; there’s no rotation link or button.

Can I use a backconnect proxy with a username and password?

Some providers allow it. Storm rotating and residential gateways use IP authorization only. If you need user:pass, for example on a machine whose IP changes, use private dedicated proxies.

Do backconnect proxies support SOCKS?

It depends on the provider. Storm gateways are HTTP(S) proxies only, not SOCKS, and they handle HTTPS sites through CONNECT tunnels.

Still have questions? Contact us here. A real person answers.

Related guides

Tool facts checked against the official documentation (October 2026): RFC 9110: HTTP Semantics, CONNECT method · curl manual: --proxy · Requests docs: Proxies. Storm Proxies facts: our plans page and refund policy.

Unlimited bandwidth. One flat monthly price.

Access is live the moment you pay, and the smallest package of each proxy type has a 24-hour money-back guarantee on your first order.