That's right, mmproxy spoofs the client IP address. From the application's point of view, this spoofed connection, coming through Spectrum and mmproxy , is indistinguishable from a real one, connecting directly to the application. This technique requires some Linux routing trickery. The mmproxy daemon …