PANE

Home-Lab Hosts Fighting Remote Access

Individuals managing self-hosted applications in home labs are experiencing significant frustration with complex networking configurations. They're grappling with issues like reverse proxy errors, VPN connectivity problems, file upload limitations, and unreliable network performance, hindering their ability to reliably access and share their services.

creator-economydevtoolsproductivityhomenetwork
FIT
0%
SIGNAL
77%
SOURCES60
FRESHEST POST1H AGO
TRACKED SINCE150D AGO

SOURCES (60)

I'm trying to set up a FreeIPA instance to manage identities on my local network, and after a lot of digging through documentation (primarily the RHEL IdM docs, but also the FreeIPA wiki and some random questionably-helpful blogposts), I feel like I'm nearing a working…

r/selfhosted9h ago
Source preview · reddit.com

what was the reason for this switch?

reddit.com1h ago
Source preview · reddit.com

Why don’t you use Tailscale’s built in on demand VPN to do this?

reddit.com1h ago
Source preview · reddit.com

Yes, exactly. In the vpn manager section

reddit.com9h ago

Hi, I’m trying to set up mTLS on my Android phone so that only devices with a valid client certificate can access my server. My setup is basically: Android phone (with .p12 file) → Caddy (reverse proxy + mTLS) → Home …

FORUM9h ago

Hello, So im wondering if someone has had this issue and how do you fix it? Nextcloud is set up and running as a VM on Promox. I can access it through the given IP from the proxmox VM console. But i want to use a reverse proxy for it, and also i have made a cloudflare tunnel so my family can access it whereever they are. Normally when i set up a reverse proxy through NGINX and cloudflare tunnels everything works as it should, but for Nextcloud its not working... Its strange because im able to ac

r/selfhosted11h ago

Try Pangolin and/or pocket id. If you use both you can reverse proxy, tunnel, they can have one login and dashboard (technically two) with everything they have access to. Sites are SSO locked behind Pangolin, but their pocketid that gets them into pangolin also can cover most everything else for logins. So they go to pangolin.yourdomain.tld or id.yourdomain.tld and they see everything you assign to them.

r/selfhosted13h ago

Hello everyone, I have installed tailscale and I can establish the vpn connection between the phone and home assistant. But despite me entering the correct credentials, home assistant refuses authentication. Do I need to…

FORUM17h ago

The problem: a dependent can be "healthy" by every current signal while its actual service is completely dead On rosa, qBittorrent (a dependent sharing gluetun's netns via AirVPN/WireGuard) had its inbound port forward silently die. The tunnel stayed up, DNS worked, every site in sites.conf stayed reachable, and (per Tenet 6 / ADR 0006) the dependent's interface and DNS both checked out fine — so gluetun monitor never saw a failure. Meanwhile every torrent in the queue sat at 0 B/s, apparently f

GITHUB17h ago

I use the traditional openvpn configured directly in my asus router, works great

r/selfhosted17h ago

I think this is very much related to our earlier talks about allowing multiple transports for one peer. Everything below this line is LLM written analysis of logs from a live two node setup. FIPS version: 0.6.0 dev ( rev 6b9faa0c2f ) Rust: rustc 1.94.1 (e408947bf 2026 03 25) OS: macOS 14.8.9, arm64 MAC addresses below are placeholders; the topology and counts are from a real two node setup. What I expected Two nodes joined by a direct cable use the cable. If they are also both on a shared wifi L

GITHUB20h ago
Source preview · forums.docker.com

Switching rootless Docker to lxc-user-nic network

forums.docker.com20h ago

This is why my TV has no more internet. And frequently complains about it. I have a fireTV connected to it, but I blocked all outgoing ports except 53,443 and it's using an adguard for dns

r/selfhosted21h ago
Source preview · reddit.com

Pangolin via vps

reddit.com21h ago

On the server check /var/log/secure and see if the user you are attempting to login with shows up. If you dont see any instance of that user or the ssh connection then its not even getting to the server

r/selfhosted21h ago

If you run it with the -v or -vv or -vvv flag, it will absolutely print something before it even connects to the server though.

r/selfhosted21h ago

Something is wrong then. You should get a success message, a failure message, or a no route to host message.

r/selfhosted21h ago

I'd try and strip back at much as possible, starting with ssh'ing from the machine to the machine if possible, using the IP address aetx and then slowing adding in layers (eg hostname, different vlan, remote) to try and isolate what layer is causing problems. I once had a router reset to an older configuration following a power cut, that messed up some stuff and puzzled me for a bit.

r/selfhosted21h ago

Weird one here. I’m looking to set my HA Green to have more than one IP address on my network. Is there a way to do this? Background, if anyone is wondering why I’d want to do this: I have a remote control that can conn…

FORUM21h ago

I found this useful guide - https://www.youtube.com/watch?v=oEaEAiLOqO4 I set up and running DuckDNS. I set up and runnig NGNIX. I have tested and cane remotely log into https://mydomain.duckdns.org and use HAOS UI. B…

FORUM22h ago

I have a similar thing. Outside of my network the DNS record resolves to tailscale ips. Within my network it resolves to the container names/ips

r/selfhosted1d ago

I use HA OS on a NUC, and I used to connect it remotely (either with a web browser or the mobile app). I use the DuckDNS extension, which redirects to my home router. The router is configured to redirect the HA port to t…

FORUM1d ago

One way to do this is have 2+ accounts (either they make their own or you set up a shared one for them) and just share your reverse proxy/services to their account rather than all being on one common Tailnet and trying to lock everything down with ACLs

r/selfhosted1d ago

Can you please provide more details on your observability setup? How do you see that services are trying to bypass your dns? What switch do you use? Do you think they are overkill?

r/selfhosted1d ago

Someone suggested Mikrotik, if you have the little money they cost, looks very interesting. I dont have as much budgeted for my network currently, but had bought a secondhand linksys ea6900, i wish there was openwrt support (with wireless, wired alone works, no wifi drivers) https://freshtomato.org/ does support wireless. And easy to configure + ssh access. I flashed the firmware already (else id ditched the device). And basically use what i got. Id prefer anything openwrt or ddwrt, but if a bsd

r/selfhosted1d ago
Source preview · reddit.com

Bind is pretty easy

reddit.com1d ago

I used dnsmasq for a couple years and it’s really simple. I gave it its own dedicated VM after a year as when it sat on my docker host, if that host ever had an issue DNS would stop working. I now configure kt with ansible, so in theory you coild use ansible to push the config to multiple locations. I stopped using dnsmasq a few weeks ago when I finally got a router with the capability to add custom entries.

r/selfhosted1d ago
Source preview · reddit.com

Bind9

reddit.com1d ago

unbound is also very easy to use! Could also use it on opnsense in combination with certs and caddy.

r/selfhosted1d ago
Source preview · reddit.com

Your router, probably.

reddit.com1d ago

Sort of. It's not about NAT. NAT is a translation layer for someone outside of your router trying to make a connection to something inside of your home network. So it lets you expose a service on a private network, like 192.168.1.12 for example, to a public network like the wan ip that your ISP gives you. Btw, very much not recommend to do this unless you really know what you're doing. Exposing internal resources like that can leave your network vulnerable to automated or targeted attack

r/selfhosted1d ago
Source preview · reddit.com

Use the host file

reddit.com1d ago

Wireguard is simple once it's set up. Click a button on my phone or laptop and I'm connected to all services on my home LAN.

r/selfhosted1d ago

And like... If you can't run a simple bind server for dns...that's rough technical debt.

r/sysadmin1d ago

Updated to 2026.8.3 today and started having odd issues. Yes I have a backup, yes I can roll back, but I don’t want to. I want to fix this issue. I understand that HTTP Config option has been moved from the YAML into a …

FORUM1d ago

Useful for intent and auditing, especially with containers. I’d still keep port rules as the final enforcement layer though, with the service mapping generated on top

r/selfhosted1d ago

What happens if you set up WireGuard on UDP:53 so it looks a little like DNS? Are you sure VPNs are completely blocked and it's not just that you're on CGNAT?

r/selfhosted1d ago

I don't get the connection, I use my VPN with public subdomains, it's great. But definitely, VPN is practical and recommended, to avoid exposing attackers. I switched from router WireGuard to tailscale for ipv4 issues and it's also just a toggle after setup

r/selfhosted1d ago

Is your feature request related to a problem? Please describe. ATM you need one target port per instance and one instance per domain. This will end in a nightmare with thousands of account on one host. Solution you would like. The solution is trivial: instead of this: cat /etc/anubis/0.env DIFFICULTY=4 METRICS BIND=127.0.0.1:9090 SERVE ROBOTS TXT=0 BIND=127.0.0.1:9000 TARGET=http://127.0.0.1:3001 ProxyPreserveHost=On use this: DNS=10.0.0.1 TARGET=http://$DOMAINNAME:3001 or: IPS=/etc/anubis/domai

GITHUB1d ago

Hey guys.I’ve been thinking about Linux firewalling and whether firewall rules should care about which service owns a port , not just the port itself. For example, instead of: allow TCP/443 you could say: nginx.service may expose TCP/443 publicly So if nginx stops and another process later binds 443, it wouldn’t automatically inherit that permission. Would this actually be useful on self-hosted Linux servers? Or are ports usually stable enough that nftables/firewalld already solves the problem w

r/selfhosted1d ago

Would've posted this to r/tailscale but whatever auto-filtering they got blocked it without any form of appeal so I'm posting here. I am sharing my tailnet selectively with my siblings so they get access to fun stuff like jellyfin. I have ACL tags setup on all the different VMs and stuff and those devices are properly hidden from them as I selected. However, whenever I attempt to tag proper clients (like my phone) seperately they are suddenly unable to connect to tailscale at all. Is the

r/selfhosted1d ago

Local is Ubuntu 26.04 (docker(portainer, pihole, nginx, Jellyfin) Wan side is cloudflare with my domain, registered with porkbun. <fakedomain.com> I’m comfortable interacting with docker compose yml files, though I don’t fully understand them. I also have a pretty fair understanding of what my Lan looks like, enough to assign static ip addresses to my Linux box and NAS. How exactly does one use cloudflare and nginx to point jellyfin.fakedomain.com to my Jellyfin container safely? I feel li

r/selfhosted1d ago

Yes, it falls back to DNS to locate but not guaranteed a local DC, its just whichever it pings responds first. It also reduces running the discovery process much more frequently. I actually don't believe it's the issue because as noted gpupdate works whereas with /force it fails which is just plain odd. We have a very large multi site network spanning the country and I have not seen this issue with our WiFi devices.

r/sysadmin1d ago

Strange. That shouldn't be possible in my opinion as it is just UDP. Have you tried messing with the MTU? Lowering it might help

r/selfhosted1d ago

Realtime /v1/realtime/calls suddenly failing with 401 ip_not_authorized despite static Cloud Run IP being allowlisted

FORUM1d ago

Environment Version: v0.3.0 ( pi windows amd64.exe ) OS: Windows Server 2022 Region: mainland China (representative of any region where direct routes to provider endpoints are blocked or slow) The problem pi agent rust's HTTP client has no proxy support at all : src/http/client.rs contains no proxy wiring (no proxy option, no proxy lookup). The underlying stack (asupersync) has a proxy() builder method, but pi agent rust never calls it. The Windows system proxy (WinINET registry settings) is not

GITHUB1d ago

Yeah this is what I do too. If it's something I want friends to access, e.g. copyparty, it's exposed. Otherwise, VPN.

r/selfhosted1d ago

I don't notice. Using Wireguard with my OPNsense router. My phone (and my kid's phones) auto connect to the VPN when we drop from the house WiFi. VPN only gets turned off when it reconnects to our SSID. Kids iPads and any laptops are easy to connect to when traveling as well. It's not even something I worry about as it just works and has for a number of years now.

r/selfhosted1d ago

Just turn it on and leave it on. As long as hairpin nat is enable (opnsense does this by default) you litterally wont notice.

r/selfhosted1d ago

I have 2 items for my home lab that run through a cloudflare tunnel but are blocked by cloudflare access requiring okta. The rest I use wireguard to access

r/selfhosted1d ago
Source preview · reddit.com

I have mine automatically turn on/off when I open/close a specific app.

reddit.com1d ago

I use Tailscale. It’s really easy to setup and I have not had any issues accessing my homelab away from home. We are constantly streaming, or accessing self hosted apps or using my LLM. No issues at all.

r/selfhosted1d ago

With Wireguard you don’t need a custom shortcut, it’s built into the WG app

r/selfhosted1d ago

In LAB manual IP assigned to VMs without gateway set. Now the security team ask to install crowdstrike but without gateway it wont work and also does not connect cloud server. Is there any way to have proxy server in between the lab VM PC and cloud server? submitted by /u/Less_Secret7729 [link] [comments]

r/sysadmin1d ago

I have an automation on my phone, which turns on Tailscale when I open Home Assistant for example and I'm not home. I also think Tailscale has the option to only route the necessary traffir trough it and nothing else. So you could keep your vpn on all the time with no issues. Never had issues.

r/selfhosted2d ago

Using subdomains and VPN are not mutually exclusive options. I use both. But I don't need to access my services very often but still It's like a one button click on my phone to connect to VPN.

r/selfhosted2d ago

use a cloudflare tunnel or smth like pangolin? you dont lose the convenience to access services by using its subdomains and reduce exposure at the same time

r/selfhosted2d ago
Source preview · reddit.com

Tailscale with Tailnet

reddit.com2d ago

I use wireguard via a VPS relay as I'm on CGNAT. I honestly don't mind connecting in. I have a double tap shortcut set up on Android too

r/selfhosted2d ago
Source preview · reddit.com

It just fixed my typos in the post.

reddit.com2d ago

SOLUTION LANDSCAPE

Brought to you byTop Sectors

A Player feature.See how many ways this pain can be solved, who's already building, and where the gaps are.