Comment by ๐ SavaRocks
you'll need a VPN. you can install wireguard easy with docker (makes it much easier) and open only the ports wireguard needs. when family connects to the VPN it will be like they are connected to the lan, no more port forwading needed
2025-11-23 ยท 5 months ago
4 Later Comments โ
๐ Vindemiatrix ยท Nov 23 at 17:04:
Pretty sure you can configure tailscale to only allow specific LAN traffic, much easier than a conventional VPN
I've also heard good things about Tailscale. I've solved this with a VPN (wireguard) for my personal use.
๐ devoid ยท Nov 30 at 17:50:
I set up everything the "old-fashioned way" (in this case I'd use a vpn). Are you looking for a turnkey solution or would you like to (learn how to) diy?
๐ stack ยท Nov 30 at 18:20:
wireguard is a pretty good solution to many problems of creating geographically wide private networks or connecting a home network to a remote machine that acts as an Internet gateway.
Original Post
Homelab x security โ I'm thinking about making a homelab. I'm wonder what's the best / most secure practices. I'm not in tech as a field, but I know enough that I should be careful. If I only have a homelab available to the fellow residents of the Half_Elf_Monastery, then I don't need to open up ports on routers. I just point my/their phones to servicename.homelab.local, and then it only really works when they're at home. But what if I want it to work when we're out and about on Rumspringa or...