- Joined
- Sep 16, 2018
- Messages
- 35,901
- Reaction score
- 12,072
Just wondering how people access home network resources from outside, like the router and NAS.
1. Using vendor provided solution:
Some of the solutions use cloud server based solutions which will work behind CGNAT. Some of the solutions may require you to have public IP (and may need to use DDNS since most of the users get dynamic Public IP address).
Asus router remote access from Internet: not working behind CGNAT or Double NAT
https://www.asus.com/sg/support/faq/1000926/
TP-Link router: remote management of wireless routers, with lots of limitations.
https://www.tp-link.com/sg/support/faq/1553/
https://www.tp-link.com/sg/support/faq/1697/
Some people think the above is not secure and prefer to use #2/#3/#4.
2. Using VPN servers like Wireguard, OpenVPN and IPSec. You will need public IP and this may be a problem for users behind CGNAT. IPv6 helps a bit but then you can only use networks with IPv6 access.
You may set up the VPN server on the home network router or other devices like a mini PC or Raspberry Pi.
Asus router Wireguard VPN sever setup guide
https://www.asus.com/sg/support/faq/1048280/
Asus router Instant Guard VPN server setup guide (IPsec based)
https://www.asus.com/sg/support/faq/1044340/
Asus router Instant Guard VPN server setup guide behind another router (Double NAT)
https://www.asus.com/sg/support/faq/1045725/
TP-Link Wireguard VPN server setup for Archer series
https://www.tp-link.com/sg/support/faq/3772/
TP-Link Wireguard VPN server setup for Deco series
https://www.tp-link.com/sg/support/faq/3988/
PIVPN with Wireguard or OpenVPN
https://www.pivpn.io/
3. Using overlay VPN like Tailscale, Zerotier and Netbird. Usually this can work behind CGNAT.
Tailscale KB
https://tailscale.com/kb
Zerotier document
https://docs.zerotier.com/
Netbird document
https://docs.netbird.io/
Nebula document
https://nebula.defined.net/docs/
Netmaker document
https://docs.netmaker.io/docs/about
Twingate (Closed Source)
https://www.twingate.com/docs/
4. Using other remote access solutions like Cloudflare Tunnel and Pangolin
Cloudflare tunnel - you will need a domain name and public IP address.
https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/
Pangolin - Pangolin is a self-hosted tunneled reverse proxy server with identity and access control, designed to securely expose private resources on distributed networks. You need a domain name and public IP address.
https://github.com/fosrl/pangolin
FRP: frp is a fast reverse proxy that allows you to expose a local server located behind a NAT or firewall to the Internet
https://gofrp.org/en/
5. Using things like Teamviewer, RustDesk and Chrome Remote Desktop, to access a specific device at home.
Teamviewer Remote
https://www.teamviewer.com/apac/products/remote/
RustDesk: Fast Open-Source Remote Access and Support Software
https://rustdesk.com/
Chrome Remote Desktop
https://remotedesktop.google.com/?pli=1
6. More options
https://github.com/anderspitman/awesome-tunneling
1. Using vendor provided solution:
Some of the solutions use cloud server based solutions which will work behind CGNAT. Some of the solutions may require you to have public IP (and may need to use DDNS since most of the users get dynamic Public IP address).
Asus router remote access from Internet: not working behind CGNAT or Double NAT
https://www.asus.com/sg/support/faq/1000926/
TP-Link router: remote management of wireless routers, with lots of limitations.
https://www.tp-link.com/sg/support/faq/1553/
https://www.tp-link.com/sg/support/faq/1697/
Some people think the above is not secure and prefer to use #2/#3/#4.
2. Using VPN servers like Wireguard, OpenVPN and IPSec. You will need public IP and this may be a problem for users behind CGNAT. IPv6 helps a bit but then you can only use networks with IPv6 access.
You may set up the VPN server on the home network router or other devices like a mini PC or Raspberry Pi.
Asus router Wireguard VPN sever setup guide
https://www.asus.com/sg/support/faq/1048280/
Asus router Instant Guard VPN server setup guide (IPsec based)
https://www.asus.com/sg/support/faq/1044340/
Asus router Instant Guard VPN server setup guide behind another router (Double NAT)
https://www.asus.com/sg/support/faq/1045725/
TP-Link Wireguard VPN server setup for Archer series
https://www.tp-link.com/sg/support/faq/3772/
TP-Link Wireguard VPN server setup for Deco series
https://www.tp-link.com/sg/support/faq/3988/
PIVPN with Wireguard or OpenVPN
https://www.pivpn.io/
3. Using overlay VPN like Tailscale, Zerotier and Netbird. Usually this can work behind CGNAT.
Tailscale KB
https://tailscale.com/kb
Zerotier document
https://docs.zerotier.com/
Netbird document
https://docs.netbird.io/
Nebula document
https://nebula.defined.net/docs/
Netmaker document
https://docs.netmaker.io/docs/about
Twingate (Closed Source)
https://www.twingate.com/docs/
4. Using other remote access solutions like Cloudflare Tunnel and Pangolin
Cloudflare tunnel - you will need a domain name and public IP address.
https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/
Pangolin - Pangolin is a self-hosted tunneled reverse proxy server with identity and access control, designed to securely expose private resources on distributed networks. You need a domain name and public IP address.
https://github.com/fosrl/pangolin
FRP: frp is a fast reverse proxy that allows you to expose a local server located behind a NAT or firewall to the Internet
https://gofrp.org/en/
5. Using things like Teamviewer, RustDesk and Chrome Remote Desktop, to access a specific device at home.
Teamviewer Remote
https://www.teamviewer.com/apac/products/remote/
RustDesk: Fast Open-Source Remote Access and Support Software
https://rustdesk.com/
Chrome Remote Desktop
https://remotedesktop.google.com/?pli=1
6. More options
https://github.com/anderspitman/awesome-tunneling
Last edited: