tomayac,
@tomayac@toot.cafe avatar

🌐 I'm embarrassingly bad at this, so hoping for help: if I want to access my #HomeAssistant from remote based on some sort of dynamic DNS address, what port openings, forwarding rules, Windows firewall settings, etc. do I need to adjust and at what component to make this work based on the setup in the slide: https://docs.google.com/presentation/d/115ovKcq2rSqks2f_MeV7NDqrkS3rxB_XqvqJD-HIQFs/edit?usp=sharing&resourcekey=0-LEm6we2P2x7_a13YbbALmA. Thanks in advance for your expertise!

maschaper,
@maschaper@freiburg.social avatar

@tomayac If you only need the webinterface the cloudflared add-on maybe is what you‘re searching

tomayac,
@tomayac@toot.cafe avatar

@maschaper Oh, this looks interesting, and probably is more secure than opening ports. Thank you, I'll check it out.

fm_volker,
@fm_volker@mastodon.social avatar

@tomayac Not 100% sure how you have configured the Nest/why your wifi is in the .86.-subnet and not in the .1. that falls out of the router?
I hope you didn't accidentally configure a double-NAT. Short checklist:

  • make sure that HA has an IP that is pinned down on the DHCP-server (is that the router or the Nest?)
  • start with forwarding 8123 from the router to HA:8123, that should be enough.

1/n

tomayac,
@tomayac@toot.cafe avatar

@fm_volker Thanks for getting back! I honestly just plugged the Nest in and it just worked ("it" being all the devices connecting to the mesh network). The router is in NAT (standard) mode, and the two add-on points are in Bridge mode. DNS is all handled by the Nest.

tomayac,
@tomayac@toot.cafe avatar
fm_volker,
@fm_volker@mastodon.social avatar

@tomayac It's true that for outgoing traffic double-NAT is not a problem (except conceptually annoying ;-). But if you have it, then incoming you'd need two forwarding rules, one from the Huawei to the Nest, and another one from the Nest to HA, because you can't reach HA directly from the router.

tomayac,
@tomayac@toot.cafe avatar

@fm_volker Thanks again! Yes, I guess this is what I'm asking. From Huawei to Nest, do I need to open the 8123 port? And then likewise open 8123 from Nest to HomeAssistant's IP?

AngryAnt,
@AngryAnt@mastodon.gamedev.place avatar

@tomayac The simpler and less security-risky approach would be to get https://www.nabucasa.com

If you want a less baked-in solution at a cheaper price point, https://tailscale.com is a good choice.

tomayac,
@tomayac@toot.cafe avatar

@AngryAnt Aware of those and supportive of paying for the service of an otherwise free software; or Ngrok as an alternative. I was explicitly hoping to see if I could roll it myself, though.

AngryAnt,
@AngryAnt@mastodon.gamedev.place avatar

@tomayac So, cheekily twisting your "roll it myself" words there in order to stay with the more secure option which does not involve poking holes in your firewalls:

  • Get a VPS.
  • Install a container or VM on it, running a relay of either:
    -- Headscale.
    -- Wireguard.
    -- SSH port mapping with a reverse proxy.
  • Have your Home Assistant maintain a connection to the relay.
  • All
  • Subscribed
  • Moderated
  • Favorites
  • homeassistant
  • ngwrru68w68
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • megavids
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • provamag3
  • JUstTest
  • All magazines