Reaching a device at your home from the Internet

Static IP, dedicated IP, port forwarding, “open NAT,” remote access

Our network is designed for your security first

On the Further Reach network, nothing on the Internet can start a connection to your home. Your devices reach out, and the replies come back. Uninvited traffic never arrives. There is no door for anyone to try.

This matters more every year. According to the 2026 Imperva Bad Bot Report, bots now generate more than half of all web traffic, malicious bots alone account for 40% of all traffic, and AI-driven bot attacks grew more than twelve-fold in a single year. Every home with a public IP address is scanned around the clock by automated tools looking for an open port, an old camera, or a router with a default password. Staying ahead of that means running and maintaining your own firewall, forever.

We handle that for you. Because your home is not reachable from the Internet, you don’t have to outsmart the bots. This protection is part of every Further Reach subscription. Your devices and passwords are still yours to keep updated.

Disclaimer: read before continuing

It is a best practice to employ an Internet firewall that blocks inbound Internet traffic – that is, traffic initiated from outside your home or office network to your home network. Firewalls block this inbound traffic but allow outbound traffic like when you browse the Internet, stream, send/receive emails.

Hence, services such as gaming, business or industrial applications that require a static or dedicated IP often do so because those “SERVICES” initiate traffic from a location on the Internet to the devices on your home network. Allowing inbound Internet traffic originating from the public Internet is inherently dangerous because it could enable attacking devices on your home network.

BY FOLLOWING THESE INSTRUCTIONS, YOU AGREE THAT TO THE FULLEST EXTENT PERMITTED BY LAW, FURTHER REACH DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, STATUTORY OR OTHERWISE REGARDING THESE INSTRUCTIONS. YOU ACKNOWLEDGE THE INHERENT RISKS OF BYPASSING THE FURTHER REACH FIREWALL AND RELEASE FURTHER REACH OF ANY AND ALL DAMAGES OR LIABILITY ASSOCIATED WITH YOUR DOING SO.

Letting connections from the Internet into your home anyway

Sometimes you do want something at home reachable from outside: a camera, a file server, a website, a game server. Each method below is a way to let a connection that starts on the Internet reach a device in your home, which is exactly what our network otherwise blocks. That is why the disclaimer applies. The methods go from easiest to most involved. Pick the first one that fits.

  • Option 0 Use a product that has remote access built in: cameras, doorbells, smart home, NAS.
  • Option 1 Let only yourself and people you trust reach your home devices: Plex or Jellyfin, remote desktop, Home Assistant, a NAS at full speed, a 3D printer.
  • Option 2 Let anyone reach a website, blog, or web app you host, for free.
  • Option 3 Have your own public IP address: your own domain on your own terms, any port, any protocol, or a fixed address you can point anything at.

About the time estimates. Options 0 and 1 are point-and-click. Options 2 and 3 involve the command line, and Option 3 also involves server and router configuration. None of them takes more than about 45 minutes if you are working with an AI agent (Claude, ChatGPT, or similar) and know how to use one, or if you are experienced with networking. Without either, expect them to take much longer.

Option 0: The product already does it

Usually free or included with the product. Nothing to set up on our network. No technical skill needed.

Most products sold today connect out to the manufacturer’s cloud and let you reach them through it. Look in the product’s app or settings for “remote access,” “cloud access,” or “relay” and turn it on.

Products known to work this way

Home Assistant Cloud (paid subscription), Synology QuickConnect, UniFi Remote Access, Ring, Nest, Wyze, Eufy, and most NAS and camera brands. Xbox and PlayStation online play works for most games; party chat and hosting features that need an “open” NAT type may not.

Plex is the exception: its Remote Access feature falls back to a slow relay on our network. Use Option 1 for Plex.

Option 1: Private access to your home network

Free. About 15 minutes. No command line, no AI agent needed.

For when only you and people you choose need in: watching your Plex or Jellyfin library from away, remote desktop to a home computer, Home Assistant, full-speed access to a NAS, checking on a 3D printer. Nothing is visible to the public. Uses Tailscale, free for personal use.

Requirement: a computer at your home that stays powered on and connected to the Internet whenever you want to reach your home network remotely. If it’s asleep or off, nothing works. A desktop, a mini PC, a Raspberry Pi, or a NAS that supports Tailscale all work. A laptop that gets closed does not.

Show the steps
  1. Create a Tailscale account.
  2. Install Tailscale on the always-on home computer. Sign in.
  3. Install Tailscale on your laptop and phone. Sign in with the same account.
  4. You can now reach that home computer from anywhere by the name Tailscale shows.
  5. To reach everything on your home network (printers, cameras, NAS), turn on “subnet router” on the home computer and enter your home network range (usually 192.168.x.0/24; ask us if unsure). Approve it in the Tailscale admin page. Now every device at home is reachable from your laptop and phone.
  6. To let a friend or family member in, invite them to your Tailscale network from the admin page.

Limit: only devices signed into Tailscale can connect. The public cannot.

Option 2: A public website or web app, for free

Free. About 30 minutes. Uses the command line; an AI agent is recommended unless you are comfortable there.

For when anyone on the Internet should be able to open your site or app in a browser, without installing anything.

How it works: a small program on your home computer opens a connection out to a service on the Internet and keeps it open. Visitors go to that service, which passes their traffic down the open connection to your computer. The Internet never connects to your home directly.

Requirement: the computer running your site must stay powered on and connected whenever you want the site reachable.

2A. Tailscale Funnel — no domain name needed
  1. Do steps 1–2 of Option 1 on the computer running your site.
  2. In the Tailscale admin page, enable Funnel for that computer (the first time you run the command below, it prints a link that does this).
  3. On that computer run: tailscale funnel --bg 8080 (replace 8080 with the port your site runs on).
  4. Your site is now at https://..ts.net. Tailscale provides the HTTPS certificate.

Limits: HTTPS only. The address ends in .ts.net; you cannot use your own domain. Fine for personal and small-group use.

2B. Cloudflare Tunnel — use your own domain name
  1. Own a domain (about $10/year from Cloudflare or any registrar) and put its DNS on Cloudflare (free plan).
  2. In Cloudflare, go to Zero Trust → Networks → Tunnels → Create a tunnel. Cloudflare shows a one-line install command for cloudflared.
  3. Run that command on the computer hosting your site.
  4. In the tunnel’s “Public Hostname” tab, add home.yourdomain.com → https://localhost:8080 (your site’s port).
  5. Your site is now at https://home.yourdomain.com, with Cloudflare providing the certificate.

Limits: web traffic only. Cloudflare decrypts traffic at its edge, so don’t use it for anything you need kept private from Cloudflare. Cloudflare’s free plan is not meant for heavy media streaming; if that is your use, see Option 3A.

Stuck on either of these? Ask us. We can help.

Option 3: Your own public IP address, through a cloud server

About $6/month. About 45 minutes, most of it creating the DigitalOcean account. An AI agent or real networking experience is required. This is not a point-and-click setup.

The idea, in plain terms. You rent a tiny computer on the Internet – a “cloud server” – for about $6 a month. It has its own public IP address. Something at your home opens a permanent, encrypted tunnel out to that server and keeps it open. Anything sent to the server’s address travels back through the tunnel to your home. To the outside world, the server’s address is your address.

Your home never accepts an incoming connection. It only ever connects out, to a server you control. That is what keeps this compatible with our network.

Why choose this over Option 2: you get an address that is entirely yours. Any domain name, any port, any protocol, no third party in the middle, no free-tier limits. It works for a personal media server with heavy streaming, a mail server, SSH, a game server, industrial or monitoring equipment, or a private VPN back into your home from wherever you are.

The tunnel is WireGuard. It is built into most operating systems and routers. It has one property that matters on our network: if our side of your connection changes address (which it can, during maintenance or failover), the tunnel re-establishes itself without any action from you.

There are two ways to build it. Pick the first one that fits.

3A. One device, nothing changes on your router

About 45 minutes.

For when one specific device is what you want reachable: a Mac or PC running Plex or Jellyfin, a home server, a NAS. The tunnel runs on that device itself. Your Further Reach router and everything else at home are untouched.

What you need and the steps

What you need:

  • A cloud server: DigitalOcean’s smallest droplet (about $6/month), Ubuntu.
  • The home device, running macOS, Windows, or Linux, powered on and connected whenever you want it reachable.
  • Optionally, a domain name, if you want watch.yourdomain.com rather than a bare IP address.

The steps:

  1. Create the droplet. Install WireGuard on it and configure it as the tunnel endpoint.
  2. Install WireGuard on your home device. Configure it to connect out to the droplet, with persistent keepalive set to 25 seconds. Without keepalive the tunnel drops on our network.
  3. Confirm the tunnel is up from both ends.
  4. On the droplet, install a reverse proxy (Caddy is the simplest) that answers on ports 80 and 443 and passes traffic down the tunnel to your device. Caddy obtains and renews the HTTPS certificate on its own. If you need ports other than 80 and 443, forward those instead.
  5. If using a domain, point it at the droplet’s IP address with a plain A record (no proxy or CDN in front of it).
  6. Test from a phone on cellular data.

Limits: only that one device is reachable. If you want more than one, see 3B.

3B. Your whole home network, through your own router

About 45 minutes.

For when several devices need to be reachable, the device you want can’t run WireGuard, or you want a fixed address for the whole site. The tunnel runs on a router you own, sitting behind the Further Reach equipment.

What you need and the steps

What you need:

  • A cloud server, as in 3A.
  • Your own router that runs WireGuard, plugged into the Further Reach equipment we installed. GL.iNet, OPNsense, pfSense, UniFi, MikroTik, or a Raspberry Pi all work. $30–200 if you don’t already have one.

The steps:

  1. Create the droplet. Install WireGuard on it and configure it as the tunnel hub.
  2. On your router, add a WireGuard interface pointing at the droplet, with persistent keepalive set to 25 seconds. Confirm the tunnel is up.
  3. On the droplet, forward the ports you want (for example 80, 443, 22) down the tunnel to your router.
  4. On your router, forward those ports to the device that should receive them, and route the replies back through the tunnel rather than out your normal connection. This last part is the step most people get wrong.
  5. Test from a phone on cellular data.

The same droplet can also serve as a private VPN entry point to your home network, or a hub connecting several locations, using standard WireGuard configuration.

Limits of Option 3, both versions: monthly cost. If the droplet is down, you are unreachable until it’s back. Whatever ports you open are open to the entire Internet, so open only what you need and keep those devices updated.

Getting help

  • Do it yourself. Options 0, 1, and 2 need no hardware, and we’re glad to answer questions along the way. Option 3 needs the cloud server and, for 3B, a WireGuard-capable router. Support for a self-built Option 3 setup is billed on a time-and-materials basis.
  • Have Further Reach do it. We can build and manage it for you. Contact us and we’ll send you a proposal.

Questions: support@furtherreach.net.

Updated September 2026.