Skip to content
Adam Palma, home
← homelab

Remote access without opening ports

Why neither router has a single port forwarded, and how everything is still reachable.

updated · Cloudflare Tunnel · Tailscale · Security

Two doors, both locked from the inside

Me and my friend had recently switched to T-Mobile Home Internet. T-Mobile for home internet locks our ips behind CGNAT which doesn’t allow port forwarding.

  • Cloudflare Tunnel for the media apps. A small connector on the server makes an outbound connection to Cloudflare, so visitors reach Navidrome through Cloudflare’s edge and nothing on the home network accepts inbound connections.
  • Tailscale for everything else. Admin access, video, backups and file sync travel over an encrypted WireGuard mesh that only our own devices can join.

Why it matters for client sites

The same pattern (no public ports, everything behind an authenticated edge) is how I approach client hosting / staging environments / admin panels.