10-Minute Guide to a Secure Remote Home Lab Setup

Поділитися
Вставка
  • Опубліковано 27 вер 2024

КОМЕНТАРІ • 59

  • @hornetbad
    @hornetbad 7 місяців тому +11

    i was using cloudflare tunnel for some time BUT when i used tailscale i never looked back 👍thank you for this video man

    • @massgrave8x
      @massgrave8x 6 місяців тому +1

      two different product with two different purposes as far as I am aware. how did you replace cloudflare tunnel with tailscale?

  • @tetsujinXLIV
    @tetsujinXLIV 7 місяців тому +2

    The timing of this video is awesome! I plan on setting this up this weekend! Thanks for all the great videos!

  • @SickBeard
    @SickBeard 7 місяців тому +19

    Whenever this comes up, I just want to make sure that people are aware that Cloudflare MITMs all of your traffic (including HTTPS; going over the tunnel). That might be perfectly fine for most people, I just feel like they should be made aware.

    • @PowerUsr1
      @PowerUsr1 7 місяців тому +2

      Totally agree with you and I think Tom Lawrence did put a disclaimer.
      None the less I highly suggest setting up VPN.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS 7 місяців тому

      @@PowerUsr1 Yes also, people get excited about "Free Things" but Cloudflare Tunnels are a lock in to Cloudflare

  • @gibahcanada4494
    @gibahcanada4494 7 місяців тому +1

    Man.. Thank you very much. This example helped me a bunch with my setup!!!

  • @aflea8272
    @aflea8272 7 місяців тому +1

    thanks for the video. got it all set up and working with my rasberry pi 5 im configuring to replace my old pi 2b

  • @LinuxZombie
    @LinuxZombie 2 місяці тому

    I could never get mine to work!! Thank you!!!!!!!!!

  • @redeux
    @redeux 7 місяців тому

    Very cool. I hadnt yet seen the cf zero trust functionality used yet. That does look pretty interesting for some use cases I've been throwing around. Thanks for the video!

  • @mikeborrego9795
    @mikeborrego9795 7 місяців тому +3

    Can this setup be used to lock down my Reolink camera remote access

  • @breezy8504
    @breezy8504 7 місяців тому

    Thanks for the shout-out!

  • @chrisumali9841
    @chrisumali9841 7 місяців тому

    Thanks for the demo and info, have a great day

  • @bruxodasilva
    @bruxodasilva 7 місяців тому +2

    X in 10 mins, explained in a 20 min video :D Joke aside, keep up the excellent job!

    • @redeux
      @redeux 7 місяців тому +1

      My SO makes fun of me for doing this. I am glad I'm not the only one who confuses how long 10 minutes is 😅

  • @itninja9503
    @itninja9503 4 місяці тому

    would have been awesome if you showed how to set up an RDP connection.

  • @JoeRanieri
    @JoeRanieri 7 місяців тому +1

    Can you still connect with home assistant companion app, if you lock down the tunnel?

  • @conrat2000
    @conrat2000 7 місяців тому

    I really like Tailscale. But thos looks cool as well
    Thank!

  • @mrxmry3264
    @mrxmry3264 7 місяців тому +2

    i use tailscale to remotely access my home assistant. so far its been pretty reliable (but will it stay that way?)
    the only issue is that it sucks the battery dry FAST.

    • @lhamil64
      @lhamil64 7 місяців тому

      Your home assistant server is running on battery?

    • @jadamsnz
      @jadamsnz 7 місяців тому

      @@lhamil64 I imagine he’s using a battery powered mobile device of some sort to access his Home Assistant and the Tailscale client for the mobile device is power hungry.

    • @mrxmry3264
      @mrxmry3264 7 місяців тому

      @@jadamsnz exactly.

  • @patriknilsson4416
    @patriknilsson4416 7 місяців тому

    Great video! I have managed to do everything you demonstrate in the video. One thing I can't figure out how to accomplish though is how to pipe the inform-traffic from my remote sites, through the Cloudflare tunnel, to my locally installed CloudKey. If you can show how to configure that I will be forever loyal to your channel. The only holes that remains to be closed in my firewall are these holes for inform- and STUN-traffic from my remote sites.

    • @CrosstalkSolutions
      @CrosstalkSolutions  7 місяців тому +1

      UniFi inform traffic is HTTP over port 8080, so I would think if you match up the same rule (ie. Cloudflare FQDN forwards to HTTP 8080 on your local UniFi controller) that should work? I'm just not sure if UniFi devices will like having to go through HTTPS to get there...I've never tried it.

    • @patriknilsson4416
      @patriknilsson4416 7 місяців тому

      @@CrosstalkSolutions Well, that's what I thought as well. However, I can't get these messages through the tunnel. Everything else I send that way reach its destination, including reaching the CloudKey's web interface. But the inform traffic refuses. Isn't that a challenge for a the next video ;-)

  • @Movies4118
    @Movies4118 7 місяців тому

    Does CF tunnels allow for on-http/https traffic such a tcp/udp to be exposed via tunnels?

  • @ShermNE
    @ShermNE 7 місяців тому

    Can this method be a replacement for NGINx proxy manager? I would like to do this with Vaultwarden.

  • @LordHog
    @LordHog 7 місяців тому

    I was able to follow the instructions and the tunnel is working on my PiKVM. My problem is I am still able to go directly to the site without being prompted for one-time pin even after adding the Access Application

    • @LordHog
      @LordHog 7 місяців тому

      Argh, so frustrating. I have watched two other video which basically show the same info, but my configuration still doesn't work.

    • @CrosstalkSolutions
      @CrosstalkSolutions  7 місяців тому

      Double-check the Application rules - make sure you have the * in the hostname so that the application catches all sub-domains.

    • @LordHog
      @LordHog 7 місяців тому

      @@CrosstalkSolutions Funny, I just added a new "Application domain", but this time I left the "subdomain" blank. So now there are two two Application Domains. Both have the same domain, but one has an "*" for the subdomain and the other one is left blank for the subdomain. Now, when I go to the domain I see the "Get a login code emailed to you". I don't understand.

  • @cameronpalm4617
    @cameronpalm4617 7 місяців тому

    So if you go this route, does this make it super easy to pull let’s encrypt ssl carts for your homeland devices? Eg a synology?

    • @CrosstalkSolutions
      @CrosstalkSolutions  7 місяців тому

      Cloudflare creates the SSL certs for the domain that you add - no need for Let's Encrypt on the device locally...all traffic is valid SSL traffic. There is an argument to be made for not having control over the SSL cert though as I'm sure many in comments will bring up - that's a decision you'd have to weigh.

    • @cameronpalm4617
      @cameronpalm4617 7 місяців тому

      @@CrosstalkSolutions I figured remote ssl was handled via the tunnel, but my pet peeve is getting rid of ssl warning in local lan. It is a topic I’ve always hoped you would cover as my setup is similar to yours. But I don’t want to expose everything to the web. I’m also am having trouble getting through my gateway to my dream machine.
      So right now I’m tooling with setting up a “.internal” TLD and using unbound or nginx to redirect dns queries locally and issue my own carts.
      There is some discussion of using bind for it, but the few tutorials I’ve read have the bind server be your dhcp server as well, and I want to keep my dhcp through UniFi.

    • @romayojr
      @romayojr 7 місяців тому

      @@cameronpalm4617you could setup pihole for your local dns. that’s what i use with my homelab

  • @Cam.Klingon
    @Cam.Klingon 7 місяців тому

    I looked into your training, but it's expensive for what it is.

  • @gotelldonn
    @gotelldonn 7 місяців тому

    Where can I get that shirt? Have to have it!

  • @thecircusb0y1
    @thecircusb0y1 7 місяців тому +1

    Vim for days

  • @kevinoconnor6570
    @kevinoconnor6570 7 місяців тому

    Is this CG-NAT or do they use IPv6 to IPv4 translation?

  • @jnmanor
    @jnmanor 6 місяців тому

    What is the solution for SMB?

  • @htcmagic
    @htcmagic 7 місяців тому +1

    Self-Hosted ZeroTier all day and all night.. love CloudFlare but marry with zerotier. 😂😂😂

  • @Shamrock013
    @Shamrock013 7 місяців тому

    Not sure what I'm doing wrong.. Installed Cloudflared, Configured the Tunnel in the ZT Dash, it shows healthy, but when I try to access that environment, it drops. I'm just getting a 404, and it doesn't look like DNS is resolving. Is the CNAME supposed to resolve properly?

    • @CrosstalkSolutions
      @CrosstalkSolutions  7 місяців тому

      If you do it too quickly, sometimes the SSL cert hasn't been generated yet - give it a bit and try back later.

    • @Shamrock013
      @Shamrock013 7 місяців тому

      @@CrosstalkSolutions looks like Cloudflare was having a DNS propagation issue when I was attempting this. What timing on your video and CF's issue!

  • @jackipiegg
    @jackipiegg 7 місяців тому

    unless you're out of the loop, there's multiple n100 boards with 2.5g ethernet built it for the same price on amazon. Are you being paid by them or something.

    • @CrosstalkSolutions
      @CrosstalkSolutions  7 місяців тому +1

      Which one is your favorite model? List it here and I'll check it out.

  • @markbooth3066
    @markbooth3066 7 місяців тому

    If you think that coffee tastes good after being ruined in a blade grinder, you really should pick up a cheap burr grinder. You wouldn't believe how much better it would taste, even if you do ruin it further in a drip coffee maker. *8')

    • @CrosstalkSolutions
      @CrosstalkSolutions  7 місяців тому +3

      Pro tip - thanks!

    • @markbooth3066
      @markbooth3066 7 місяців тому

      I can't tell if that's sarcasm or not @@CrosstalkSolutions , but I'm glad you like your friends coffee, and if it's as good as you say, people who try it will keep going back for more, even if they do ruin it with blade grinders and drip coffee makers. *8')

    • @WakeandBrewCoffee
      @WakeandBrewCoffee 7 місяців тому

      ​@@markbooth3066Hey! The good thing about our coffee is it tastes great even if a blade grinder, Burr grinder, drip machine, pour over or French press is used to enjoy! Our beans are roasted the day your order ships and shipping is always free in the USA! Thanks for checking us out!

    • @aaronboggs5799
      @aaronboggs5799 6 місяців тому

      As a coffee enthusiast myself, I will caution that that rabbit hole can go deep and get quite expensive. For regular coffee, you can do quite well with a quality hand grinder and something like a V60 pour over or AeroPress.

  • @EuroPC4711
    @EuroPC4711 7 місяців тому

    Thanks for the great video. I followed your instructions and got my zima board working. But adding my Diskstation failed, telling me „Bad gateway“. I may have figured it out. HTTP works. But not https.

  • @ShinyTechThings
    @ShinyTechThings 7 місяців тому +1

    First!