<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.ampr.org/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=KN6DWI</id>
	<title>44Net Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.ampr.org/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=KN6DWI"/>
	<link rel="alternate" type="text/html" href="https://wiki.ampr.org/wiki/Special:Contributions/KN6DWI"/>
	<updated>2026-08-29T03:59:09Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.42.3</generator>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=CGNAT&amp;diff=2875</id>
		<title>CGNAT</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=CGNAT&amp;diff=2875"/>
		<updated>2026-08-29T00:26:06Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added diagram for CGNAT&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Carrier Grade Network Address Translation (CGNAT) is a form of [https://en.wikipedia.org/wiki/Network_address_translation Network Address Translation] (NAT) performed by internet service providers (ISPs). It involves placing many customers behind a single publicly routable IP address, and is a workaround to partially mitigate the impact of [https://en.wikipedia.org/wiki/IPv4_address_exhaustion IPv4 address exhaustion]. This can be an issue for people looking to self-host. In a non-CGNAT setup, your home router controls the NAT between your LAN and the WAN, and thus can forward ports from LAN devices to the WAN. In a CGNAT setup, there is a second layer of NAT performed by an ISP-owned router, which does not allow you to control port forwarding, and thus prevents self-hosting. This can be worked around by using a [[44Net_Connect/Single_Device_Tunnel|44Net Connect tunnel]] to expose a device directly to the internet using a 44Net IPv4 address. &lt;br /&gt;
&lt;br /&gt;
[[File:CGNAT_network.png]]&lt;br /&gt;
&lt;br /&gt;
== How to tell if you have CGNAT ==&lt;br /&gt;
The Internet Assigned Numbers Authority (IANA) has designated the IP range 100.64.0.0/10 for CGNAT usage. If your router is assigned an IP address in this range, your ISP is using CGNAT. This information can be found on your router&#039;s configuration page. Using websites such as whatismyip.net or similar will not tell you whether your ISP uses CGNAT, because the CGNAT IP range is not publicly routable. This means that your router&#039;s packets originating from a CGNAT IP are relabeled with a publicly routable IP by the ISP router before they exit the ISP&#039;s network, so internet services are not able to see the CGNAT IP. &lt;br /&gt;
&lt;br /&gt;
[[Category:Reference]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=File:CGNAT_network.png&amp;diff=2874</id>
		<title>File:CGNAT network.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=File:CGNAT_network.png&amp;diff=2874"/>
		<updated>2026-08-29T00:17:15Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: A diagram illustrating the network topology involved in CGNAT. Hosts behind the home router receive RFC1918 addresses, the home router receives a CGNAT address, and its traffic is translated to a public-facing address by the ISP address before being routed on the WAN.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
A diagram illustrating the network topology involved in CGNAT. Hosts behind the home router receive RFC1918 addresses, the home router receives a CGNAT address, and its traffic is translated to a public-facing address by the ISP address before being routed on the WAN.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=CGNAT&amp;diff=2873</id>
		<title>CGNAT</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=CGNAT&amp;diff=2873"/>
		<updated>2026-08-28T23:40:03Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added Wikipedia link to network address translation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Carrier Grade Network Address Translation (CGNAT) is a form of [https://en.wikipedia.org/wiki/Network_address_translation Network Address Translation] (NAT) performed by internet service providers (ISPs). It involves placing many customers behind a single publicly routable IP address, and is a workaround to partially mitigate the impact of [https://en.wikipedia.org/wiki/IPv4_address_exhaustion IPv4 address exhaustion]. This can be an issue for people looking to self-host. In a non-CGNAT setup, your home router controls the NAT between your LAN and the WAN, and thus can forward ports from LAN devices to the WAN. In a CGNAT setup, there is a second layer of NAT performed by an ISP-owned router, which does not allow you to control port forwarding, and thus prevents self-hosting. This can be worked around by using a [[44Net_Connect/Single_Device_Tunnel|44Net Connect tunnel]] to expose a device directly to the internet using a 44Net IPv4 address. &lt;br /&gt;
&lt;br /&gt;
== How to tell if you have CGNAT ==&lt;br /&gt;
The Internet Assigned Numbers Authority (IANA) has designated the IP range 100.64.0.0/10 for CGNAT usage. If your router is assigned an IP address in this range, your ISP is using CGNAT. This information can be found on your router&#039;s configuration page. Using websites such as whatismyip.net or similar will not tell you whether your ISP uses CGNAT, because the CGNAT IP range is not publicly routable. This means that your router&#039;s packets originating from a CGNAT IP are relabeled with a publicly routable IP by the ISP router before they exit the ISP&#039;s network, so internet services are not able to see the CGNAT IP. &lt;br /&gt;
&lt;br /&gt;
[[Category:Reference]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=CGNAT&amp;diff=2872</id>
		<title>CGNAT</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=CGNAT&amp;diff=2872"/>
		<updated>2026-08-28T23:39:12Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added link to single device tunnel page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Carrier Grade Network Address Translation (CGNAT) is a form of Network Address Translation (NAT) performed by internet service providers (ISPs). It involves placing many customers behind a single publicly routable IP address, and is a workaround to partially mitigate the impact of [https://en.wikipedia.org/wiki/IPv4_address_exhaustion IPv4 address exhaustion]. This can be an issue for people looking to self-host. In a non-CGNAT setup, your home router controls the NAT between your LAN and the WAN, and thus can forward ports from LAN devices to the WAN. In a CGNAT setup, there is a second layer of NAT performed by an ISP-owned router, which does not allow you to control port forwarding, and thus prevents self-hosting. This can be worked around by using a [[44Net_Connect/Single_Device_Tunnel|44Net Connect tunnel]] to expose a device directly to the internet using a 44Net IPv4 address. &lt;br /&gt;
&lt;br /&gt;
== How to tell if you have CGNAT ==&lt;br /&gt;
The Internet Assigned Numbers Authority (IANA) has designated the IP range 100.64.0.0/10 for CGNAT usage. If your router is assigned an IP address in this range, your ISP is using CGNAT. This information can be found on your router&#039;s configuration page. Using websites such as whatismyip.net or similar will not tell you whether your ISP uses CGNAT, because the CGNAT IP range is not publicly routable. This means that your router&#039;s packets originating from a CGNAT IP are relabeled with a publicly routable IP by the ISP router before they exit the ISP&#039;s network, so internet services are not able to see the CGNAT IP. &lt;br /&gt;
&lt;br /&gt;
[[Category:Reference]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=CGNAT&amp;diff=2871</id>
		<title>CGNAT</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=CGNAT&amp;diff=2871"/>
		<updated>2026-08-28T23:37:21Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Wrote how to tell if you have CGNAT&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Carrier Grade Network Address Translation (CGNAT) is a form of Network Address Translation (NAT) performed by internet service providers (ISPs). It involves placing many customers behind a single publicly routable IP address, and is a workaround to partially mitigate the impact of [https://en.wikipedia.org/wiki/IPv4_address_exhaustion IPv4 address exhaustion]. This can be an issue for people looking to self-host. In a non-CGNAT setup, your home router controls the NAT between your LAN and the WAN, and thus can forward ports from LAN devices to the WAN. In a CGNAT setup, there is a second layer of NAT performed by an ISP-owned router, which does not allow you to control port forwarding, and thus prevents self-hosting. This can be worked around by using a 44Net Connect tunnel to expose a device directly to the internet using a 44Net IPv4 address. &lt;br /&gt;
&lt;br /&gt;
== How to tell if you have CGNAT ==&lt;br /&gt;
The Internet Assigned Numbers Authority (IANA) has designated the IP range 100.64.0.0/10 for CGNAT usage. If your router is assigned an IP address in this range, your ISP is using CGNAT. This information can be found on your router&#039;s configuration page. Using websites such as whatismyip.net or similar will not tell you whether your ISP uses CGNAT, because the CGNAT IP range is not publicly routable. This means that your router&#039;s packets originating from a CGNAT IP are relabeled with a publicly routable IP by the ISP router before they exit the ISP&#039;s network, so internet services are not able to see the CGNAT IP. &lt;br /&gt;
&lt;br /&gt;
[[Category:Reference]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=CGNAT&amp;diff=2870</id>
		<title>CGNAT</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=CGNAT&amp;diff=2870"/>
		<updated>2026-08-28T22:50:35Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Created page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Carrier Grade Network Address Translation (CGNAT) is a form of Network Address Translation (NAT) performed by internet service providers (ISPs). It involves placing many customers behind a single publicly routable IP address, and is a workaround to partially mitigate the impact of [https://en.wikipedia.org/wiki/IPv4_address_exhaustion IPv4 address exhaustion]. &lt;br /&gt;
&lt;br /&gt;
[[Category:Reference]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Ipv6&amp;diff=2869</id>
		<title>Ipv6</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Ipv6&amp;diff=2869"/>
		<updated>2026-08-28T22:30:08Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Fixed typos&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;IPv6 is an experimental area for hams.  Here are a collection of notes and loose development in relation to that.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Back in 1998, Naoto Shimazaki, 7L4FEP described an idea for use of IPv6 over the amateur radio in a [http://www.qsl.net/k/kb9mwr//wapr/tcpip/Take_the_Next_Step_with_the_Next_Generation_Protocol.pdf document] he presented to a TAPR Digital Communication Conference:&lt;br /&gt;
&lt;br /&gt;
      &#039;&#039;IPv6 has huge address space and it supports real-time traffic. IPv6 realize new applications. For example, managing IPv4 address is not easy. It is possible to encode our &amp;quot;call sign&amp;quot; into IPv6 address. It enables us to managing IP address much easier.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
In 2012 a few members from the [http://www.wm7rc.org/ Mesa Amateur Radio Club] of Arizona took this to code and announced:&lt;br /&gt;
&lt;br /&gt;
   &#039;&#039;Club Members Jacques N1ZZH and Vinnie N1LQJ have developed a method of embedding a 2x5 (7 Character) callsign plus up to 185 nodes, plus 1 universal bit and three reserved bits in the 2nd octet, and a 16 bit amateur radio identifier at bit 24 of an IPv6 /64 Subnet address.  Tools for encoding and decoding amateur radio callsigns, up to 2x4 and 185 nodes, from IPv6 /64 subnets with Universal bit support and Amateur Radio Flag at the 24bit. Experimental RFC to IETF is being submitted for this proposed amateur standard.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
[http://sourceforge.net/projects/hamv6/ http://sourceforge.net/projects/hamv6/]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Kevin, N8VNR contacted [http://en.wikipedia.org/wiki/Internet_Assigned_Numbers_Authority IANA] in February 2011 hoping to get an allocation for the whole of Amateur Radio in the same vein as 44.0.0.0/8 and received this response:&lt;br /&gt;
&lt;br /&gt;
    &#039;&#039;Currently, the only policy we have been given for the allocation of global unicast IPv6 address space is for allocation to the RIRs. We do not have a policy allowing allocation to organisations like AMPRNet. For this reason, we would strongly suggest contacting an RIR for an IPv6 allocation&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Kevin says perhaps someone with some more influence could contact them and make our case. He mentions other options include:&lt;br /&gt;
&lt;br /&gt;
- Get an AMPRnet allocation in each of the [http://en.wikipedia.org/wiki/Regional_Internet_registry RIR] regions. This has the disadvantage of fragmenting the routing table (one of the things IPv6 was designed to mitigate). There&#039;s also no guarantee all of the RIRs would grant such a request.&lt;br /&gt;
&lt;br /&gt;
- Use [http://en.wikipedia.org/wiki/Unique_local_address ULA] space. This has the disadvantage of rendering the IPv6 AMPRnet non-globally routable. Then again, not much of the IPv4 AMPRnet is truly globally routed, with the gateway for the greater Internet being a single machine somewhere at UCSD.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
In 2015, Robert, N6DRC coded an encoding method for radio callsigns into numeric identifiers:&lt;br /&gt;
&lt;br /&gt;
  &#039;&#039;This document describes a mechanism for efficiently and reversibly encoding radio callsigns into compact numeric identifiers. It also defines two addressing mechanisms using this numeric encoding: A new adaptive link-layer addressing scheme (HAM-64) intended for use with new link-layer networking protocols like ARNGLL (Up to 12 characters), and an adaptation of EUI-48 and EUI-64 addresses (Up to 8 and 11 characters, respectively) intended for use with existing link layer protocols.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/darconeous/ham-addr/ https://github.com/darconeous/ham-addr/]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
At the 2016 Digital Communications Conference Brian, W9CR gave a presentation promoting the use and support of IPv6 within the amateur community:&lt;br /&gt;
&lt;br /&gt;
    &#039;&#039;A historical overview of legacy Internet protocols and their limitations will be presented here. IPv6 is the internationally recognized standard replacing these protocols. A short introduction to IPv6 and a case for its support in the amateur radio community is lacking. Finally an overview of the coming IPv6 deployment in HamWAN Tampa Bay is presented as a study of deployment for use by radio amateurs. Some background in IPv4 and Internet protocols is assumed.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[http://www.youtube.com/watch?v=VfOrF5pssCs Presentation on Youtube]&lt;br /&gt;
&lt;br /&gt;
[http://www.qsl.net/k/kb9mwr//wapr/tcpip/DCC2016-IPV6.pdf Abstract]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
In October 2017, Steve, VK5ASF posted to the 44Net mailing list a message titled Using IPv6 hosts for AMPRNET, which gave some details of some experiments he was performing to tunnel IPv4 inside IPv6:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Hi All,&lt;br /&gt;
&lt;br /&gt;
AMPRNET consists of IPv4 addresses 44.0.0.0/9 and 44.128.0.0/10. Tunnels used to support AMPRNET use IPv4 hosts as destinations for the tunnels, creating a &amp;quot;mesh-like&amp;quot; network.&lt;br /&gt;
&lt;br /&gt;
Bent OZ6BL and I have been experimenting with using an IPv6 host to carry AMPRNET traffic. The reason you might want to do this is that IPv6 addresses, particularly static addresses, can be much more readily available than with IPv4. Also, it&#039;s an interesting thing to try! We have working tunneled 44.0.0.0/9 and 44.128.0.0/10 connectivity between three different IPv6 hosts. However, there are some issues that arise, mainly due to the way in which AMPRNET functions.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Tunneling IPv4 inside IPv6 (ip4in6) is easily done and is well documented. In Linux, commands like these are all that&#039;s needed:&lt;br /&gt;
&lt;br /&gt;
/sbin/ip -6 tunnel add ip6tnl1 mode ip4ip6 \&lt;br /&gt;
    remote   2001:0DB8:112:35c::5630:6324  \&lt;br /&gt;
    local 2001:0DB8:1245:5200::ca0c:5902&lt;br /&gt;
/sbin/ip link set dev ip6tnl1 up&lt;br /&gt;
/sbin/ip  route replace  44.145.40.32/32  dev ip6tnl1  src 44.136.170.20&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It&#039;s very similar to how conventional AMPRNET is set up. However, the first issue is that with ip4in6 you cant (unlike ip4in4) leave the &amp;quot;remote&amp;quot; address empty, and then use routing commands to set the destination for different AMPRNET hosts (you&#039;d be trying to add an IPv4 route to an IPv6 gateway destination). So there&#039;s a scalability problem - you&#039;d need to set up a different tunnel device for each subnet you communicate with!&lt;br /&gt;
&lt;br /&gt;
The second issue is interoperability - if Alf, Bob and Charlie each only have IPv6 hosted AMPRNET, and Doug, Ed and Fred have only IPv4, then A, B, and C can communicate with themselves, as can D,E,F, but the two groups cannot interconnect from tunneled addresses. Of course, A,B and C could host IP4 tunnels as well, but that would somewhat defeat the purpose! Alternatively, one or more gateways (G) could host both IP4 and IP6 based tunnels, and route between the different type of network, a bit like this:&lt;br /&gt;
&lt;br /&gt;
A,B,C &amp;lt;----&amp;gt; G &amp;lt;----&amp;gt; D,E,F&lt;br /&gt;
&lt;br /&gt;
Could/should amprgw be configured to do this? Or maybe some hosts elsewhere do that function? But it adds complexity to the overall routing setup (and starts to become a more centralised network).&lt;br /&gt;
&lt;br /&gt;
The final issue is dissemination of the information - can the Portal be modified to support IPv6 hosts, or do we need another mechanism? Can encap.txt be used still? Would facilities such as ampr-ripd and ripd44 need modifications?&lt;br /&gt;
&lt;br /&gt;
So there&#039;s plenty to think about....&lt;br /&gt;
&lt;br /&gt;
Steve, VK5ASF&lt;br /&gt;
&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&#039;&#039;&#039;Conclusion&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
At this time we have come to the conclusion that there won&#039;t be a amprnet conversion to IPv6.  A new network will evolve.  It seems very unlikely hams will need their own allocation as the smallest ipv6 prefix assigned to a residential connection is a /64 subnet yielding 18,446,744,073,709,551,616 hosts.&lt;br /&gt;
&lt;br /&gt;
We just need a means of advertising the ham netblocks (possibly announced by RIP) and automatically configuring filtering (an iptables whitelist). A DNS to register the ham host in, etc.  An ideal situation would be a totally self-service DNS that uses LoTW (Logbook of the World) P12 certificates to authenticate hams, where they could then enter the IPv6 address(es) from their residential connection that are for ham use.&lt;br /&gt;
&lt;br /&gt;
[[Category:Reference]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2868</id>
		<title>Minecraft</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2868"/>
		<updated>2026-08-27T19:31:35Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Wrote troubleshooting steps for connection failures&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If you want to host a Minecraft server, but are behind {{Term|CGNAT}} or can&#039;t port forward for other reasons, 44Net Connect will let you make your server publicly accessible. &lt;br /&gt;
This will add latency, since connections are routed first through the 44Net Connect endpoint and then to your Minecraft server. This latency can be minimized by picking a 44Net Connect node&lt;br /&gt;
physically close to you and your players. &lt;br /&gt;
&lt;br /&gt;
Prerequisites:&lt;br /&gt;
* 44Net Portal account&lt;br /&gt;
* Verified callsign&lt;br /&gt;
* Configuration file from 44Net Connect&lt;br /&gt;
* Some sort of internet access&lt;br /&gt;
&lt;br /&gt;
== Step 1: Configure your firewall ==&lt;br /&gt;
Ensure you have a firewall program installed, and configure it so that only the desired ports are exposed. If you&#039;re using SSH, avoid exposing it to the internet unless you&#039;re willing to secure it against constant attack. Open port 25565 to TCP traffic to allow connections to your Minecraft server. For more information on firewall configuration, see [[Firewalling Basics]].&lt;br /&gt;
&lt;br /&gt;
== Step 2: Set up 44Net Connect tunnel ==&lt;br /&gt;
Next, set up a single device tunnel on the machine that will host your Minecraft server. Go to the [[https://wiki.ampr.org/wiki/44Net_Connect/Single_Device_Tunnel#Tutorials list of single device tunnel tutorials]] and follow the one for your operating system.&lt;br /&gt;
&lt;br /&gt;
== Step 3: Set up your Minecraft server ==&lt;br /&gt;
=== Download the server jar ===&lt;br /&gt;
Download a Minecraft server jar file [https://www.minecraft.net/en-us/download/server from the official Minecraft website], and put it in its own folder. When you run the jar file, other server files will be generated in this folder. The official website recommends starting it with the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;java -Xmx4G -Xms4G -jar &amp;lt;server jar name&amp;gt;.jar nogui&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The flag &amp;lt;code&amp;gt;-Xms4G&amp;lt;/code&amp;gt; sets the minimum memory allocation to 4 gigabytes, and the flag &amp;lt;code&amp;gt;-Xmx4G&amp;lt;/code&amp;gt; sets the maximum memory allocation to 4 gigabytes. This allocation should always be at least 1 gigabyte less than the amount of memory in your entire system, as the operating system needs some memory for itself. If you have exactly 4 GB of RAM, decrease the amount allocated in these flags. If you have more memory, you can set them higher, but it&#039;s not required. Setting them to be the same forces the memory allocation to be a fixed size, which improves performance by avoiding the need to request more memory in real time. &lt;br /&gt;
&lt;br /&gt;
=== Configure the server ===&lt;br /&gt;
The first time you start the server, it will tell you to agree to the End User License Agreement and create the &amp;lt;code&amp;gt;eula.txt&amp;lt;/code&amp;gt; file, then quit. Read the [https://www.minecraft.net/en-us/eula Minecraft End User License Agreement], then change the last line of the &amp;lt;code&amp;gt;eula.txt&amp;lt;/code&amp;gt; file from &amp;lt;code&amp;gt;eula=false&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;eula=true&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Since your server will be exposed to the internet, you may want to enable the whitelist to prevent random people from joining. To do this, edit the &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt; text file, and set &amp;lt;code&amp;gt;enforce-whitelist=true&amp;lt;/code&amp;gt; as well as &amp;lt;code&amp;gt;white-list=true&amp;lt;/code&amp;gt;. Each player who wants to join will need to be added to the whitelist by running the command &amp;lt;code&amp;gt;whitelist add &amp;lt;username&amp;gt;&amp;lt;/code&amp;gt; in the server console or in the client of a server operator. Add someone as an operator by running &amp;lt;code&amp;gt;op &amp;lt;username&amp;gt;&amp;lt;/code&amp;gt;, and remove them by running &amp;lt;code&amp;gt;deop &amp;lt;username&amp;gt;&amp;lt;/code&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
After configuring the server, start it up again using the command specified in the previous section. Test connectivity by joining via the address of your 44Net Connect tunnel, which is visible in the 44Net Connect tunnels page, or in the configuration file for your tunnel. &lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Can&#039;t connect to Minecraft server from either LAN or 44Net ===&lt;br /&gt;
Check that the port for your Minecraft server is opened in the firewall. If using a firewall such as &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt; that allows interfaces to be moved between zones, ensure the rules have been added to the zones containing your LAN and WireGuard interfaces. &lt;br /&gt;
&lt;br /&gt;
=== Minecraft server is only accessible over LAN, not 44Net ===&lt;br /&gt;
Ensure that your 44Net tunnel is up. On Linux systems, check its status with &amp;lt;code&amp;gt;systemctl status &amp;lt;name of systemd unit&amp;lt;/code&amp;gt;. The default &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt; unit name for a WireGuard tunnel started with &amp;lt;code&amp;gt;wg-quick&amp;lt;/code&amp;gt; is &amp;lt;code&amp;gt;wg-quick@wg0&amp;lt;/code&amp;gt;. Also check the 44Net Connect tunnels page to see if the endpoint thinks your tunnel is connected. The webpage can take a few minutes to update after the tunnel is enabled. If after a few minutes, the device and endpoint still disagree on whether your tunnel is up, you may have configuration issues. Make sure your IPv4 address in the configuration file is set to a /32, not a /24, as this can prevent the endpoint from updating the status page properly.&lt;br /&gt;
&lt;br /&gt;
If the tunnel is up and you&#039;re still having issues, double check your firewall configuration. &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt; users should make sure port 25565 is open in the zone(s) containing the LAN and WireGuard interfaces. (The recommended configuration is to place the WireGuard interface for your tunnel in a less permissive zone for security purposes.)  &lt;br /&gt;
 &lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2867</id>
		<title>Minecraft</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2867"/>
		<updated>2026-08-27T19:23:43Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Wrote Minecraft server setup section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If you want to host a Minecraft server, but are behind {{Term|CGNAT}} or can&#039;t port forward for other reasons, 44Net Connect will let you make your server publicly accessible. &lt;br /&gt;
This will add latency, since connections are routed first through the 44Net Connect endpoint and then to your Minecraft server. This latency can be minimized by picking a 44Net Connect node&lt;br /&gt;
physically close to you and your players. &lt;br /&gt;
&lt;br /&gt;
Prerequisites:&lt;br /&gt;
* 44Net Portal account&lt;br /&gt;
* Verified callsign&lt;br /&gt;
* Configuration file from 44Net Connect&lt;br /&gt;
* Some sort of internet access&lt;br /&gt;
&lt;br /&gt;
== Step 1: Configure your firewall ==&lt;br /&gt;
Ensure you have a firewall program installed, and configure it so that only the desired ports are exposed. If you&#039;re using SSH, avoid exposing it to the internet unless you&#039;re willing to secure it against constant attack. Open port 25565 to TCP traffic to allow connections to your Minecraft server. For more information on firewall configuration, see [[Firewalling Basics]].&lt;br /&gt;
&lt;br /&gt;
== Step 2: Set up 44Net Connect tunnel ==&lt;br /&gt;
Next, set up a single device tunnel on the machine that will host your Minecraft server. Go to the [[https://wiki.ampr.org/wiki/44Net_Connect/Single_Device_Tunnel#Tutorials list of single device tunnel tutorials]] and follow the one for your operating system.&lt;br /&gt;
&lt;br /&gt;
== Step 3: Set up your Minecraft server ==&lt;br /&gt;
=== Download the server jar ===&lt;br /&gt;
Download a Minecraft server jar file [https://www.minecraft.net/en-us/download/server from the official Minecraft website], and put it in its own folder. When you run the jar file, other server files will be generated in this folder. The official website recommends starting it with the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;java -Xmx4G -Xms4G -jar &amp;lt;server jar name&amp;gt;.jar nogui&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The flag &amp;lt;code&amp;gt;-Xms4G&amp;lt;/code&amp;gt; sets the minimum memory allocation to 4 gigabytes, and the flag &amp;lt;code&amp;gt;-Xmx4G&amp;lt;/code&amp;gt; sets the maximum memory allocation to 4 gigabytes. This allocation should always be at least 1 gigabyte less than the amount of memory in your entire system, as the operating system needs some memory for itself. If you have exactly 4 GB of RAM, decrease the amount allocated in these flags. If you have more memory, you can set them higher, but it&#039;s not required. Setting them to be the same forces the memory allocation to be a fixed size, which improves performance by avoiding the need to request more memory in real time. &lt;br /&gt;
&lt;br /&gt;
=== Configure the server ===&lt;br /&gt;
The first time you start the server, it will tell you to agree to the End User License Agreement and create the &amp;lt;code&amp;gt;eula.txt&amp;lt;/code&amp;gt; file, then quit. Read the [https://www.minecraft.net/en-us/eula Minecraft End User License Agreement], then change the last line of the &amp;lt;code&amp;gt;eula.txt&amp;lt;/code&amp;gt; file from &amp;lt;code&amp;gt;eula=false&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;eula=true&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Since your server will be exposed to the internet, you may want to enable the whitelist to prevent random people from joining. To do this, edit the &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt; text file, and set &amp;lt;code&amp;gt;enforce-whitelist=true&amp;lt;/code&amp;gt; as well as &amp;lt;code&amp;gt;white-list=true&amp;lt;/code&amp;gt;. Each player who wants to join will need to be added to the whitelist by running the command &amp;lt;code&amp;gt;whitelist add &amp;lt;username&amp;gt;&amp;lt;/code&amp;gt; in the server console or in the client of a server operator. Add someone as an operator by running &amp;lt;code&amp;gt;op &amp;lt;username&amp;gt;&amp;lt;/code&amp;gt;, and remove them by running &amp;lt;code&amp;gt;deop &amp;lt;username&amp;gt;&amp;lt;/code&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
After configuring the server, start it up again using the command specified in the previous section. Test connectivity by joining via the address of your 44Net Connect tunnel, which is visible in the 44Net Connect tunnels page, or in the configuration file for your tunnel. &lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2866</id>
		<title>Minecraft</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2866"/>
		<updated>2026-08-27T19:03:15Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Fix link formatting&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If you want to host a Minecraft server, but are behind {{Term|CGNAT}} or can&#039;t port forward for other reasons, 44Net Connect will let you make your server publicly accessible. &lt;br /&gt;
This will add latency, since connections are routed first through the 44Net Connect endpoint and then to your Minecraft server. This latency can be minimized by picking a 44Net Connect node&lt;br /&gt;
physically close to you and your players. &lt;br /&gt;
&lt;br /&gt;
Prerequisites:&lt;br /&gt;
* 44Net Portal account&lt;br /&gt;
* Verified callsign&lt;br /&gt;
* Configuration file from 44Net Connect&lt;br /&gt;
* Some sort of internet access&lt;br /&gt;
&lt;br /&gt;
== Step 1: Configure your firewall ==&lt;br /&gt;
Ensure you have a firewall program installed, and configure it so that only the desired ports are exposed. If you&#039;re using SSH, avoid exposing it to the internet unless you&#039;re willing to secure it against constant attack. Open port 25565 to TCP traffic to allow connections to your Minecraft server. For more information on firewall configuration, see [[Firewalling Basics]].&lt;br /&gt;
&lt;br /&gt;
== Step 2: Set up 44Net Connect tunnel ==&lt;br /&gt;
Next, set up a single device tunnel on the machine that will host your Minecraft server. Go to the [[https://wiki.ampr.org/wiki/44Net_Connect/Single_Device_Tunnel#Tutorials list of single device tunnel tutorials]] and follow the one for your operating system.&lt;br /&gt;
&lt;br /&gt;
== Step 3: Set up your Minecraft server ==&lt;br /&gt;
Download a Minecraft server jar file [https://www.minecraft.net/en-us/download/server from the official Minecraft website].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2865</id>
		<title>Minecraft</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2865"/>
		<updated>2026-08-27T19:02:43Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Direct people to the list of OS-specific tutorials&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If you want to host a Minecraft server, but are behind {{Term|CGNAT}} or can&#039;t port forward for other reasons, 44Net Connect will let you make your server publicly accessible. &lt;br /&gt;
This will add latency, since connections are routed first through the 44Net Connect endpoint and then to your Minecraft server. This latency can be minimized by picking a 44Net Connect node&lt;br /&gt;
physically close to you and your players. &lt;br /&gt;
&lt;br /&gt;
Prerequisites:&lt;br /&gt;
* 44Net Portal account&lt;br /&gt;
* Verified callsign&lt;br /&gt;
* Configuration file from 44Net Connect&lt;br /&gt;
* Some sort of internet access&lt;br /&gt;
&lt;br /&gt;
== Step 1: Configure your firewall ==&lt;br /&gt;
Ensure you have a firewall program installed, and configure it so that only the desired ports are exposed. If you&#039;re using SSH, avoid exposing it to the internet unless you&#039;re willing to secure it against constant attack. Open port 25565 to TCP traffic to allow connections to your Minecraft server. For more information on firewall configuration, see [[Firewalling Basics]].&lt;br /&gt;
&lt;br /&gt;
== Step 2: Set up 44Net Connect tunnel ==&lt;br /&gt;
Next, set up a single device tunnel on the machine that will host your Minecraft server. Go to the [list of single device tunnel tutorials](https://wiki.ampr.org/wiki/44Net_Connect/Single_Device_Tunnel#Tutorials) and follow the one for your operating system.&lt;br /&gt;
&lt;br /&gt;
== Step 3: Set up your Minecraft server ==&lt;br /&gt;
Download a Minecraft server jar file [https://www.minecraft.net/en-us/download/server from the official Minecraft website].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2864</id>
		<title>Minecraft</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2864"/>
		<updated>2026-08-27T18:31:30Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Tell people to open port 25565&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If you want to host a Minecraft server, but are behind {{Term|CGNAT}} or can&#039;t port forward for other reasons, 44Net Connect will let you make your server publicly accessible. &lt;br /&gt;
This will add latency, since connections are routed first through the 44Net Connect endpoint and then to your Minecraft server. This latency can be minimized by picking a 44Net Connect node&lt;br /&gt;
physically close to you and your players. &lt;br /&gt;
&lt;br /&gt;
Prerequisites:&lt;br /&gt;
* 44Net Portal account&lt;br /&gt;
* Verified callsign&lt;br /&gt;
* Configuration file from 44Net Connect&lt;br /&gt;
* Some sort of internet access&lt;br /&gt;
&lt;br /&gt;
== Step 1: Configure your firewall ==&lt;br /&gt;
Ensure you have a firewall program installed, and configure it so that only the desired ports are exposed. If you&#039;re using SSH, avoid exposing it to the internet unless you&#039;re willing to secure it against constant attack. Open port 25565 to TCP traffic to allow connections to your Minecraft server. For more information on firewall configuration, see [[Firewalling Basics]].&lt;br /&gt;
&lt;br /&gt;
== Step 2: Set up 44Net Connect tunnel ==&lt;br /&gt;
&lt;br /&gt;
== Step 3: Set up your Minecraft server ==&lt;br /&gt;
Download a Minecraft server jar file [https://www.minecraft.net/en-us/download/server from the official Minecraft website].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2863</id>
		<title>Minecraft</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2863"/>
		<updated>2026-08-27T18:14:45Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added link to firewalling basics&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If you want to host a Minecraft server, but are behind {{Term|CGNAT}} or can&#039;t port forward for other reasons, 44Net Connect will let you make your server publicly accessible. &lt;br /&gt;
This will add latency, since connections are routed first through the 44Net Connect endpoint and then to your Minecraft server. This latency can be minimized by picking a 44Net Connect node&lt;br /&gt;
physically close to you and your players. &lt;br /&gt;
&lt;br /&gt;
Prerequisites:&lt;br /&gt;
* 44Net Portal account&lt;br /&gt;
* Verified callsign&lt;br /&gt;
* Configuration file from 44Net Connect&lt;br /&gt;
* Some sort of internet access&lt;br /&gt;
&lt;br /&gt;
== Step 1: Configure your firewall ==&lt;br /&gt;
Ensure you have a firewall program installed, and configure it so that only the desired ports are exposed. If you&#039;re using SSH, avoid exposing it to the internet unless you&#039;re willing to secure it against constant attack. For more information on firewall configuration, see [[Firewalling Basics]].&lt;br /&gt;
&lt;br /&gt;
== Step 2: Set up 44Net Connect tunnel ==&lt;br /&gt;
&lt;br /&gt;
== Step 3: Set up your Minecraft server ==&lt;br /&gt;
Download a Minecraft server jar file [https://www.minecraft.net/en-us/download/server from the official Minecraft website].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2862</id>
		<title>Minecraft</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2862"/>
		<updated>2026-08-27T18:10:34Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Created categories&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If you want to host a Minecraft server, but are behind {{Term|CGNAT}} or can&#039;t port forward for other reasons, 44Net Connect will let you make your server publicly accessible. &lt;br /&gt;
This will add latency, since connections are routed first through the 44Net Connect endpoint and then to your Minecraft server. This latency can be minimized by picking a 44Net Connect node&lt;br /&gt;
physically close to you and your players. &lt;br /&gt;
&lt;br /&gt;
Prerequisites:&lt;br /&gt;
* 44Net Portal account&lt;br /&gt;
* Verified callsign&lt;br /&gt;
* Configuration file from 44Net Connect&lt;br /&gt;
* Some sort of internet access&lt;br /&gt;
&lt;br /&gt;
== Step 1: Configure your firewall ==&lt;br /&gt;
Ensure you have a firewall program installed, and configure it so that only the desired ports are exposed. If you&#039;re using SSH, avoid exposing it to the internet unless you&#039;re willing to secure it against constant attack. &lt;br /&gt;
&lt;br /&gt;
== Step 2: Set up 44Net Connect tunnel ==&lt;br /&gt;
&lt;br /&gt;
== Step 3: Set up your Minecraft server ==&lt;br /&gt;
Download a Minecraft server jar file [https://www.minecraft.net/en-us/download/server from the official Minecraft website].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2861</id>
		<title>Minecraft</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2861"/>
		<updated>2026-08-27T00:55:54Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Discussed latency penalty&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If you want to host a Minecraft server, but are behind {{Term|CGNAT}} or can&#039;t port forward for other reasons, 44Net Connect will let you make your server publicly accessible. &lt;br /&gt;
This will add latency, since connections are routed first through the 44Net Connect endpoint and then to your Minecraft server. This latency can be minimized by picking a 44Net Connect node&lt;br /&gt;
physically close to you and your players. &lt;br /&gt;
&lt;br /&gt;
Prerequisites:&lt;br /&gt;
* 44Net Portal account&lt;br /&gt;
* Verified callsign&lt;br /&gt;
* Configuration file from 44Net Connect&lt;br /&gt;
* Some sort of internet access&lt;br /&gt;
&lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2860</id>
		<title>Minecraft</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Minecraft&amp;diff=2860"/>
		<updated>2026-08-27T00:18:33Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Created page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If you want to host a Minecraft server, but are behind {{Term|CGNAT}} or can&#039;t port forward for other reasons, 44Net Connect will let you make your server publicly accessible. &lt;br /&gt;
&lt;br /&gt;
Prerequisites:&lt;br /&gt;
* 44Net Portal account&lt;br /&gt;
* Verified callsign&lt;br /&gt;
* Configuration file from 44Net Connect&lt;br /&gt;
* Some sort of internet access&lt;br /&gt;
&lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2859</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2859"/>
		<updated>2026-08-26T22:39:41Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added category use cases&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run Certbot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run Certbot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run Certbot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up Certbot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. &lt;br /&gt;
&lt;br /&gt;
[[File:Home_Assistant_TLS_Settings.png|500px]]&lt;br /&gt;
&lt;br /&gt;
Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and Certbot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up Certbot yourself.&lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Before running the &amp;lt;code&amp;gt;certbot&amp;lt;/code&amp;gt; command, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. &lt;br /&gt;
&lt;br /&gt;
[[File:Home_Assistant_TLS_Settings.png|500px]]&lt;br /&gt;
&lt;br /&gt;
Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Home Assistant is not accessible from the 44Net IP ===&lt;br /&gt;
* Ensure you are accessing the correct port for Home Assistant. If you don&#039;t specify a port in your web browser, it will attempt to use port 80 (HTTP) or port 443 (HTTPS) by default, but the default Home Assistant port is 8123. &lt;br /&gt;
* Verify that your firewall configuration has port 8123 (or whatever alternate port you&#039;re using) open. &lt;br /&gt;
* Verify that your 44Net Connect tunnel is up using the [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page].&lt;br /&gt;
&lt;br /&gt;
=== Certificate authority fails to download challenge from the Certbot temporary web server ===&lt;br /&gt;
This typically happens if your 44Net tunnel is not up, or if your firewall is not configured to allow inbound connections on port 80. Try the following troubleshooting steps&lt;br /&gt;
* Use &amp;lt;code&amp;gt;ifconfig&amp;lt;/code&amp;gt; to verify that your 44Net Connect tunnel is up. You should see a WireGuard interface with your 44Net IP address. &lt;br /&gt;
* Visit [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page] and ensure your tunnel shows up as being connected. &lt;br /&gt;
* Check your firewall configuration and make sure port 80 is open. If you have recently changed your firewall configuration, reload the firewall. &lt;br /&gt;
* If running Certbot inside your Home Assistant docker container, make sure the docker container has its port 80 mapped to the host&#039;s port 80.&lt;br /&gt;
&lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=44Net_Connect/Quick_Start/Fedora&amp;diff=2858</id>
		<title>44Net Connect/Quick Start/Fedora</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=44Net_Connect/Quick_Start/Fedora&amp;diff=2858"/>
		<updated>2026-08-20T17:42:58Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Updated automatic start instructions to use automatically generated systemd unit&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== What you need ===&lt;br /&gt;
&lt;br /&gt;
* A 44Net Portal account&lt;br /&gt;
* A verified amateur radio callsign&lt;br /&gt;
* A configuration file from 44Net Connect&lt;br /&gt;
* A device running Fedora Linux&lt;br /&gt;
* Some sort of Internet access&lt;br /&gt;
&lt;br /&gt;
If you haven&#039;t set up your Portal account or verified your callsign yet, see [[GetStarted|44Net: Get Started]] for instructions. If you haven&#039;t obtained a WireGuard tunnel configuration file from 44Net Connect, get one using the [[44Net_Connect/Quick_Start|the 44Net Connect quick start guide]]&lt;br /&gt;
&lt;br /&gt;
== Install Dependencies ==&lt;br /&gt;
=== Step 1: Ensure your OS is up to date ===&lt;br /&gt;
Update your system packages using either your GUI tool of choice, or by opening&lt;br /&gt;
a terminal and running &amp;lt;code&amp;gt;sudo dnf update &amp;amp;&amp;amp; sudo dnf upgrade&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Step 2: Install wireguard ===&lt;br /&gt;
Run &amp;lt;code&amp;gt;sudo dnf install wireguard-tools&amp;lt;/code&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
=== Step 3: Verify that systemd-resolved is enabled ===&lt;br /&gt;
&amp;lt;code&amp;gt;systemd-resolved&amp;lt;/code&amp;gt; comes installed by default on Fedora. Ensure that it&#039;s running by executing &amp;lt;code&amp;gt;systemctl status systemd-resolved&amp;lt;/code&amp;gt; in your terminal. If the unit is running without issues, there will be a green circle at the top left. The second line, beginning with &amp;quot;Loaded,&amp;quot; should indicate that the unit is enabled. If it&#039;s not, run &amp;lt;code&amp;gt;systemctl enable systemd-resolved&amp;lt;/code&amp;gt; to enable the unit. This will ensure that the unit starts automatically when your Fedora machine boots from now on. &lt;br /&gt;
&lt;br /&gt;
The third line, beginning with &amp;quot;Active,&amp;quot; should indicate that the unit is active (running). &lt;br /&gt;
If it&#039;s not, run &amp;lt;code&amp;gt;systemctl start systemd-resolved&amp;lt;/code&amp;gt; to start the unit. This will ensure that the unit is currently running.&lt;br /&gt;
&lt;br /&gt;
== Configure your WireGuard client ==&lt;br /&gt;
* Create a new file for your WireGuard configuration in &amp;lt;code&amp;gt;/etc/wireguard/&amp;lt;/code&amp;gt;, for example &amp;lt;code&amp;gt;/etc/wireguard/wg0.conf&amp;lt;/code&amp;gt;.&lt;br /&gt;
* You can name this file however you want, but this file name will become the name of your WireGuard interface.&lt;br /&gt;
* Paste the configuration text in from 44Net Connect, or if you prefer to use the file that was emailed to you, upload that one. &lt;br /&gt;
&lt;br /&gt;
[[File:wireguard_tunnel_config.png|500px]]&lt;br /&gt;
&lt;br /&gt;
The first time you create your tunnel, the private key will be present in the config for you to copy. Every subsequent time you view the config in the portal, the private key will not be shown. Saving a backup of the private key in a secure place is recommended.&lt;br /&gt;
&lt;br /&gt;
After creating your config file, set its permissions so that only the owner has read or write permissions. This can be done with the command &amp;lt;code&amp;gt;sudo chmod 600 /etc/wireguard/wg0.conf&amp;lt;/code&amp;gt;. (Replace &amp;lt;code&amp;gt;wg0&amp;lt;/code&amp;gt; with the name of your file.)&lt;br /&gt;
&lt;br /&gt;
== Activate and connect == &lt;br /&gt;
=== Activate your tunnel ===&lt;br /&gt;
Run the command &amp;lt;code&amp;gt;wg-quick up wg0&amp;lt;/code&amp;gt; (replace &amp;lt;code&amp;gt;wg0&amp;lt;/code&amp;gt; with the name of your configuration file if different).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Confirm Connection in the Connect dashboard ===&lt;br /&gt;
* Your tunnel status should show as &amp;quot;Active&amp;quot; with a green indicator.&lt;br /&gt;
[[File:wireguard_tunnel_connected.png|500px]]&lt;br /&gt;
* The &amp;lt;code&amp;gt;Endpoint&amp;lt;/code&amp;gt; field should show the IP address your device is connecting from, as well as the port it&#039;s using. This is not the 44Net IP from which your device is publicly accessible.&lt;br /&gt;
&lt;br /&gt;
=== Other Ways to Confirm Connection === &lt;br /&gt;
* Visit https://connect.44net.cloud/myip in your browser, or query it from the command line using &amp;lt;code&amp;gt;curl https://connect.44net.cloud/myip&amp;lt;/code&amp;gt;&lt;br /&gt;
* Use &amp;lt;code&amp;gt;traceroute&amp;lt;/code&amp;gt; to inspect the path between you and some other device, such as &amp;lt;code&amp;gt;traceroute 1.1.1.1&amp;lt;/code&amp;gt;. When the tunnel is working, the first hop will be through a 44Net gateway, so its IP will be in the &amp;lt;code&amp;gt;44.0.0.0/9&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;44.128.0.0/10&amp;lt;/code&amp;gt; subnet.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Starting the Tunnel Automatically ==&lt;br /&gt;
* On Linux distributions that use &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt;, using the &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt; unit automatically generated by &amp;lt;code&amp;gt;wg-quick&amp;lt;/code&amp;gt; is the recommended way to automatically start the tunnel. These are automatically created for any config file in &amp;lt;code&amp;gt;/etc/wireguard&amp;lt;/code&amp;gt;. &lt;br /&gt;
* The automatically created unit is called &amp;lt;code&amp;gt;wg-quick@&amp;lt;config file name&amp;gt;.service&amp;lt;/code&amp;gt;, so a file &amp;lt;code&amp;gt;/etc/wireguard/wg0.conf&amp;lt;/code&amp;gt; would make &amp;lt;code&amp;gt;wg-quick@wg0.service&amp;lt;/code&amp;gt;. &lt;br /&gt;
* Enable and start the service by running &amp;lt;code&amp;gt;sudo systemctl enable --now wg-quick@&amp;lt;config file&amp;gt;&amp;lt;/code&amp;gt;, where &amp;lt;code&amp;gt;&amp;lt;config file&amp;gt;&amp;lt;/code&amp;gt; is replaced with the name of your config file without the extension.&lt;br /&gt;
* Verify that the service has started by running &amp;lt;code&amp;gt;systemctl status wg-quick@&amp;lt;config file&amp;gt;&amp;lt;/code&amp;gt; and checking that it says enabled and active, the same way we previously checked that systemd-resolved was working. &lt;br /&gt;
&lt;br /&gt;
[[Category:Tutorial]]&lt;br /&gt;
[[Category:How-To]]&lt;br /&gt;
[[Category:Participation Methods]]&lt;br /&gt;
[[Category:44Net Connect]]&lt;br /&gt;
[[Category:Getting Started]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=44Net_Connect/Quick_Start/Debian_based_distributions&amp;diff=2856</id>
		<title>44Net Connect/Quick Start/Debian based distributions</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=44Net_Connect/Quick_Start/Debian_based_distributions&amp;diff=2856"/>
		<updated>2026-08-20T17:32:32Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Changed autostart instructions to use systemd unit automatically generated by wg-quick&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;&lt;br /&gt;
&amp;lt;div class=&amp;quot;toclimit-3&amp;quot;&amp;gt;&lt;br /&gt;
__TOC__&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
{{DISPLAYTITLE:44Net Connect Quick Start: Debian-based distributions}}&lt;br /&gt;
&lt;br /&gt;
=== What you need ===&lt;br /&gt;
&lt;br /&gt;
* A 44Net Portal account&lt;br /&gt;
* A verified amateur radio callsign&lt;br /&gt;
* A configuration file from 44Net Connect&lt;br /&gt;
* A machine running a Debian-based Linux distribution&lt;br /&gt;
* Some sort of Internet access&lt;br /&gt;
&lt;br /&gt;
If you haven&#039;t set up your Portal account or verified your callsign yet, see [[GetStarted|44Net: Get Started]] for instructions. If you haven&#039;t obtained a WireGuard tunnel configuration file from 44Net Connect, get one using the [[44Net_Connect/Quick_Start|the 44Net Connect quick start guide]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Install Dependencies ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1: Ensure your OS is up to date ===&lt;br /&gt;
Open a terminal and run &amp;lt;code&amp;gt;sudo apt-get update&amp;lt;/code&amp;gt;, then &amp;lt;code&amp;gt;sudo apt-get upgrade&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Step 2: Install wireguard and systemd-resolved ===&lt;br /&gt;
Run &amp;lt;code&amp;gt;sudo apt-get install wireguard systemd-resolved&amp;lt;/code&amp;gt;, then restart your Raspberry Pi. Restarting is required for &amp;lt;code&amp;gt;systemd-resolved&amp;lt;/code&amp;gt; to function. &lt;br /&gt;
&lt;br /&gt;
=== Step 3: Verify that systemd-resolved is enabled ===&lt;br /&gt;
Run &amp;lt;code&amp;gt;systemctl status systemd-resolved&amp;lt;/code&amp;gt;. If the unit is running without issues, there will be a green asterisk or circle at the top left. The second line, beginning with &amp;quot;Loaded,&amp;quot; should indicate that the unit is enabled. If it&#039;s not, run &amp;lt;code&amp;gt;systemctl enable systemd-resolved&amp;lt;/code&amp;gt; to enable the unit. This will ensure that the unit starts automatically when your Raspberry Pi boots from now on. &lt;br /&gt;
&lt;br /&gt;
The third line, beginning with &amp;quot;Active,&amp;quot; should indicate that the unit is active (running). &lt;br /&gt;
If it&#039;s not, run &amp;lt;code&amp;gt;systemctl start systemd-resolved&amp;lt;/code&amp;gt; to start the unit. This will ensure that the unit is currently running.&lt;br /&gt;
&lt;br /&gt;
== Configure your WireGuard client ==&lt;br /&gt;
* Create a new file for your WireGuard configuration in &amp;lt;code&amp;gt;/etc/wireguard/&amp;lt;/code&amp;gt;, for example &amp;lt;code&amp;gt;/etc/wireguard/wg0.conf&amp;lt;/code&amp;gt;.&lt;br /&gt;
* You can name this file however you want, but this file name will become the name of your WireGuard interface.&lt;br /&gt;
* Paste the configuration text in from 44Net Connect, or if you prefer to use the file that was emailed to you, upload that one. &lt;br /&gt;
&lt;br /&gt;
[[File:wireguard_tunnel_config.png|500px]]&lt;br /&gt;
&lt;br /&gt;
The first time you create your tunnel, the private key will be present in the config for you to copy. Every subsequent time you view the config in the portal, the private key will not be shown. Saving a backup of the private key in a secure place is recommended.&lt;br /&gt;
&lt;br /&gt;
After creating your config file, set its permissions so that only the owner has read or write permissions. This can be done with the command &amp;lt;code&amp;gt;sudo chmod 600 /etc/wireguard/wg0.conf&amp;lt;/code&amp;gt;. (Replace &amp;lt;code&amp;gt;wg0&amp;lt;/code&amp;gt; with the name of your file.)&lt;br /&gt;
&lt;br /&gt;
== Activate and connect == &lt;br /&gt;
=== Activate your tunnel ===&lt;br /&gt;
* Run the command &amp;lt;code&amp;gt;wg-quick up wg0&amp;lt;/code&amp;gt; (replace &amp;lt;code&amp;gt;wg0&amp;lt;/code&amp;gt; with the name of your configuration file if different).&lt;br /&gt;
* If at this step WireGuard reports the error &amp;lt;code&amp;gt;Failed to activate service &#039;org.freedesktop.resolve1&#039;: timed out&amp;lt;/code&amp;gt;, you may have forgotten to restart your computer after installing &amp;lt;code&amp;gt;systemd-resolved&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Confirm Connection in the Connect dashboard ===&lt;br /&gt;
* Your tunnel status should show as &amp;quot;Active&amp;quot; with a green indicator.&lt;br /&gt;
[[File:wireguard_tunnel_connected.png|500px]]&lt;br /&gt;
* The &amp;lt;code&amp;gt;Endpoint&amp;lt;/code&amp;gt; field should show the IP address your device is connecting from, as well as the port it&#039;s using. This is not the 44Net IP from which your device is publicly accessible.&lt;br /&gt;
&lt;br /&gt;
=== Other Ways to Confirm Connection === &lt;br /&gt;
* Visit https://connect.44net.cloud/myip in your browser, or query it from the command line using &amp;lt;code&amp;gt;curl https://connect.44net.cloud/myip&amp;lt;/code&amp;gt;&lt;br /&gt;
* Use &amp;lt;code&amp;gt;traceroute&amp;lt;/code&amp;gt; to inspect the path between you and some other device, such as &amp;lt;code&amp;gt;traceroute 1.1.1.1&amp;lt;/code&amp;gt;. When the tunnel is working, the first hop will be through a 44Net gateway, so its IP will be in the &amp;lt;code&amp;gt;44.0.0.0/9&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;44.128.0.0/10&amp;lt;/code&amp;gt; subnet.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Starting the Tunnel Automatically ==&lt;br /&gt;
* On Linux distributions that use &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt;, using the &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt; unit automatically generated by &amp;lt;code&amp;gt;wg-quick&amp;lt;/code&amp;gt; is the recommended way to automatically start the tunnel. These are automatically created for any config file in &amp;lt;code&amp;gt;/etc/wireguard&amp;lt;/code&amp;gt;. &lt;br /&gt;
* The automatically created unit is called &amp;lt;code&amp;gt;wg-quick@&amp;lt;config file name&amp;gt;.service&amp;lt;/code&amp;gt;, so a file &amp;lt;code&amp;gt;/etc/wireguard/wg0.conf&amp;lt;/code&amp;gt; would make &amp;lt;code&amp;gt;wg-quick@wg0.service&amp;lt;/code&amp;gt;. &lt;br /&gt;
* Enable and start the service by running &amp;lt;code&amp;gt;sudo systemctl enable --now wg-quick@&amp;lt;config file&amp;gt;&amp;lt;/code&amp;gt;, where &amp;lt;code&amp;gt;&amp;lt;config file&amp;gt;&amp;lt;/code&amp;gt; is replaced with the name of your config file without the extension.&lt;br /&gt;
* Verify that the service has started by running &amp;lt;code&amp;gt;systemctl status wg-quick@&amp;lt;config file&amp;gt;&amp;lt;/code&amp;gt; and checking that it says enabled and active, the same way we previously checked that systemd-resolved was working. &lt;br /&gt;
&lt;br /&gt;
[[Category:Tutorial]]&lt;br /&gt;
[[Category:How-To]]&lt;br /&gt;
[[Category:Participation Methods]]&lt;br /&gt;
[[Category:44Net Connect]]&lt;br /&gt;
[[Category:Getting Started]]&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2854</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2854"/>
		<updated>2026-08-19T22:47:42Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added image of TLS configuration&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run Certbot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run Certbot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run Certbot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up Certbot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. &lt;br /&gt;
&lt;br /&gt;
[[File:Home_Assistant_TLS_Settings.png|500px]]&lt;br /&gt;
&lt;br /&gt;
Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and Certbot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up Certbot yourself.&lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Before running the &amp;lt;code&amp;gt;certbot&amp;lt;/code&amp;gt; command, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. &lt;br /&gt;
&lt;br /&gt;
[[File:Home_Assistant_TLS_Settings.png|500px]]&lt;br /&gt;
&lt;br /&gt;
Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Home Assistant is not accessible from the 44Net IP ===&lt;br /&gt;
* Ensure you are accessing the correct port for Home Assistant. If you don&#039;t specify a port in your web browser, it will attempt to use port 80 (HTTP) or port 443 (HTTPS) by default, but the default Home Assistant port is 8123. &lt;br /&gt;
* Verify that your firewall configuration has port 8123 (or whatever alternate port you&#039;re using) open. &lt;br /&gt;
* Verify that your 44Net Connect tunnel is up using the [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page].&lt;br /&gt;
&lt;br /&gt;
=== Certificate authority fails to download challenge from the Certbot temporary web server ===&lt;br /&gt;
This typically happens if your 44Net tunnel is not up, or if your firewall is not configured to allow inbound connections on port 80. Try the following troubleshooting steps&lt;br /&gt;
* Use &amp;lt;code&amp;gt;ifconfig&amp;lt;/code&amp;gt; to verify that your 44Net Connect tunnel is up. You should see a WireGuard interface with your 44Net IP address. &lt;br /&gt;
* Visit [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page] and ensure your tunnel shows up as being connected. &lt;br /&gt;
* Check your firewall configuration and make sure port 80 is open. If you have recently changed your firewall configuration, reload the firewall. &lt;br /&gt;
* If running Certbot inside your Home Assistant docker container, make sure the docker container has its port 80 mapped to the host&#039;s port 80.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2853</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2853"/>
		<updated>2026-08-19T22:46:51Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added image of TLS configuration&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run Certbot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run Certbot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run Certbot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up Certbot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and Certbot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up Certbot yourself.&lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Before running the &amp;lt;code&amp;gt;certbot&amp;lt;/code&amp;gt; command, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. &lt;br /&gt;
&lt;br /&gt;
[[File:Home_Assistant_TLS_Settings.png|500px]]&lt;br /&gt;
&lt;br /&gt;
Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Home Assistant is not accessible from the 44Net IP ===&lt;br /&gt;
* Ensure you are accessing the correct port for Home Assistant. If you don&#039;t specify a port in your web browser, it will attempt to use port 80 (HTTP) or port 443 (HTTPS) by default, but the default Home Assistant port is 8123. &lt;br /&gt;
* Verify that your firewall configuration has port 8123 (or whatever alternate port you&#039;re using) open. &lt;br /&gt;
* Verify that your 44Net Connect tunnel is up using the [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page].&lt;br /&gt;
&lt;br /&gt;
=== Certificate authority fails to download challenge from the Certbot temporary web server ===&lt;br /&gt;
This typically happens if your 44Net tunnel is not up, or if your firewall is not configured to allow inbound connections on port 80. Try the following troubleshooting steps&lt;br /&gt;
* Use &amp;lt;code&amp;gt;ifconfig&amp;lt;/code&amp;gt; to verify that your 44Net Connect tunnel is up. You should see a WireGuard interface with your 44Net IP address. &lt;br /&gt;
* Visit [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page] and ensure your tunnel shows up as being connected. &lt;br /&gt;
* Check your firewall configuration and make sure port 80 is open. If you have recently changed your firewall configuration, reload the firewall. &lt;br /&gt;
* If running Certbot inside your Home Assistant docker container, make sure the docker container has its port 80 mapped to the host&#039;s port 80.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=File:Home_Assistant_TLS_Settings.png&amp;diff=2852</id>
		<title>File:Home Assistant TLS Settings.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=File:Home_Assistant_TLS_Settings.png&amp;diff=2852"/>
		<updated>2026-08-19T22:29:15Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: A screenshot of the HTTP server section in Network Settings for Home Assistant.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
A screenshot of the HTTP server section in Network Settings for Home Assistant.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2851</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2851"/>
		<updated>2026-08-19T18:45:09Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Formatting fix&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run Certbot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run Certbot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run Certbot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up Certbot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and Certbot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up Certbot yourself.&lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Before running the &amp;lt;code&amp;gt;certbot&amp;lt;/code&amp;gt; command, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Home Assistant is not accessible from the 44Net IP ===&lt;br /&gt;
* Ensure you are accessing the correct port for Home Assistant. If you don&#039;t specify a port in your web browser, it will attempt to use port 80 (HTTP) or port 443 (HTTPS) by default, but the default Home Assistant port is 8123. &lt;br /&gt;
* Verify that your firewall configuration has port 8123 (or whatever alternate port you&#039;re using) open. &lt;br /&gt;
* Verify that your 44Net Connect tunnel is up using the [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page].&lt;br /&gt;
&lt;br /&gt;
=== Certificate authority fails to download challenge from the Certbot temporary web server ===&lt;br /&gt;
This typically happens if your 44Net tunnel is not up, or if your firewall is not configured to allow inbound connections on port 80. Try the following troubleshooting steps&lt;br /&gt;
* Use &amp;lt;code&amp;gt;ifconfig&amp;lt;/code&amp;gt; to verify that your 44Net Connect tunnel is up. You should see a WireGuard interface with your 44Net IP address. &lt;br /&gt;
* Visit [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page] and ensure your tunnel shows up as being connected. &lt;br /&gt;
* Check your firewall configuration and make sure port 80 is open. If you have recently changed your firewall configuration, reload the firewall. &lt;br /&gt;
* If running Certbot inside your Home Assistant docker container, make sure the docker container has its port 80 mapped to the host&#039;s port 80.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2850</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2850"/>
		<updated>2026-08-19T18:44:46Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added troubleshooting section for not being able to access Home Assistant&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run Certbot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run Certbot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run Certbot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up Certbot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and Certbot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up Certbot yourself.&lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Before running the &amp;lt;code&amp;gt;certbot&amp;lt;/code&amp;gt; command, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Home Assistant is not accessible from the 44Net IP ===&lt;br /&gt;
- Ensure you are accessing the correct port for Home Assistant. If you don&#039;t specify a port in your web browser, it will attempt to use port 80 (HTTP) or port 443 (HTTPS) by default, but the default Home Assistant port is 8123. &lt;br /&gt;
- Verify that your firewall configuration has port 8123 (or whatever alternate port you&#039;re using) open. &lt;br /&gt;
- Verify that your 44Net Connect tunnel is up using the [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page].&lt;br /&gt;
&lt;br /&gt;
=== Certificate authority fails to download challenge from the Certbot temporary web server ===&lt;br /&gt;
This typically happens if your 44Net tunnel is not up, or if your firewall is not configured to allow inbound connections on port 80. Try the following troubleshooting steps&lt;br /&gt;
* Use &amp;lt;code&amp;gt;ifconfig&amp;lt;/code&amp;gt; to verify that your 44Net Connect tunnel is up. You should see a WireGuard interface with your 44Net IP address. &lt;br /&gt;
* Visit [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page] and ensure your tunnel shows up as being connected. &lt;br /&gt;
* Check your firewall configuration and make sure port 80 is open. If you have recently changed your firewall configuration, reload the firewall. &lt;br /&gt;
* If running Certbot inside your Home Assistant docker container, make sure the docker container has its port 80 mapped to the host&#039;s port 80.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2849</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2849"/>
		<updated>2026-08-19T18:41:08Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added inline Term reference for cron job&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run Certbot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run Certbot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run Certbot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up Certbot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and Certbot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up Certbot yourself.&lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Before running the &amp;lt;code&amp;gt;certbot&amp;lt;/code&amp;gt; command, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Certificate authority fails to download challenge from the Certbot temporary web server ===&lt;br /&gt;
This typically happens if your 44Net tunnel is not up, or if your firewall is not configured to allow inbound connections on port 80. Try the following troubleshooting steps&lt;br /&gt;
* Use &amp;lt;code&amp;gt;ifconfig&amp;lt;/code&amp;gt; to verify that your 44Net Connect tunnel is up. You should see a WireGuard interface with your 44Net IP address. &lt;br /&gt;
* Visit [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page] and ensure your tunnel shows up as being connected. &lt;br /&gt;
* Check your firewall configuration and make sure port 80 is open. If you have recently changed your firewall configuration, reload the firewall. &lt;br /&gt;
* If running Certbot inside your Home Assistant docker container, make sure the docker container has its port 80 mapped to the host&#039;s port 80.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2848</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2848"/>
		<updated>2026-08-19T18:40:31Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Formatting fix for inline term usage&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run Certbot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run Certbot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run Certbot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term|cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up Certbot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and Certbot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up Certbot yourself.&lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Before running the &amp;lt;code&amp;gt;certbot&amp;lt;/code&amp;gt; command, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Certificate authority fails to download challenge from the Certbot temporary web server ===&lt;br /&gt;
This typically happens if your 44Net tunnel is not up, or if your firewall is not configured to allow inbound connections on port 80. Try the following troubleshooting steps&lt;br /&gt;
* Use &amp;lt;code&amp;gt;ifconfig&amp;lt;/code&amp;gt; to verify that your 44Net Connect tunnel is up. You should see a WireGuard interface with your 44Net IP address. &lt;br /&gt;
* Visit [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page] and ensure your tunnel shows up as being connected. &lt;br /&gt;
* Check your firewall configuration and make sure port 80 is open. If you have recently changed your firewall configuration, reload the firewall. &lt;br /&gt;
* If running Certbot inside your Home Assistant docker container, make sure the docker container has its port 80 mapped to the host&#039;s port 80.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Term:Cron_job&amp;diff=2847</id>
		<title>Term:Cron job</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Term:Cron_job&amp;diff=2847"/>
		<updated>2026-08-19T18:39:42Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Formatting fix&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{TermDefinition&lt;br /&gt;
 | short = Recurring task executed at the specified interval by the cron daemon&lt;br /&gt;
 | long = Cron is a daemon (background process) that executes commands at specified intervals. Each user has their own crontab file where the tasks are described, and there&#039;s a system crontab file as well. Your crontab file can be edited with the command crontab -e.&lt;br /&gt;
 | mode = {{{mode|view}}}&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Term:Cron_job&amp;diff=2846</id>
		<title>Term:Cron job</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Term:Cron_job&amp;diff=2846"/>
		<updated>2026-08-19T18:39:22Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Created term&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{TermDefinition&lt;br /&gt;
 | short = Recurring task executed at the specified interval by the cron daemon }}&lt;br /&gt;
 | long = Cron is a daemon (background process) that executes commands at specified intervals. Each user has their own crontab file where the tasks are described, and there&#039;s a system crontab file as well. Your crontab file can be edited with the command crontab -e.&lt;br /&gt;
 | mode = {{{mode|view}}}&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2845</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2845"/>
		<updated>2026-08-19T18:36:40Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Create cron job term&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run Certbot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run Certbot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run Certbot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a {{Term:cron job}} that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up Certbot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and Certbot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up Certbot yourself.&lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Before running the &amp;lt;code&amp;gt;certbot&amp;lt;/code&amp;gt; command, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Certificate authority fails to download challenge from the Certbot temporary web server ===&lt;br /&gt;
This typically happens if your 44Net tunnel is not up, or if your firewall is not configured to allow inbound connections on port 80. Try the following troubleshooting steps&lt;br /&gt;
* Use &amp;lt;code&amp;gt;ifconfig&amp;lt;/code&amp;gt; to verify that your 44Net Connect tunnel is up. You should see a WireGuard interface with your 44Net IP address. &lt;br /&gt;
* Visit [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page] and ensure your tunnel shows up as being connected. &lt;br /&gt;
* Check your firewall configuration and make sure port 80 is open. If you have recently changed your firewall configuration, reload the firewall. &lt;br /&gt;
* If running Certbot inside your Home Assistant docker container, make sure the docker container has its port 80 mapped to the host&#039;s port 80.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2844</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2844"/>
		<updated>2026-08-19T17:30:31Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Formatting fix&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run Certbot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run Certbot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run Certbot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up Certbot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and Certbot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up Certbot yourself.&lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Before running the &amp;lt;code&amp;gt;certbot&amp;lt;/code&amp;gt; command, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Certificate authority fails to download challenge from the Certbot temporary web server ===&lt;br /&gt;
This typically happens if your 44Net tunnel is not up, or if your firewall is not configured to allow inbound connections on port 80. Try the following troubleshooting steps&lt;br /&gt;
* Use &amp;lt;code&amp;gt;ifconfig&amp;lt;/code&amp;gt; to verify that your 44Net Connect tunnel is up. You should see a WireGuard interface with your 44Net IP address. &lt;br /&gt;
* Visit [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page] and ensure your tunnel shows up as being connected. &lt;br /&gt;
* Check your firewall configuration and make sure port 80 is open. If you have recently changed your firewall configuration, reload the firewall. &lt;br /&gt;
* If running Certbot inside your Home Assistant docker container, make sure the docker container has its port 80 mapped to the host&#039;s port 80.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2843</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2843"/>
		<updated>2026-08-19T17:29:44Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Wrote TLS setup with domain and troubleshooting&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run Certbot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run Certbot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run Certbot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up Certbot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the Certbot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and Certbot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up Certbot yourself.&lt;br /&gt;
&lt;br /&gt;
=== Set up Certbot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install Certbot according to its instructions]. Before running the &amp;lt;code&amp;gt;certbot&amp;lt;/code&amp;gt; command, ensure your firewall has port 80 open on the machine where you installed Certbot. When you request a certificate for an IP, Certbot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running Certbot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Certificate authority fails to download challenge from the Certbot temporary web server ===&lt;br /&gt;
This typically happens if your 44Net tunnel is not up, or if your firewall is not configured to allow inbound connections on port 80. Try the following troubleshooting steps&lt;br /&gt;
- Use &amp;lt;code&amp;gt;ifconfig&amp;lt;/code&amp;gt; to verify that your 44Net Connect tunnel is up. You should see a WireGuard interface with your 44Net IP address. &lt;br /&gt;
- Visit [https://connect.44net.cloud/tunnels the 44Net Connect tunnels page] and ensure your tunnel shows up as being connected. &lt;br /&gt;
- Check your firewall configuration and make sure port 80 is open. If you have recently changed your firewall configuration, reload the firewall. &lt;br /&gt;
- If running Certbot inside your Home Assistant docker container, make sure the docker container has its port 80 mapped to the host&#039;s port 80.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2842</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2842"/>
		<updated>2026-08-19T16:54:29Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Minor phrasing edits&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run CertBot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run CertBot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up CertBot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install CertBot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed CertBot. When you request a certificate for an IP, CertBot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running CertBot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run CertBot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring. Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up CertBot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and CertBot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md instructions for the Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to set up CertBot yourself.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2841</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2841"/>
		<updated>2026-08-19T01:38:12Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added configuring bind mount step&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run CertBot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run CertBot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up CertBot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install CertBot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed CertBot. When you request a certificate for an IP, CertBot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running CertBot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run CertBot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring. Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
=== Configure Docker bind mount ===&lt;br /&gt;
If you set up CertBot on your host machine rather than in your container, you&#039;ll need to set up a [https://docs.docker.com/get-started/docker-concepts/running-containers/sharing-local-files/#file-permissions-for-docker-access-to-host-files bind mount] for the certificate and private key to be accessible to Home Assistant. Keep track of the directory inside the container that the mount is mapped to, and use that path in the next step. &lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and CertBot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip set up CertBot yourself].&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2840</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2840"/>
		<updated>2026-08-19T01:19:27Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Use more specific certbot tutorial link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run CertBot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run CertBot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up CertBot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install CertBot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed CertBot. When you request a certificate for an IP, CertBot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running CertBot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run CertBot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring. Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and CertBot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip set up CertBot yourself].&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2839</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2839"/>
		<updated>2026-08-18T23:15:04Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Made both TLS sections H2&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS without a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run CertBot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run CertBot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up CertBot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install CertBot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed CertBot. When you request a certificate for an IP, CertBot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running CertBot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run CertBot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring. Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.&lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS with a domain ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and CertBot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to [https://certbot.eff.org/ set up CertBot yourself].&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2838</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2838"/>
		<updated>2026-08-18T23:13:24Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Section reorganization&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
== Set up TLS without a domain ==&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run CertBot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run CertBot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
=== Set up CertBot ===&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install CertBot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed CertBot. When you request a certificate for an IP, CertBot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.&lt;br /&gt;
&lt;br /&gt;
Users running CertBot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run CertBot and acquire the certificate, run the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring. Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
=== Configure SSL in Home Assistant ===&lt;br /&gt;
Next, go to &amp;lt;code&amp;gt;Settings &amp;gt; System &amp;gt; Network&amp;lt;/code&amp;gt;, and in the HTTP server section, fill in the paths for your SSL certificate and SSL key. Then, go to the IP banning section, and set the number of login attempts before ban to something other than -1 to prevent people from brute forcing your Home Assistant password.&lt;br /&gt;
&lt;br /&gt;
=== With a doman ===&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and CertBot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to [https://certbot.eff.org/ set up CertBot yourself].&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2837</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2837"/>
		<updated>2026-08-17T23:00:38Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added config example and cron job&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
=== Without a domain ===&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run CertBot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run CertBot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install CertBot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed CertBot. When you request a certificate for an IP, CertBot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.  &lt;br /&gt;
Users running CertBot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run CertBot and acquire the certificate, run the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If it succeeds, you should see output including the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Successfully received certificate.&lt;br /&gt;
Certificate is saved at: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
Key is saved at:         /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&lt;br /&gt;
This certificate expires on 2026-08-24.&lt;br /&gt;
These files will be updated when the certificate renews.&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then, edit the &amp;lt;code&amp;gt;config.yaml&amp;lt;/code&amp;gt; file and configure the location of your certificate.&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;# Example configuration.yaml entry for the HTTP component&lt;br /&gt;
http:&lt;br /&gt;
  ssl_certificate: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/fullchain.pem&lt;br /&gt;
  ssl_key: /etc/letsencrypt/live/&amp;lt;your 44Net IP&amp;gt;/privkey.pem&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set up automatic renewal of your certificate by running the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;echo &amp;quot;0 0,12 * * * root /opt/certbot/bin/python -c &#039;import random; import time; time.sleep(random.random() * 3600)&#039; &amp;amp;&amp;amp; sudo certbot renew -q&amp;quot; | sudo tee -a /etc/crontab &amp;gt; /dev/null&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will add a cron job that checks every 12 hours whether it needs to renew your certificate, and renews the certificate if it&#039;s close to expiring. Finally, verify that your configuration is working by restarting Home Assistant to make it use the new configuration, and then visiting your 44Net IP. Your browser should indicate that your connection to Home Assistant is now encrypted.&lt;br /&gt;
&lt;br /&gt;
=== With a doman ===&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and CertBot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to [https://certbot.eff.org/ set up CertBot yourself].&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2836</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2836"/>
		<updated>2026-08-17T19:00:53Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Started explanation on using CertBot without a domain&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
=== Without a domain ===&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. Unfortunately, the Let&#039;s Encrypt app for Home Assistant OS doesn&#039;t support this, so HAOS users should either use a domain or run CertBot on another machine and find a way to automate updating the certificate in HAOS. Users running Home Assistant in a container can run CertBot in the container or on the host system. &lt;br /&gt;
&lt;br /&gt;
First, [https://certbot.eff.org/instructions?ws=other&amp;amp;os=pip install CertBot according to its instructions]. Stop before the &amp;quot;Choose how you&#039;d like to run Certbot&amp;quot; step. We&#039;ll be using a slightly different command because we&#039;re request a short-lived certificate for a bare IP. &lt;br /&gt;
&lt;br /&gt;
Next, ensure your firewall has port 80 open on the machine where you installed CertBot. When you request a certificate for an IP, CertBot will start a temporary web server on port 80, and tell the Let&#039;s Encrypt server to contact the requested IP on that port. The connection will be through your 44Net IP, so ensure port 80 is open in the correct network zone of your firewall. See [[Firewalling Basics]] for more information.  &lt;br /&gt;
Users running CertBot inside the same Docker container as Home Assistant, but running their single device tunnel on the host OS, may need to [https://docs.docker.com/engine/network/port-publishing/ create a docker port mapping] in addition to opening the port on their host OS&#039;s firewall.&lt;br /&gt;
&lt;br /&gt;
To run CertBot and acquire the certificate, run the following command: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo certbot certonly --standalone --preferred-profile shortlived --ip-address &amp;lt;your 44Net IP&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then, edit the &amp;lt;code&amp;gt;config.yaml&amp;lt;/code&amp;gt; file and configure the location of your certificate.&lt;br /&gt;
&lt;br /&gt;
=== With a doman ===&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and CertBot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to [https://certbot.eff.org/ set up CertBot yourself].&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2835</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2835"/>
		<updated>2026-08-17T16:53:12Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Created without domain and with domain sections&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS ==&lt;br /&gt;
By default, your connection to Home Assistant is unencrypted. Since it contains control traffic that affects the physical devices in your home, encrypting that connection with TLS is recommended. TLS certificates can be obtained for free through Let&#039;s Encrypt, and renewal can be automated via the CertBot project from the Electronic Frontier Foundation.&lt;br /&gt;
&lt;br /&gt;
=== Without a domain ===&lt;br /&gt;
Let&#039;s Encrypt will issue short-lived certificates for bare IP addresses, which are valid for 6 days. &lt;br /&gt;
&lt;br /&gt;
=== With a doman ===&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and CertBot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to [https://certbot.eff.org/ set up CertBot yourself].&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2834</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2834"/>
		<updated>2026-08-13T18:02:43Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added instructions for setting up TLS&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS ==&lt;br /&gt;
If you have a domain name, it can be used with Let&#039;s Encrypt and CertBot to easily set up an automatically renewing TLS certificate. If you&#039;re running Home Assistant OS, you can use the [https://github.com/home-assistant/addons/blob/master/letsencrypt/DOCS.md Let&#039;s Encrypt app]. If you&#039;re running Home Assistant in a docker container, apps are not supported, so you&#039;ll need to [https://certbot.eff.org/ set up CertBot yourself].&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2833</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2833"/>
		<updated>2026-08-13T17:34:42Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added verify connection, TLS, and troubleshooting sections&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Step 3: Verify connection ==&lt;br /&gt;
After opening the port, verify that Home Assistant is accessible via its 44Net IP address on the port you opened. Visit that IP and port in your browser by going to &amp;lt;code&amp;gt;http://&amp;lt;IP&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;. It&#039;s important to use &amp;lt;code&amp;gt;http&amp;lt;/code&amp;gt; rather than &amp;lt;code&amp;gt;https&amp;lt;/code&amp;gt; if you haven&#039;t set up TLS.  &lt;br /&gt;
&lt;br /&gt;
== Optional: Set up TLS ==&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2832</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2832"/>
		<updated>2026-08-07T23:26:35Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added examples for opening the port&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].  &lt;br /&gt;
&lt;br /&gt;
For fresh installations using a single device tunnel, it&#039;s recommended to configure WireGuard as a {{Term|split tunnel}} by setting &amp;lt;code&amp;gt;AllowedIPs&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;44.0.0.0/9, 44.128.0.0/10&amp;lt;/code&amp;gt;. This puts &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port. The syntax for doing so varies based on your firewall tool. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo firewall-ctl --zone=&amp;lt;wireguard interface zone&amp;gt; --add-port 8123/tcp --permanent&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;: &amp;lt;code&amp;gt;sudo ufw allow 8123 proto tcp&amp;lt;/code&amp;gt;&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2820</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2820"/>
		<updated>2026-08-07T18:36:36Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Added prerequisites and wrote step 2&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Prerequisites: &lt;br /&gt;
* A Home Assistant instance (set this up &#039;&#039;&#039;before&#039;&#039;&#039; exposing it to the internet so that setup cannot be hijacked)&lt;br /&gt;
* A 44Net Connect account &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].&lt;br /&gt;
&lt;br /&gt;
For fresh installations using a single device tunnel, it&#039;s recommended to configure WireGuard as a {{Term|split tunnel}} by setting &amp;lt;code&amp;gt;AllowedIPs&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;44.0.0.0/9, 44.128.0.0/10&amp;lt;/code&amp;gt;. This puts &lt;br /&gt;
&lt;br /&gt;
== Step 2: Open port == &lt;br /&gt;
Now that your Home Assistant instance and 44Net Connect tunnel are set up, it&#039;s time to open the required port in your firewall to make Home Assistant publicly accessible. The default Home Assistant port is 8123, so unless you&#039;ve changed it, you&#039;ll need to open &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt; in your firewall. If you&#039;re running a single device tunnel with a Home Assistant VM or docker container, it&#039;s as simple as opening the device&#039;s firewall on &amp;lt;code&amp;gt;8123/tcp&amp;lt;/code&amp;gt;. If you have a Home Assistant appliance inside a routed subnet, you&#039;ll need to open the port in the router&#039;s firewall, and ensure the firewall&#039;s rule set allows {{Term|WAN}} devices to initiate connections on that port.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2819</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2819"/>
		<updated>2026-08-06T22:25:51Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Created Step 1 section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
== Step 1: Set up your tunnel == &lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, the easiest option is running it as a docker container on a device with a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. If you have a dedicated Home Assistant appliance, such as a Home Assistant Green or a Raspberry Pi running Home Assistant OS on {{Term|bare metal}}, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].&lt;br /&gt;
&lt;br /&gt;
For fresh installations using a single device tunnel, if you want Home Assistant to also be available on the LAN, configure WireGuard as a {{Term|split tunnel}} by setting &amp;lt;code&amp;gt;AllowedIPs&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;44.0.0.0/9, 44.128.0.0/10&amp;lt;/code&amp;gt;.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2818</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2818"/>
		<updated>2026-08-05T22:38:05Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Mentioned that the HA WireGuard app is unmaintained&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. It&#039;s not designed to be directly facing the internet, as it has poor device firewall configuration options. Using the shell to edit the &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt; config is technically possible, but it&#039;s not officially supported and risks breaking the Docker &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; configuration that apps running inside Home Assistant use. There is no package manager with which to install higher level firewall tools, and the Home Assistant WireGuard application is unmaintained as of 2026. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, or already have it running as a VM or Docker container, the easiest option is running it as a docker container on a device with a single device tunnel. If you have a dedicated physical Home Assistant appliance, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2817</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2817"/>
		<updated>2026-08-05T22:21:55Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Mention that there&amp;#039;s no package manager in HA OS&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. It&#039;s not designed to be directly facing the internet, as it has poor device firewall configuration options. Using the shell to edit the &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt; config is technically possible, but it&#039;s not officially supported and risks breaking the Docker &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; configuration that apps running inside Home Assistant use. There is no package manager with which to install higher level firewall tools. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, or already have it running as a VM or Docker container, the easiest option is running it as a docker container on a device with a single device tunnel. If you have a dedicated physical Home Assistant appliance, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2816</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2816"/>
		<updated>2026-08-05T22:20:40Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Describe recommended configuration, recommend against exposing bare HA OS appliance&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
Home Assistant OS is designed to operate less like a general purpose computing device and more like an appliance. It&#039;s not designed to be directly facing the internet, as it has poor device firewall configuration options. Using the shell to edit the &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt; config is technically possible, but it&#039;s not officially supported and risks breaking the Docker &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; configuration that apps running inside Home Assistant use. If you&#039;re setting up a fresh Home Assistant installation for the express purpose of exposing it to 44Net, or already have it running as a VM or Docker container, the easiest option is running it as a docker container on a device with a single device tunnel. If you have a dedicated physical Home Assistant appliance, the recommended configuration is to put it on a [[44Net_Connect/Routed Subnet | routed subnet]].&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2815</id>
		<title>Home Assistant</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Home_Assistant&amp;diff=2815"/>
		<updated>2026-08-03T21:37:29Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Remind users they probably have a dynamic IP even if they don&amp;#039;t have CGNAT&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Home Assistant is an open source home automation server. It has integrations for a wide variety of devices, and allows you to create custom dashboards for viewing sensor information and controlling your devices. If you want to access your Home Assistant instance from anywhere, but cannot port forward due to {{Term|CGNAT}}, making your instance publicly accessible via 44Net is one solution. Even if your home internet isn&#039;t behind CGNAT, it likely has a dynamic IP, which would require you to set up dynamic DNS for your instance to maintain consistent external access. A 44Net IP lets your instance be publicly accessible at a fixed IPv4 address for free. &lt;br /&gt;
&lt;br /&gt;
The easiest way to make your Home Assistant instance publicly accessible is by setting up a [[44Net_Connect/Single Device Tunnel | single device tunnel]]. However, before you make it publicly accessible, there are a few security considerations. First, you should configure your firewall. See [[Firewalling Basics]] for help with firewall configuration. It&#039;s also desirable to set up Let&#039;s Encrypt, so that your connection to Home Assistant will be encrypted with TLS, and will have protection against man-in-the-middle attacks.&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Firewalling_Basics&amp;diff=2814</id>
		<title>Firewalling Basics</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Firewalling_Basics&amp;diff=2814"/>
		<updated>2026-08-03T19:10:25Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: /* ufw */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 44Net Connect and Security == &lt;br /&gt;
44Net Connect provides every device with a public facing IPv4 address, and does not inspect, filter, or block any traffic directed towards 44Net devices. Devices with publicly routable IP addresses face a constant barrage of traffic from various scanners and bots on the internet. Some of them are malicious, and correctly configuring your firewall is a key part of defending against them. &lt;br /&gt;
&lt;br /&gt;
== What does a firewall do? ==&lt;br /&gt;
At its most basic, a firewall inspects incoming and outgoing packets, and based on its set of rules, decides whether each packet should be allowed through, dropped, or diverted. Rules may consider a packet&#039;s source and destination IP, source and destination interface, port, protocol (TCP vs UDP), or various special flags that may be set. Basic firewall usage is primarily concerned with source/destination IP, source/destination interface, and port. There are several goals we can achieve via firewall rules: allow outside connections to public-facing services, block outside connections to private services, and in case your device is compromised, block outgoing malicious traffic originating from your device. &lt;br /&gt;
&lt;br /&gt;
Outside connections to a public-facing service are typically allowed using a firewall rule that accepts all packets on the port that service is using, regardless of the packet&#039;s source IP. Private services, such as those only intended for your LAN, are typically protected by a firewall rule that only accepts packets whose source IP is inside your LAN. Packets sent to that port that originate externally will be dropped. You may have services that are only meant to be accessed from &amp;lt;code&amp;gt;localhost&amp;lt;/code&amp;gt;, such as control interfaces accessed only by other software on the same device. &lt;br /&gt;
&lt;br /&gt;
=== Stateful Firewalls ===&lt;br /&gt;
Stateful firewalls are capable of remembering information about previous packets, and using it when making later decisions. The most common use for this is connection tracking, a feature enabled by default on many firewalls. Connection tracking remembers when a trusted device, usually one inside your LAN, has initiated a connection to an external device. When the return traffic from the external device comes in, it will be allowed through the firewall, even if the default policy would have otherwise dropped it. It&#039;s important to remember this feature when testing your firewall. Even if your device is able to initiate connections to an untrusted device on the outside of your firewall, that device may not be able to initiate a connection to your device, depending on your firewall rules. Most modern firewalls, such as those based on &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt;, are stateful. If for some reason this behavior is undesirable, it can be overridden with rules that explicitly drop the unwanted external traffic. &lt;br /&gt;
&lt;br /&gt;
Stateful firewalls also enable various advanced security features that are outside the scope of this guide, such as those utilizing TCP sequence numbers. &lt;br /&gt;
&lt;br /&gt;
Stateless firewalls are not capable of remembering previous packets, and handle each packet as if it&#039;s completely unrelated to all other packets.&lt;br /&gt;
&lt;br /&gt;
== Configuration Recommendations ==&lt;br /&gt;
When configuring any kind of security policy, best practice is to apply the &#039;&#039;&#039;principle of least privilege.&#039;&#039;&#039; This means that a person or device is given the minimum level of access to perform their job. This minimizes attack surface (the ways in which a malicious party can attack your network) and minimizes damage if a device or user&#039;s credentials are compromised. When it comes to configuring a firewall, that means only opening the ports on which you&#039;re actually running services, and only allowing communication between network segments if it&#039;s actually necessary. &lt;br /&gt;
&lt;br /&gt;
For example, some people confine Internet of Things (IoT) devices to their own {{term|VLAN}} due to their often poor security. In such a configuration, you might allow devices from the regular LAN to initiate connections to the IoT devices, but not the other way around, to prevent a compromised IoT device from attacking the rest of your network. We recommend a similar configuration for your 44Net subnet. Some take it a step further, and block {{term|WAN}} access from the IoT VLAN to prevent devices from sending telemetry to their manufacturer.&lt;br /&gt;
&lt;br /&gt;
When restricting access between devices on your internal network, it can be helpful to use a policy that explicitly rejects disallowed packets rather than silently dropping them. This feedback can be helpful when troubleshooting, as it immediately lets you know that packets are being blocked by firewall policy rather than something like a port mismatch or a hostname/IP typo. Reject policies should not be used for WAN-facing interfaces, otherwise you may spend lots of compute power sending packet rejections to automated scanners and other malicious actors on the wider internet.&lt;br /&gt;
&lt;br /&gt;
== Low Level Tools ==&lt;br /&gt;
=== iptables ===&lt;br /&gt;
&amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; is a Linux firewall rule management tool that was deprecated in favor of &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt; in 2014. It allows system administrators to define &#039;&#039;tables&#039;&#039; containing &#039;&#039;chains&#039;&#039; of &#039;&#039;rules&#039;&#039; for the treatment of packets.&amp;lt;ref&amp;gt;https://en.wikipedia.org/wiki/Iptables&amp;lt;/ref&amp;gt; Both &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt; use the netfilter framework to interface with the Linux kernel. &lt;br /&gt;
&lt;br /&gt;
Modern systems no longer ship with an actual copy of &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt;, instead using a compatibility layer that translates its rules to &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== nftables ===&lt;br /&gt;
nftables is the currently maintained Linux firewall rule management tool. It interfaces with the Linux kernel via the netfilter framework, and can be administrated with the &amp;lt;code&amp;gt;nft&amp;lt;/code&amp;gt; command line tool as well as editing &amp;lt;code&amp;gt;/etc/nftables.conf&amp;lt;/code&amp;gt;. Changes made with the &amp;lt;code&amp;gt;nft&amp;lt;/code&amp;gt; tool will not persist between reboots, and must be written into the config file to ensure persistence. It functions similarly to &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt;, employing tables of chains of rules, but with no predefined chains and more flexible rules.&lt;br /&gt;
&lt;br /&gt;
[[ File:Netfilter.png | 500px | A diagram illustrating the table, chain, and rule hierarchy used by iptables and nftables. A packet proceeds into the table, through the first chain, and does not match any rules. It proceeds through the second chain, matches the second rule, and makes a routing decision. ]]&lt;br /&gt;
&lt;br /&gt;
While firewall rules can be directly configured with &amp;lt;code&amp;gt;nft&amp;lt;/code&amp;gt;, this is not recommended. The output of &amp;lt;code&amp;gt;sudo nft list ruleset&amp;lt;/code&amp;gt; is extremely verbose and not well formatted. &amp;lt;code&amp;gt;nft&amp;lt;/code&amp;gt; provides few formatting options for this output. See the next section for user-friendly tools that interface with nftables.&lt;br /&gt;
&lt;br /&gt;
== High Level Tools ==&lt;br /&gt;
=== firewalld ===&lt;br /&gt;
&amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt; is an &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt;-based CLI firewall management tool. It ships by default on CentOS, Fedora, OpenSUSE, RHEL, SUSE Enterprise, and EndeavourOS, and is packaged for many more distributions. It introduces the idea of a &amp;quot;zone,&amp;quot; which is a named set of policies that an interface can be assigned to. Each zone has a target, which is set to &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;DROP&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;REJECT&amp;lt;/code&amp;gt;, or &amp;lt;code&amp;gt;ACCEPT&amp;lt;/code&amp;gt;. These targets determine what action will be taken on packets in the zone that don&#039;t match any of the rules, services, or ports. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; will accept ICMP and drop everything else.&lt;br /&gt;
* &amp;lt;code&amp;gt;DROP&amp;lt;/code&amp;gt; will discard packets without notifying the sender.&lt;br /&gt;
* &amp;lt;code&amp;gt;REJECT&amp;lt;/code&amp;gt; will discard the packet and notify the sender of its rejection.&lt;br /&gt;
* &amp;lt;code&amp;gt;ACCEPT&amp;lt;/code&amp;gt; will allow the packet through.&lt;br /&gt;
&lt;br /&gt;
Check your current zone configuration by running &amp;lt;code&amp;gt;sudo firewalld --list-all-zones&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
It&#039;s best to put public-facing interfaces into a &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;DROP&amp;lt;/code&amp;gt; target zone. &amp;lt;code&amp;gt;ACCEPT&amp;lt;/code&amp;gt; will allow unwanted or malicious traffic, and &amp;lt;code&amp;gt;REJECT&amp;lt;/code&amp;gt; will spend lots of bandwidth replying to the barrage of traffic from bots scanning the internet. Devices owned by you but publicly accessible from the internet are typically put in a demilitarized zone (DMZ), a network area with only some access to the LAN. This typically involves preventing DMZ devices from initiating connections to LAN devices, but allowing the opposite. &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt; comes with a &amp;lt;code&amp;gt;dmz&amp;lt;/code&amp;gt; zone by default, and this is a good place to put the interface that faces your 44Net subnet. (Note that your LAN interface must also be in a default accept zone for it to allow initiating connections to DMZ devices.) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt; can be controlled using the &amp;lt;code&amp;gt;firewall-cmd&amp;lt;/code&amp;gt; utility, or by editing the config file at &amp;lt;code&amp;gt;/etc/firewalld&amp;lt;/code&amp;gt;. Typical policy changes introduced using &amp;lt;code&amp;gt;firewall-cmd&amp;lt;/code&amp;gt; are called &amp;quot;runtime&amp;quot; changes, and will not persist after a restart of the service or a reboot. Permanent changes can be made by adding the &amp;lt;code&amp;gt;--permanent&amp;lt;/code&amp;gt; flag, or by introducing runtime changes and then invoking &amp;lt;code&amp;gt;firewall-cmd --runtime-to-permanent&amp;lt;/code&amp;gt;, which saves all current runtime changes to permanent configuration.&lt;br /&gt;
&lt;br /&gt;
Services are a &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt; abstraction containing a list of ports, protocols, destinations, and optionally a list of firewall helper modules to be loaded if the service is enabled. They make it easy to toggle these configuration groups, rather than having to toggle every rule in them individually. They can be configured using &amp;lt;code&amp;gt;firewall-cmd&amp;lt;/code&amp;gt; or by creating an XML file in &amp;lt;code&amp;gt;/etc/firewalld/services/&amp;lt;/code&amp;gt;. See &amp;lt;code&amp;gt;man firewalld.service&amp;lt;/code&amp;gt; for more information on services. As an example, the following command would enable the &amp;lt;code&amp;gt;ssh&amp;lt;/code&amp;gt; service in the &amp;lt;code&amp;gt;public&amp;lt;/code&amp;gt; zone. &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;sudo firewall-cmd --permanent --zone public --add-service ssh&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Another advantage of using services is that the service definition can be edited, and then it will apply to all zones with that service enabled when firewalld is reloaded. firewalld can be reloaded using &amp;lt;code&amp;gt;sudo firewall-cmd --reload&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== ufw ===&lt;br /&gt;
Uncomplicated Firewall is a CLI program designed for easily managing a netfilter firewall. It also supports GUI management via the &amp;lt;code&amp;gt;gufw&amp;lt;/code&amp;gt; tool. When running, the active firewall rules can be viewed with &amp;lt;code&amp;gt;sudo ufw status&amp;lt;/code&amp;gt;. If you want to see the firewall rules while &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt; is not running, use &amp;lt;code&amp;gt;sudo ufw show added&amp;lt;/code&amp;gt;. It uses a simple syntax with property names rather than flags. For the very simple operation of opening a port without utilizing any optional parameters, you need not even specify property names. One can allow TCP connections on port 22 (for example, to allow an SSH server) and start UFW as follows:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;sudo ufw allow 22/tcp&lt;br /&gt;
sudo ufw enable&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It also allows comments by specifying the &amp;lt;code&amp;gt;comment&amp;lt;/code&amp;gt; property and enclosing the actual comment in quotes. For example, &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo ufw allow 22/tcp comment &#039;SSH port&#039;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
will show in the &amp;lt;code&amp;gt;ufw status&amp;lt;/code&amp;gt; output as &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
To                         Action      From&lt;br /&gt;
--                         ------      ----&lt;br /&gt;
22/tcp                     ALLOW       Anywhere                 # SSH port&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt; uses similar targets to &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt;, except it uses &amp;lt;code&amp;gt;deny&amp;lt;/code&amp;gt; instead of &amp;lt;code&amp;gt;DROP&amp;lt;/code&amp;gt;. To put a 44Net subnet in a {{term:DMZ}}, apply the following rules. &lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
sudo ufw reject in on &amp;lt;subnet interface&amp;gt; to &amp;lt;LAN interface&amp;gt;&lt;br /&gt;
sudo ufw accept in on &amp;lt;LAN interface&amp;gt; to &amp;lt;subnet interface&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By default, Docker writes its own &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; rules and ignores &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt; rules. This can cause conflicts and security issues in combination with &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;.&amp;lt;ref&amp;gt;“Uncomplicated Firewall - ArchWiki.” 2024. Archlinux.Org. https://wiki.archlinux.org/title/Uncomplicated_Firewall.&amp;lt;/ref&amp;gt;&lt;br /&gt;
If you wish to use &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt; on a system that has Docker, consider [https://docs.docker.com/engine/network/firewall-nftables#migrating-from-iptables-to-nftables migrating Docker to nftables.]&lt;br /&gt;
&lt;br /&gt;
== Verifying Configuration ==&lt;br /&gt;
After configuring your firewall, it&#039;s important to test the configuration to ensure that it&#039;s working how you think it is. This can be done with the help of a few command line tools. &lt;br /&gt;
&lt;br /&gt;
=== Verify that a port is open or closed === &lt;br /&gt;
To test whether a port is properly opened or closed, you can use set up a &amp;lt;code&amp;gt;netcat&amp;lt;/code&amp;gt; listener a device behind the firewall, and use &amp;lt;code&amp;gt;curl&amp;lt;/code&amp;gt; to connect to it with a device outside the firewall. On the inside device, run &amp;lt;code&amp;gt;nc -l -p &amp;lt;port&amp;gt;&amp;lt;/code&amp;gt; (but replace &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; with your desired port) to start the listener. If you have a service that normally runs on this port, you&#039;ll need to temporarily stop it so that &amp;lt;code&amp;gt;netcat&amp;lt;/code&amp;gt; can bind to the port. On the outside device, run &amp;lt;code&amp;gt;curl &amp;lt;hostname&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;, and if the port is open, you&#039;ll see some text pop up on the &amp;lt;code&amp;gt;netcat&amp;lt;/code&amp;gt; listener indicating that it received an HTTP GET request. &lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Traffic is supposed to pass but only works intermittently ===&lt;br /&gt;
This can happen when you have duplicate or conflicting firewall rules. This can happen if you add runtime rules that are already part of persistent configuration, or add the same rules to multiple scripts or configuration files. Re-read your firewall rules and ensure there are no duplicates or conflicting rules. It may help to restore the last known working configuration, and start from there.&lt;br /&gt;
&lt;br /&gt;
=== Traffic is supposed to pass but is not going through ===&lt;br /&gt;
Common causes:&lt;br /&gt;
* The firewall was not reloaded after changing configuration files&lt;br /&gt;
* The device has its own firewall &#039;&#039;and&#039;&#039; is behind the router firewall, and one of them is missing allow rules. &lt;br /&gt;
* Traffic has not been allowed on the correct protocol (TCP instead of UDP, or vice versa) &lt;br /&gt;
&lt;br /&gt;
== References ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
	<entry>
		<id>https://wiki.ampr.org/w/index.php?title=Firewalling_Basics&amp;diff=2813</id>
		<title>Firewalling Basics</title>
		<link rel="alternate" type="text/html" href="https://wiki.ampr.org/w/index.php?title=Firewalling_Basics&amp;diff=2813"/>
		<updated>2026-08-03T18:22:21Z</updated>

		<summary type="html">&lt;p&gt;KN6DWI: Recommend putting 44Net devices in a DMZ&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 44Net Connect and Security == &lt;br /&gt;
44Net Connect provides every device with a public facing IPv4 address, and does not inspect, filter, or block any traffic directed towards 44Net devices. Devices with publicly routable IP addresses face a constant barrage of traffic from various scanners and bots on the internet. Some of them are malicious, and correctly configuring your firewall is a key part of defending against them. &lt;br /&gt;
&lt;br /&gt;
== What does a firewall do? ==&lt;br /&gt;
At its most basic, a firewall inspects incoming and outgoing packets, and based on its set of rules, decides whether each packet should be allowed through, dropped, or diverted. Rules may consider a packet&#039;s source and destination IP, source and destination interface, port, protocol (TCP vs UDP), or various special flags that may be set. Basic firewall usage is primarily concerned with source/destination IP, source/destination interface, and port. There are several goals we can achieve via firewall rules: allow outside connections to public-facing services, block outside connections to private services, and in case your device is compromised, block outgoing malicious traffic originating from your device. &lt;br /&gt;
&lt;br /&gt;
Outside connections to a public-facing service are typically allowed using a firewall rule that accepts all packets on the port that service is using, regardless of the packet&#039;s source IP. Private services, such as those only intended for your LAN, are typically protected by a firewall rule that only accepts packets whose source IP is inside your LAN. Packets sent to that port that originate externally will be dropped. You may have services that are only meant to be accessed from &amp;lt;code&amp;gt;localhost&amp;lt;/code&amp;gt;, such as control interfaces accessed only by other software on the same device. &lt;br /&gt;
&lt;br /&gt;
=== Stateful Firewalls ===&lt;br /&gt;
Stateful firewalls are capable of remembering information about previous packets, and using it when making later decisions. The most common use for this is connection tracking, a feature enabled by default on many firewalls. Connection tracking remembers when a trusted device, usually one inside your LAN, has initiated a connection to an external device. When the return traffic from the external device comes in, it will be allowed through the firewall, even if the default policy would have otherwise dropped it. It&#039;s important to remember this feature when testing your firewall. Even if your device is able to initiate connections to an untrusted device on the outside of your firewall, that device may not be able to initiate a connection to your device, depending on your firewall rules. Most modern firewalls, such as those based on &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt;, are stateful. If for some reason this behavior is undesirable, it can be overridden with rules that explicitly drop the unwanted external traffic. &lt;br /&gt;
&lt;br /&gt;
Stateful firewalls also enable various advanced security features that are outside the scope of this guide, such as those utilizing TCP sequence numbers. &lt;br /&gt;
&lt;br /&gt;
Stateless firewalls are not capable of remembering previous packets, and handle each packet as if it&#039;s completely unrelated to all other packets.&lt;br /&gt;
&lt;br /&gt;
== Configuration Recommendations ==&lt;br /&gt;
When configuring any kind of security policy, best practice is to apply the &#039;&#039;&#039;principle of least privilege.&#039;&#039;&#039; This means that a person or device is given the minimum level of access to perform their job. This minimizes attack surface (the ways in which a malicious party can attack your network) and minimizes damage if a device or user&#039;s credentials are compromised. When it comes to configuring a firewall, that means only opening the ports on which you&#039;re actually running services, and only allowing communication between network segments if it&#039;s actually necessary. &lt;br /&gt;
&lt;br /&gt;
For example, some people confine Internet of Things (IoT) devices to their own {{term|VLAN}} due to their often poor security. In such a configuration, you might allow devices from the regular LAN to initiate connections to the IoT devices, but not the other way around, to prevent a compromised IoT device from attacking the rest of your network. We recommend a similar configuration for your 44Net subnet. Some take it a step further, and block {{term|WAN}} access from the IoT VLAN to prevent devices from sending telemetry to their manufacturer.&lt;br /&gt;
&lt;br /&gt;
When restricting access between devices on your internal network, it can be helpful to use a policy that explicitly rejects disallowed packets rather than silently dropping them. This feedback can be helpful when troubleshooting, as it immediately lets you know that packets are being blocked by firewall policy rather than something like a port mismatch or a hostname/IP typo. Reject policies should not be used for WAN-facing interfaces, otherwise you may spend lots of compute power sending packet rejections to automated scanners and other malicious actors on the wider internet.&lt;br /&gt;
&lt;br /&gt;
== Low Level Tools ==&lt;br /&gt;
=== iptables ===&lt;br /&gt;
&amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; is a Linux firewall rule management tool that was deprecated in favor of &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt; in 2014. It allows system administrators to define &#039;&#039;tables&#039;&#039; containing &#039;&#039;chains&#039;&#039; of &#039;&#039;rules&#039;&#039; for the treatment of packets.&amp;lt;ref&amp;gt;https://en.wikipedia.org/wiki/Iptables&amp;lt;/ref&amp;gt; Both &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt; use the netfilter framework to interface with the Linux kernel. &lt;br /&gt;
&lt;br /&gt;
Modern systems no longer ship with an actual copy of &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt;, instead using a compatibility layer that translates its rules to &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== nftables ===&lt;br /&gt;
nftables is the currently maintained Linux firewall rule management tool. It interfaces with the Linux kernel via the netfilter framework, and can be administrated with the &amp;lt;code&amp;gt;nft&amp;lt;/code&amp;gt; command line tool as well as editing &amp;lt;code&amp;gt;/etc/nftables.conf&amp;lt;/code&amp;gt;. Changes made with the &amp;lt;code&amp;gt;nft&amp;lt;/code&amp;gt; tool will not persist between reboots, and must be written into the config file to ensure persistence. It functions similarly to &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt;, employing tables of chains of rules, but with no predefined chains and more flexible rules.&lt;br /&gt;
&lt;br /&gt;
[[ File:Netfilter.png | 500px | A diagram illustrating the table, chain, and rule hierarchy used by iptables and nftables. A packet proceeds into the table, through the first chain, and does not match any rules. It proceeds through the second chain, matches the second rule, and makes a routing decision. ]]&lt;br /&gt;
&lt;br /&gt;
While firewall rules can be directly configured with &amp;lt;code&amp;gt;nft&amp;lt;/code&amp;gt;, this is not recommended. The output of &amp;lt;code&amp;gt;sudo nft list ruleset&amp;lt;/code&amp;gt; is extremely verbose and not well formatted. &amp;lt;code&amp;gt;nft&amp;lt;/code&amp;gt; provides few formatting options for this output. See the next section for user-friendly tools that interface with nftables.&lt;br /&gt;
&lt;br /&gt;
== High Level Tools ==&lt;br /&gt;
=== firewalld ===&lt;br /&gt;
&amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt; is an &amp;lt;code&amp;gt;nftables&amp;lt;/code&amp;gt;-based CLI firewall management tool. It ships by default on CentOS, Fedora, OpenSUSE, RHEL, SUSE Enterprise, and EndeavourOS, and is packaged for many more distributions. It introduces the idea of a &amp;quot;zone,&amp;quot; which is a named set of policies that an interface can be assigned to. Each zone has a target, which is set to &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;DROP&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;REJECT&amp;lt;/code&amp;gt;, or &amp;lt;code&amp;gt;ACCEPT&amp;lt;/code&amp;gt;. These targets determine what action will be taken on packets in the zone that don&#039;t match any of the rules, services, or ports. &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; will accept ICMP and drop everything else.&lt;br /&gt;
* &amp;lt;code&amp;gt;DROP&amp;lt;/code&amp;gt; will discard packets without notifying the sender.&lt;br /&gt;
* &amp;lt;code&amp;gt;REJECT&amp;lt;/code&amp;gt; will discard the packet and notify the sender of its rejection.&lt;br /&gt;
* &amp;lt;code&amp;gt;ACCEPT&amp;lt;/code&amp;gt; will allow the packet through.&lt;br /&gt;
&lt;br /&gt;
Check your current zone configuration by running &amp;lt;code&amp;gt;sudo firewalld --list-all-zones&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
It&#039;s best to put public-facing interfaces into a &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;DROP&amp;lt;/code&amp;gt; target zone. &amp;lt;code&amp;gt;ACCEPT&amp;lt;/code&amp;gt; will allow unwanted or malicious traffic, and &amp;lt;code&amp;gt;REJECT&amp;lt;/code&amp;gt; will spend lots of bandwidth replying to the barrage of traffic from bots scanning the internet. Devices owned by you but publicly accessible from the internet are typically put in a demilitarized zone (DMZ), a network area with only some access to the LAN. This typically involves preventing DMZ devices from initiating connections to LAN devices, but allowing the opposite. &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt; comes with a &amp;lt;code&amp;gt;dmz&amp;lt;/code&amp;gt; zone by default, and this is a good place to put the interface that faces your 44Net subnet. (Note that your LAN interface must also be in a default accept zone for it to allow initiating connections to DMZ devices.) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt; can be controlled using the &amp;lt;code&amp;gt;firewall-cmd&amp;lt;/code&amp;gt; utility, or by editing the config file at &amp;lt;code&amp;gt;/etc/firewalld&amp;lt;/code&amp;gt;. Typical policy changes introduced using &amp;lt;code&amp;gt;firewall-cmd&amp;lt;/code&amp;gt; are called &amp;quot;runtime&amp;quot; changes, and will not persist after a restart of the service or a reboot. Permanent changes can be made by adding the &amp;lt;code&amp;gt;--permanent&amp;lt;/code&amp;gt; flag, or by introducing runtime changes and then invoking &amp;lt;code&amp;gt;firewall-cmd --runtime-to-permanent&amp;lt;/code&amp;gt;, which saves all current runtime changes to permanent configuration.&lt;br /&gt;
&lt;br /&gt;
Services are a &amp;lt;code&amp;gt;firewalld&amp;lt;/code&amp;gt; abstraction containing a list of ports, protocols, destinations, and optionally a list of firewall helper modules to be loaded if the service is enabled. They make it easy to toggle these configuration groups, rather than having to toggle every rule in them individually. They can be configured using &amp;lt;code&amp;gt;firewall-cmd&amp;lt;/code&amp;gt; or by creating an XML file in &amp;lt;code&amp;gt;/etc/firewalld/services/&amp;lt;/code&amp;gt;. See &amp;lt;code&amp;gt;man firewalld.service&amp;lt;/code&amp;gt; for more information on services. As an example, the following command would enable the &amp;lt;code&amp;gt;ssh&amp;lt;/code&amp;gt; service in the &amp;lt;code&amp;gt;public&amp;lt;/code&amp;gt; zone. &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;sudo firewall-cmd --permanent --zone public --add-service ssh&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Another advantage of using services is that the service definition can be edited, and then it will apply to all zones with that service enabled when firewalld is reloaded. firewalld can be reloaded using &amp;lt;code&amp;gt;sudo firewall-cmd --reload&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== ufw ===&lt;br /&gt;
Uncomplicated Firewall is a CLI program designed for easily managing a netfilter firewall. It also supports GUI management via the &amp;lt;code&amp;gt;gufw&amp;lt;/code&amp;gt; tool. When running, the active firewall rules can be viewed with &amp;lt;code&amp;gt;sudo ufw status&amp;lt;/code&amp;gt;. If you want to see the firewall rules while &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt; is not running, use &amp;lt;code&amp;gt;sudo ufw show added&amp;lt;/code&amp;gt;. It uses a simple syntax with property names rather than flags. For the very simple operation of opening a port without utilizing any optional parameters, you need not even specify property names. One can allow TCP connections on port 22 (for example, to allow an SSH server) and start UFW as follows:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;sudo ufw allow 22/tcp&lt;br /&gt;
sudo ufw enable&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It also allows comments by specifying the &amp;lt;code&amp;gt;comment&amp;lt;/code&amp;gt; property and enclosing the actual comment in quotes. For example, &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo ufw allow 22/tcp comment &#039;SSH port&#039;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
will show in the &amp;lt;code&amp;gt;ufw status&amp;lt;/code&amp;gt; output as &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
To                         Action      From&lt;br /&gt;
--                         ------      ----&lt;br /&gt;
22/tcp                     ALLOW       Anywhere                 # SSH port&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By default, Docker writes its own &amp;lt;code&amp;gt;iptables&amp;lt;/code&amp;gt; rules and ignores &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt; rules. This can cause conflicts and security issues in combination with &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt;.&amp;lt;ref&amp;gt;“Uncomplicated Firewall - ArchWiki.” 2024. Archlinux.Org. https://wiki.archlinux.org/title/Uncomplicated_Firewall.&amp;lt;/ref&amp;gt;&lt;br /&gt;
If you wish to use &amp;lt;code&amp;gt;ufw&amp;lt;/code&amp;gt; on a system that has Docker, consider [https://docs.docker.com/engine/network/firewall-nftables#migrating-from-iptables-to-nftables migrating Docker to nftables.]&lt;br /&gt;
&lt;br /&gt;
== Verifying Configuration ==&lt;br /&gt;
After configuring your firewall, it&#039;s important to test the configuration to ensure that it&#039;s working how you think it is. This can be done with the help of a few command line tools. &lt;br /&gt;
&lt;br /&gt;
=== Verify that a port is open or closed === &lt;br /&gt;
To test whether a port is properly opened or closed, you can use set up a &amp;lt;code&amp;gt;netcat&amp;lt;/code&amp;gt; listener a device behind the firewall, and use &amp;lt;code&amp;gt;curl&amp;lt;/code&amp;gt; to connect to it with a device outside the firewall. On the inside device, run &amp;lt;code&amp;gt;nc -l -p &amp;lt;port&amp;gt;&amp;lt;/code&amp;gt; (but replace &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; with your desired port) to start the listener. If you have a service that normally runs on this port, you&#039;ll need to temporarily stop it so that &amp;lt;code&amp;gt;netcat&amp;lt;/code&amp;gt; can bind to the port. On the outside device, run &amp;lt;code&amp;gt;curl &amp;lt;hostname&amp;gt;:&amp;lt;port&amp;gt;&amp;lt;/code&amp;gt;, and if the port is open, you&#039;ll see some text pop up on the &amp;lt;code&amp;gt;netcat&amp;lt;/code&amp;gt; listener indicating that it received an HTTP GET request. &lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Traffic is supposed to pass but only works intermittently ===&lt;br /&gt;
This can happen when you have duplicate or conflicting firewall rules. This can happen if you add runtime rules that are already part of persistent configuration, or add the same rules to multiple scripts or configuration files. Re-read your firewall rules and ensure there are no duplicates or conflicting rules. It may help to restore the last known working configuration, and start from there.&lt;br /&gt;
&lt;br /&gt;
=== Traffic is supposed to pass but is not going through ===&lt;br /&gt;
Common causes:&lt;br /&gt;
* The firewall was not reloaded after changing configuration files&lt;br /&gt;
* The device has its own firewall &#039;&#039;and&#039;&#039; is behind the router firewall, and one of them is missing allow rules. &lt;br /&gt;
* Traffic has not been allowed on the correct protocol (TCP instead of UDP, or vice versa) &lt;br /&gt;
&lt;br /&gt;
== References ==&lt;/div&gt;</summary>
		<author><name>KN6DWI</name></author>
	</entry>
</feed>