OcxlyDev · Field Guide

Zero-trust in the home lab: ditch port forwarding forever

The oldest way to reach your home lab from outside is to forward a port, and it is also the one that exposes your home network to constant internet scanning. This explains why to stop, and the zero-trust tools that replace it.

OcxlyDev Published 15 August 2026 ~6 min read Sources linked throughout

A common early step in self-hosting is to forward port 443 to your server and watch the app load from your phone on mobile data. The problem is that this does the thing most security guidance warns against: it opens an inbound entrance in your home firewall, and automated scanners will find it quickly. There is a better approach, and it is the same one companies adopted over the last decade: zero trust.

01Why port forwarding is a real risk

A forwarded port is a permanent, publicly reachable entrance into your home network. The internet is scanned continuously — services like Shodan catalogue exposed devices around the clock — so an open port is not hidden until someone finds it; it is found quickly and probed repeatedly. Every service you expose this way is only as safe as its worst unpatched vulnerability and weakest password, and a single compromised app can become a foothold into the rest of your network, including the laptops and phones on it. This is the normal outcome of leaving ports open on the public internet, not a rare one.

02What zero trust means

Zero trust is not a product; it is a security model, defined by NIST in Special Publication 800-207. The core idea is that no user or device is trusted simply for being on a particular network: every access request is authenticated and authorised on its own, and trust is not granted just because a request came from inside.1 For a home lab, the practical version is straightforward: instead of exposing a service to the network and hoping the network is safe, you make every connection prove who it is first. That shift is what lets you close every inbound port and still reach everything.

03Reverse proxy plus Cloudflare Tunnel

The first replacement for port forwarding is an outbound-only tunnel. Cloudflare Tunnel runs a small daemon (cloudflared) inside your network that makes an outbound connection to Cloudflare; inbound traffic then reaches your services through that connection, so you never open an inbound port on your router.2 Your firewall stays closed to the internet, your home IP address is hidden behind Cloudflare, and you can add Cloudflare Access policies to require a login before anyone reaches the app. Pair the tunnel with a local reverse proxy (Traefik, Caddy, or Nginx Proxy Manager) and each service gets a clean HTTPS hostname with no port number.

cloudflared
# The key idea: the connection goes out, not in.
cloudflared tunnel run my-homelab

# cloudflared dials Cloudflare from inside your network.
# Your router's inbound ports stay closed. Nothing is forwarded.

04ZTNA with Tailscale and Twingate

The second replacement is a zero-trust network access overlay: a private mesh that only your authenticated devices can join. Tailscale builds a mesh VPN between your devices on top of the WireGuard protocol,5 where each device authenticates through your identity provider and they connect directly and encrypted, with no public ports and no central VPN box to expose.3 Twingate offers a similar model built around least-privilege, per-resource access.4 The model is different from a traditional VPN: rather than letting a device onto the network, you grant a specific authenticated device access to specific resources, which is what NIST 800-207 describes.1

Port forwarding trusts the whole internet to behave and your weakest service to hold. Zero trust asks every connection to prove itself and trusts nothing by default.

05Reaching your apps from your phone

The result is that remote access gets easier, not harder. With Tailscale on your phone, your self-hosted apps are reachable over the encrypted mesh from anywhere, as if you were at home, with no port forwarding and nothing exposed for a scanner to find.3 With a Cloudflare Tunnel plus Access, you open the app's hostname in a browser and authenticate at Cloudflare's edge before the request reaches your network.2 In both cases the internet sees nothing pointing at your house, and you can still reach your dashboards from anywhere. That is what zero trust looks like in practice: less exposure and more convenience at once.

06Where OcxlyDev lands

We do not forward ports, and we do not recommend it. The zero-trust tools are free or inexpensive, take an evening to set up, and remove an entire category of risk — the standing, public, inbound entrance — from your home network. Start with Tailscale for your own device access, since it is the quickest win, and add a Cloudflare Tunnel when you need to share a service with someone who is not on your mesh. Close every inbound port, make every connection authenticate, and treat your home network the way a company treats its own: nothing is trusted just for showing up.1

About this piece. This is part two of a five-part OcxlyDev field guide on building a home lab — the 10-layer stack, zero-trust networking, de-Googling with self-hosted apps, mini-PC hardware, and Infrastructure as Code with Ansible. Project names and hardware move quickly, so treat specifics as a snapshot rather than a fixed rule.

References

  1. NIST — Special Publication 800-207, "Zero Trust Architecture": the authoritative definition of the model
  2. Cloudflare Documentation — Cloudflare Tunnel: outbound-only connections with no open inbound ports
  3. Tailscale — "What is Tailscale?": a WireGuard-based zero-config mesh VPN with no exposed public ports
  4. Twingate — "How Twingate Works": zero-trust network access with least-privilege, per-resource access
  5. WireGuard — official site: the fast, modern, encrypted VPN protocol Tailscale is built on