Hi,
I an currently trying to add remote access to 2 of my servers but didn’t manage to get a working setup as is.
Right now I want to access 2 servers:
- one is for media stuff (navidrome, jellyfin, managing the arr stack)
- one is for my data syncing with rsync and after set a backup from borg to another server not on my domain
I was trying at some point to add stuff such as tailscale, but somehow I always had issues with having both servers reachable within the IP range I use on my local network, so everything would work as is with the current config at home being away. I have also heard of cloudflare tunnels as well, but that I didn’t try yet. At some point I tried to do just a regular wireguard from my opnsense, but I would prefer not to have open ports to worry about (and also had issues with internal IP not being assigned from wireguard as well).
Does anyone here has experience with this? If so, what was your solution and/or caviats to it?
EDIT: I got some very good responses but I think I failed to understand that what I would need is probably a hop in server of sorts for the VPN. Meaning:
- I login to the hop server
- I get an internal IP for my network, meaning, 192.168.1.xxx
- I do whatever I need to do
- log out
Does anyone has experience with such solution? My point would be able to have full access to everything on the network without having to do a VPN on every machine i need access to (although it can create a massive single point of failure/risk)


I get what you’re saying, but how exactly the whole IP rotation is done in your case? How did you manage to have it accessible at all times even when your home IP changes? In my home I actually have ipv6 which I am not sure if it does not make things more difficult
DDNS (Dynamic DNS), one 3rd party service I do use.
My network is reached by URL, not IP (although IP still works). When my IP changes the router updates the DDNS service in minutes. Lots of providers out there and it’s easy to switch if needed. I like DuckDNS. It’s free or you can choose to donate a bit to cover their expenses.
Can also check one more time wireguard directly. Thanks!