17

I wanted to improve the security of a TV connecting to a server on a different LAN, and one approach I thought of is to use a RPi on the network to look after the secure connection.

So the pi could connect to the remove server through SSH, and forward the port locally. I thought this port could then be opened, and the TV can then be pointed at the pi on the local network.

Port forwarding to the pi works but I can't connect to it from another device, even after setting firewall settings.

Basically the firewall rule is ufw allow from 192.168.1.0/24 port 1234

Does this idea work, or is there a better approach? Am I missing something in the setup?

you are viewing a single comment's thread
view the rest of the comments
[-] habitualTartare@lemmy.world 2 points 7 hours ago

Are you connecting from a public network or something? like a hotel wifi or other?

The easiest solution would be to setup the pi as your router and use a VPN like wireguard (wg-easy) or tailscale.

if it is a public network, you can double NAT. There's dedicated boxes like the GL.inet travel routers that support wireguard/openVPN and beta for tailscale. they have some features that work well with captive portals.

If it's a home network, you can probably use your PI as a entry/exit node or VPN client instead of using ssh.

[-] eyesaremosaics@lemmy.zip 1 points 1 hour ago

It's for a home network, I managed to get it working using port forwarding through SSH thanks to suggestions. I'm not sure what the difference is with using the pi as an entry/exit node, that is what I was trying to do with the SSH forwarding. VPN is also possible but it it would also need to be set up to go through the pi

this post was submitted on 16 Jun 2026
17 points (100.0% liked)

Selfhosted

59923 readers
535 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam.

  3. Posts here are to be centered around self-hosting. Please ensure it is clear in your post how it relates to self-hosting.

  4. Don't duplicate the full text of your blog or git here. Just post the link for folks to click.

  5. Submission headline should match the article title.

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS