{"id":887,"date":"2026-08-28T12:33:43","date_gmt":"2026-08-28T12:33:43","guid":{"rendered":"https:\/\/nnmaki.com\/?p=887"},"modified":"2026-09-23T13:03:32","modified_gmt":"2026-09-23T13:03:32","slug":"exposing-a-home-server-behind-cgnat-with-cloudflare-tunnel","status":"publish","type":"post","link":"https:\/\/nnmaki.com\/index.php\/2026\/08\/28\/exposing-a-home-server-behind-cgnat-with-cloudflare-tunnel\/","title":{"rendered":"Exposing a Home Server Behind CGNAT with Cloudflare Tunnel"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">A small homelab project in networking and Linux administration.<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">The problem<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Like a lot of home internet connections in Finland today, mine sits behind CGNAT (Carrier-Grade NAT) \u2014 my ISP doesn&#8217;t hand out a public IPv4 address to my router at all, which means the usual &#8220;forward a port and you&#8217;re done&#8221; approach for self-hosting simply isn&#8217;t available to me. No amount of port forwarding on my own router would help, because the public IP my traffic is exiting through is shared with hundreds of other customers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I wanted to take an old laptop, turn it into a proper Linux server, and make something on it reachable from the public internet \u2014 without paying for a VPS, without a static IP, and without opening a single inbound port.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_1_1920x1080.png.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" data-id=\"881\" src=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_1_1920x1080.png-1024x576.png\" alt=\"\" class=\"wp-image-881\" srcset=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_1_1920x1080.png-1024x576.png 1024w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_1_1920x1080.png-300x169.png 300w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_1_1920x1080.png-768x432.png 768w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_1_1920x1080.png-1536x864.png 1536w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_1_1920x1080.png.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_2_1920x1080.png.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" data-id=\"882\" src=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_2_1920x1080.png-1024x576.png\" alt=\"\" class=\"wp-image-882\" srcset=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_2_1920x1080.png-1024x576.png 1024w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_2_1920x1080.png-300x169.png 300w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_2_1920x1080.png-768x432.png 768w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_2_1920x1080.png-1536x864.png 1536w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_2_1920x1080.png.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_3_1920x1080.png.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" data-id=\"883\" src=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_3_1920x1080.png-1024x576.png\" alt=\"\" class=\"wp-image-883\" srcset=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_3_1920x1080.png-1024x576.png 1024w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_3_1920x1080.png-300x169.png 300w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_3_1920x1080.png-768x432.png 768w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_3_1920x1080.png-1536x864.png 1536w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_3_1920x1080.png.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The setup<br>Hardware: a repurposed old laptop<br>OS: Ubuntu Server<br>Web server: Nginx<br>Domain: a cheap domain purchased through Namecheap<br>DNS &amp; tunneling: Cloudflare (free tier) + cloudflared<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first deliverable was a landing page for the server itself \u2014 partly to have something real to test the pipeline against, partly as a bit of fun for the family. I built it as a static site (HTML\/CSS\/vanilla JS) with a playful, warm design, a live clock, and a couple of small interactive touches, themed loosely around our family name and our dog.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Getting around CGNAT: Cloudflare Tunnel<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of exposing a port on my router, I installed cloudflared on the server. It opens an outbound connection from my server to Cloudflare&#8217;s edge network \u2014 since it&#8217;s outbound, CGNAT is a complete non-issue. Cloudflare then proxies public requests for my domain through that tunnel back to Nginx running on localhost:80.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Stepps I have followed:<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Point the domain&#8217;s nameservers at Cloudflare.<\/li>\n\n\n\n<li>Install cloudflared on the Ubuntu server and authenticate it against my Cloudflare account.<\/li>\n\n\n\n<li>Create a named tunnel (cloudflared tunnel create), which generates a tunnel ID and a credentials file.<\/li>\n\n\n\n<li>Write an ingress configuration mapping a hostname to <a href=\"http:\/\/localhost:80\">http:\/\/localhost:80<\/a>, with a catch-all 404 rule at the end.<\/li>\n\n\n\n<li>Route DNS for the domain to the tunnel (cloudflared tunnel route dns) and install cloudflared as a systemd service so it survives reboots.<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">A couple of real-world snags worth mentioning, since this is where most of the actual learning happened.<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Ubuntu version mismatch in the package repo. My server runs a very recent Ubuntu release, and Cloudflare&#8217;s apt repository didn&#8217;t yet have a matching codename \u2014 apt update failed with a 404. The fix was to point the repo at the noble (24.04 LTS) codename instead, since cloudflared itself is a self-contained Go binary with no real dependency on the underlying distro version.<br>Conflicting DNS records. My domain registrar had already created a placeholder A record for a &#8220;parking page,&#8221; which blocked Cloudflare from creating the CNAME the tunnel needed. Deleting the stale record cleared the way.<br>sudo and home directories don&#8217;t mix well. Running cloudflared service install under sudo looks for its config under root&#8217;s home directory, not the user&#8217;s \u2014 so the config file I&#8217;d written to ~\/.cloudflared\/ was invisible to it. Moving the config and credentials file to \/etc\/cloudflared\/ (and updating the credentials-file path inside the config accordingly) resolved it.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_4_1920x1080.png.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" data-id=\"884\" src=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_4_1920x1080.png-1024x576.png\" alt=\"\" class=\"wp-image-884\" srcset=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_4_1920x1080.png-1024x576.png 1024w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_4_1920x1080.png-300x169.png 300w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_4_1920x1080.png-768x432.png 768w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_4_1920x1080.png-1536x864.png 1536w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_4_1920x1080.png.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_5_1920x1080.png.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" data-id=\"885\" src=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_5_1920x1080.png-1024x576.png\" alt=\"\" class=\"wp-image-885\" srcset=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_5_1920x1080.png-1024x576.png 1024w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_5_1920x1080.png-300x169.png 300w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_5_1920x1080.png-768x432.png 768w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_5_1920x1080.png-1536x864.png 1536w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_5_1920x1080.png.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_6_1920x1080.png.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" data-id=\"886\" src=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_6_1920x1080.png-1024x576.png\" alt=\"\" class=\"wp-image-886\" srcset=\"https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_6_1920x1080.png-1024x576.png 1024w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_6_1920x1080.png-300x169.png 300w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_6_1920x1080.png-768x432.png 768w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_6_1920x1080.png-1536x864.png 1536w, https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_6_1920x1080.png.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n\n\n<h5 class=\"wp-block-heading\">Locking it down<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">A publicly reachable web server is one thing, a publicly reachable SSH port is another. Rather than exposing SSH directly, I added a second ingress rule to the same tunnel, on a separate subdomain, pointing at ssh:\/\/localhost:22. On top of that, I&#8217;m layering Cloudflare Access so that reaching the SSH hostname requires an authenticated login (e.g. a one-time email code) before the tunnel will even proxy the TCP connection through. Combined with key-based SSH authentication on the server itself, this keeps remote administration usable without leaving a bare port open to the internet.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">What this demonstrates? Small project, but it touches a handful of things that come up constantly in real IT\/infrastructure work:<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Working comfortably in a Linux server environment via SSH, systemd, and apt<\/li>\n\n\n\n<li>Understanding NAT, CGNAT, and why traditional port-forwarding breaks down<\/li>\n\n\n\n<li>DNS management and troubleshooting (nameservers, record types, conflicting entries)<\/li>\n\n\n\n<li>Reverse-proxy concepts and outbound-only tunneling as an alternative to inbound exposure<\/li>\n\n\n\n<li>A basic zero-trust mindset: don&#8217;t expose services directly \u2014 broker access through an identity-aware layer instead<\/li>\n\n\n\n<li>Debugging by reading error messages carefully and reasoning about why a tool behaves the way it does (e.g. sudo and $HOME), rather than guessing<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">What&#8217;s next?<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Now that the tunnel is stable, the plan is to add more services behind it \u2014 a dashboard, some self-hosted tools, and eventually a proper reverse-proxy setup with multiple subdomains, each routed through the same tunnel with its own access policy.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A small homelab project in networking and Linux administration. The problem Like a lot of home internet connections in Finland [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":880,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[1],"tags":[],"class_list":["post-887","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"mb":[],"uagb_featured_image_src":{"full":["https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_fi_1200x675.png.png",1200,675,false],"thumbnail":["https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_fi_1200x675.png-150x150.png",150,150,true],"medium":["https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_fi_1200x675.png-300x169.png",300,169,true],"medium_large":["https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_fi_1200x675.png-768x432.png",768,432,true],"large":["https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_fi_1200x675.png-1024x576.png",1024,576,true],"1536x1536":["https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_fi_1200x675.png.png",1200,675,false],"2048x2048":["https:\/\/nnmaki.com\/wp-content\/uploads\/2026\/09\/homelab_fi_1200x675.png.png",1200,675,false]},"uagb_author_info":{"display_name":"NikoNmaki","author_link":"https:\/\/nnmaki.com\/index.php\/author\/nnmakicom2026\/"},"uagb_comment_info":0,"uagb_excerpt":"A small homelab project in networking and Linux administration. The problem Like a lot of home internet connections in Finland [&hellip;]","mfb_rest_fields":["title","uagb_featured_image_src","uagb_author_info","uagb_comment_info","uagb_excerpt"],"_links":{"self":[{"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/posts\/887","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/comments?post=887"}],"version-history":[{"count":7,"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/posts\/887\/revisions"}],"predecessor-version":[{"id":897,"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/posts\/887\/revisions\/897"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/media\/880"}],"wp:attachment":[{"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/media?parent=887"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/categories?post=887"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nnmaki.com\/index.php\/wp-json\/wp\/v2\/tags?post=887"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}