# Accessing node-RED using local IP

**URL:** <https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105>\
**Category:** General\
**Created:** [23 January 2022 17:46 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105 "2022-01-23T17:46:34Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [23 January 2022 17:46 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/1 "2022-01-23T17:46:34Z")

</div>

Is this expected behaviour?

Running script installed node-RED on a Raspberry Pi, and serving a public page via HTTPS using LetsEncrypt certificates.

When I'm generally working in node-RED, I access NR by `https://mydomain.co.uk:8443`, but if I access via it's local IP address instead - `http://192.168.0.8:8443`, the browser responds;

```auto
This page isn’t working
192.168.0.8 didn’t send any data.
ERR_EMPTY_RESPONSE

```

However, if I use the url - `https://192.168.0.8:8443` it does connect OK, albeit the browser complaining that the certificate is not valid, which is understandable because the certificate was issued for the domain name, and not an IP address.  
 ![url](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/2/0/201aad0b7d9669e60adfc98bebe568e46dd71504.jpeg)

In node-RED settings I have `requireHttps: false,` so I expected that I would be able to connect using `http://192.168.0.8:8443` ??

---

<div class="post-metadata">

**Author:** ![MaddyP](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/maddyp/32/53046_2.png) [@MaddyP](https://discourse.nodered.org/u/MaddyP)\
**Post date:** [23 January 2022 18:35 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/2 "2022-01-23T18:35:30Z")

</div>

HTTP and HTTPS use two different ports, 80 and 443 respectively.

Do you have a proxy setup or using Node-Red setting for ssl?

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [23 January 2022 18:45 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/3 "2022-01-23T18:45:16Z")

</div>

External traffic is accessed via Cloudflare using full (strict) end to end encryption proxy.  
But I am using node-RED to setup SSL. The certificates are stored in `.node-red/certs` and are loaded in the `settings.js` file.

---

<div class="post-metadata">

**Author:** ![MaddyP](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/maddyp/32/53046_2.png) [@MaddyP](https://discourse.nodered.org/u/MaddyP)\
**Post date:** [23 January 2022 18:51 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/4 "2022-01-23T18:51:42Z")

</div>

Try accessing the http address with port 8080 instead of 8443. 8443 is reserved for HTTPS and won’t autoforward your HTTP to 8080 without a proxy.

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [23 January 2022 19:27 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/5 "2022-01-23T19:27:03Z")

</div>

> [@Paul-Reed](#):
>
> In node-RED settings I have `requireHttps: false,` so I expected that I would be able to connect using `http://192.168.0.8:8443` ??

In the commented out section of the settings.js file

```auto
  // The following property can be used to cause insecure HTTP connections to
  // be redirected to HTTPS.
  //requireHttps: true,

```

i dont know if this setting is deprecated but from what i understand from the comment is that  
if `requireHttps` its set to `true` and you try to visit `http://192.168.0.8:8443` and you have https enabled, you should be redirected to the secure `https://192.168.0.8:8443`.

I dont think that it keeps any other ports open .. the port is whatever port you defined in  
`uiPort: process.env.PORT || 1880,`

if `requireHttps` is `false` as it is in your case, then its not going to redirect

ps. its not mentioned in the [docs](https://nodered.org/docs/user-guide/runtime/configuration) .. possibly it doesnt apply for new versions of NR

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [23 January 2022 19:36 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/6 "2022-01-23T19:36:37Z")

</div>

> [@UnborN](#):
>
> what i understand from the comment is that  
> if `requireHttps` its set to `true` and you try to visit `http://192.168.0.8:8443` and you have https enabled, you should be redirected to the secure `https://192.168.0.8:8443`

Yes, that's my understanding, but is this normal that node-RED installations using SSL, cannot make a connection on their local network without prefixing the local IP address with `https` (which then in turn upsets the browser because the certificate was not issued to an IP address)?

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [23 January 2022 19:55 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/7 "2022-01-23T19:55:13Z")

</div>

so we put Cloudflare to the side  
if you setup Node-red to be secure then its the only way to connect. no ?  
which you said you can with `https://192.168.0.8:8443` (local)  
sorry i didnt undestand what you expected to happen 😉  
you wanted to just type the ip and the port without prefixing https and it knows that its secure and goes there ?  
interesting question .. happens to my system too  
(possibly thats why that redirect setting was there in the first place)

im pretty new to this security stuff .. im interested to know also

---

<div class="post-metadata">

**Author:** ![MaddyP](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/maddyp/32/53046_2.png) [@MaddyP](https://discourse.nodered.org/u/MaddyP)\
**Post date:** [23 January 2022 20:08 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/8 "2022-01-23T20:08:03Z")

</div>

It seems something else is going on here, maybe on the Cloudflare side since it is accessible through the standard 8443 (HTTPS) port. If access via HTTPS is available on 8443 then HTTP should be accessible via 8080 unless there is another process redirecting / blocking traffic.

I'm not sure how Node-Red is handling the SSL cert, maybe a middleware which directs traffic?

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [23 January 2022 22:08 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/9 "2022-01-23T22:08:24Z")

</div>

Paul, considering your requirements, I think a proxy like nginx or haproxy would better suit your needs.

You'd set-up node-red as default (http) and use the proxy as a gateway (Https on the wan side, http on the LAN side)

That way, when you are on the LAN side, you can connect to the LAN IP on http or the wan domain name on https.

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [23 January 2022 23:03 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/10 "2022-01-23T23:03:36Z")

</div>

Thanks Steve  
I'm going to rebuild the system in the near future, so that's something that I'll read into, and try & implement.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [23 January 2022 23:28 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/11 "2022-01-23T23:28:44Z")

</div>

Some great info in this post...

> [@Node-red server with nginx reverse proxy howto guide](https://discourse.nodered.org/t/node-red-server-with-nginx-reverse-proxy-howto-guide/27397):
>
> Navigatable version on github [https://github.com/meeki007/node-red-server-howto-guide/blob/master/README.md](https://github.com/meeki007/node-red-server-howto-guide/blob/master/README.md) Ubuntu 20.04 - nigix - https - ssl - security - Fail2ban 403 bans, etc Table of Contents [Introduction](#Introduction)[Setup\_Server](#Setup_Server)[Creating\_a\_new\_privileged\_user\_account](#Creating_a_new_privileged_user_account)[Update\_Server](#Update_Server)[Enable\_a\_firewall](#Enable_a_firewall)[Install\_Fail2ban](#Install_Fail2ban)[Node-red](#Node-red)[build-essential](#build-essential)[nod-red\_script](#nod-red_script)[Autostart\_on\_boot](#Autostart_on_boot)[Hosting\_to\_the\_world](#Hosting_to_the_world)[Install\_Nginx](#Install_Nginx)[DNS](#DNS)[Reverse\_proxy](#Reverse_proxy)[HTTPS\_SSL\_certbot](#HTTPS_SSL_certbot)[Security](#Security)[adminAuth\_user\_password](#HTTPS_SSL_certbot)[fail2ban\_4…](#fail2ban_403_protection)

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [24 January 2022 05:53 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/12 "2022-01-24T05:53:33Z")

</div>

Paul,  
Indeed like Steve said, a proxy is better and much secure.  
But if - for some reason you don't have that yet - you can cheat a bit, like I do:

- First I had added the mapping from myDomain to myRaspberryIp in the [hosts file](https://www.nublue.co.uk/guides/edit-hosts-file/) of my Windows portable (in order to be able to experiment with Letsencrypt). But then it only worked on that computer.
- Later on I had moved that my mapping to the DNS Resolver section of my router. So now it works fine for all devices (Android, Windows, ...): they all connect to Node-RED via https with Letsencrypt certificates within my LAN...

So you navigate within your LAN to myDomain, but you will be redirected to your Raspberry. However since your browser has navigated to myDomain, he will receive a LetsEncrypt certificate that matches myDomain. Which means your browser will not complain anymore...

Bart

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [24 January 2022 10:24 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/13 "2022-01-24T10:24:23Z")

</div>

Thanks @Steve-Mcl @meeki007  
I think that guide was specifically written for Ubuntu, so may not strictly apply for a Pi.  
It may however help guide me in the right direction.

---

<div class="post-metadata">

**Author:** ![meeki007](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/meeki007/32/12499_2.png) [@meeki007](https://discourse.nodered.org/u/meeki007)\
**Post date:** [24 January 2022 11:38 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/14 "2022-01-24T11:38:09Z")

</div>

It should work for Pi as well as its Debian based distro but not the section on `automatic_increasing_ban_times` as this was part of the new fail to ban package for 20.04

Also for getting you password hash section `adminAuth_user_password` as you can now just use the command in terminal

```auto
$ node-red admin hash-pw yourPasswordhere

```

no need to use the bcryptjs node anymore

Good luck m8

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [7 February 2022 11:39 UTC](https://discourse.nodered.org/t/accessing-node-red-using-local-ip/57105/15 "2022-02-07T11:39:01Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
