# Remote Access for my dashboard

**URL:** <https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161>\
**Category:** Dashboard\
**Created:** [19 February 2019 19:38 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161 "2019-02-19T19:38:21Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefano.m](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@stefano.m](https://discourse.nodered.org/u/stefano.m)\
**Post date:** [19 February 2019 19:38 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/1 "2019-02-19T19:38:21Z")

</div>

Hi everybody , and thanks for your attention.  
I'm new for Node-Red , and I have a "little" question for you.

I've made a temperature reader with my raspi and a DHT22,and I've made a dashboard with a gauge to read the temperature in my room.  
Now,I am reading the value in internet through my router "natting" the 1880 port .Previously I've a DDNS service to convert my public IP to a DNS.  
I've read here this file on github : [https://github.com/node-red/cookbook.nodered.org/wiki/How-to-safely-expose-Node-RED-to-the-Internet](https://github.com/node-red/cookbook.nodered.org/wiki/How-to-safely-expose-Node-RED-to-the-Internet) and some other stuff on this forum , and I've understand that I need one of this things:

1-Cloud  
2-VPN pi to Host  
3-TeamViewer or VNC  
4-Something like webhookrelay

What is the best , secure and free , service to start to study ?  
I am afraid to publish my raspi on internet .

Thank you very much for the attention and for the help.  
Your Stefano  
Rome (ITALIA)

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [19 February 2019 21:09 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/2 "2019-02-19T21:09:25Z")

</div>

There is no 'best' answer.  
I use a home built vpn which can run in the node-red pi or in another pi. That gives me reasonably secure access to my network from anywhere. If you want to try that I wrote up how to do it.  
[http://blog.clanlaw.org.uk/pi-vpn-server.html](http://blog.clanlaw.org.uk/pi-vpn-server.html)

---

<div class="post-metadata">

**Author:** ![stefano.m](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@stefano.m](https://discourse.nodered.org/u/stefano.m)\
**Post date:** [19 February 2019 21:24 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/3 "2019-02-19T21:24:56Z")

</div>

Thank you Colin , I know there is no best answer ... but I have to start somewhere ...  
Now I'm going to study what you have post , thank you again for your help.

Your Stefano  
Rome (ITALIA)

---

<div class="post-metadata">

**Author:** ![zenofmud](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/zenofmud/32/316_2.png) [@zenofmud](https://discourse.nodered.org/u/zenofmud)\
**Post date:** [19 February 2019 23:41 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/4 "2019-02-19T23:41:41Z")

</div>

@Colin Did you miss my two messages about your VPN writeup?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [20 February 2019 07:14 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/5 "2019-02-20T07:14:05Z")

</div>

@zenofmud Apparently I did miss your messages. Where?

---

<div class="post-metadata">

**Author:** ![zenofmud](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/zenofmud/32/316_2.png) [@zenofmud](https://discourse.nodered.org/u/zenofmud)\
**Post date:** [20 February 2019 10:18 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/6 "2019-02-20T10:18:54Z")

</div>

Private messages

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [20 February 2019 10:26 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/7 "2019-02-20T10:26:45Z")

</div>

No I did not notice those, I did not get a notification. I will reply there.

[Edit], in fact that is rather embarrasing, I see I have a number of messages that I had not noticed. Presumably somehow I can get a notification when they come in.

---

<div class="post-metadata">

**Author:** ![stefano.m](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@stefano.m](https://discourse.nodered.org/u/stefano.m)\
**Post date:** [20 February 2019 13:30 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/8 "2019-02-20T13:30:42Z")

</div>

Hi Colin , I've read your website and I'm moving to study VPN on Raspberry (open VPN) ... it isn't not simple for me I think but anyway ... I will try... thank you.

Your Stefano  
Rome(ITALIA)

---

<div class="post-metadata">

**Author:** ![stefano.m](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@stefano.m](https://discourse.nodered.org/u/stefano.m)\
**Post date:** [20 February 2019 21:02 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/9 "2019-02-20T21:02:41Z")

</div>

Good evening ,I was reflecting if the shortest way , for now, is to take a SSL cerificate for my DDNS service .  
In practice I would have to generate a csr from the raspberry in order to provide it to those who provide me with the SSL certificate.  
At that point I would have an https connection.  
What do you think ?

Thanks

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [20 February 2019 21:46 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/10 "2019-02-20T21:46:42Z")

</div>

You can use Let's Encrypt if you need a cert as long as you have a domain on a DNS that you can control.

> **[How to create secure certificates](https://it.knightnet.org.uk/kb/nr-qa/https-valid-certificates/)**
>
> Generate certificates for Node-RED that are trusted by all modern browsers. This will let you access Node-RED (and other services) over an encrypted HTTPS link.

---

<div class="post-metadata">

**Author:** ![ghayne](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ghayne/32/39_2.png) [@ghayne](https://discourse.nodered.org/u/ghayne)\
**Post date:** [20 February 2019 22:48 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/11 "2019-02-20T22:48:22Z")

</div>

[http://www.pivpn.io/](http://www.pivpn.io/)

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [21 February 2019 09:10 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/12 "2019-02-21T09:10:18Z")

</div>

Unfortunately it seems pivpn is no longer maintained

> **[pivpn/pivpn](https://github.com/pivpn/pivpn)**
>
> Simple OpenVPN installer, designed for raspberry pi. - pivpn/pivpn

---

<div class="post-metadata">

**Author:** ![ghayne](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ghayne/32/39_2.png) [@ghayne](https://discourse.nodered.org/u/ghayne)\
**Post date:** [21 February 2019 09:45 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/13 "2019-02-21T09:45:21Z")

</div>

> [@Colin](#):
>
> Unfortunately it seems pivpn is no longer maintained

Oh, that is sad. It worked very well for me. I'm off to study your guide then Colin 🙂

---

<div class="post-metadata">

**Author:** ![Keptenkurk](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/keptenkurk/32/3789_2.png) [@Keptenkurk](https://discourse.nodered.org/u/Keptenkurk)\
**Post date:** [22 February 2019 07:04 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/14 "2019-02-22T07:04:47Z")

</div>

I'm using a NGINX reversed proxy with SSL on a second Pi. It handles authentication and encryption for all servers in the home network i would like to expose to the outside.  
\paul

---

<div class="post-metadata">

**Author:** ![stefano.m](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@stefano.m](https://discourse.nodered.org/u/stefano.m)\
**Post date:** [22 February 2019 13:26 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/15 "2019-02-22T13:26:09Z")

</div>

Thank you Paul , but why you don't use only one rasp with ngnix installed , for security ?

S.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [22 February 2019 15:09 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/16 "2019-02-22T15:09:57Z")

</div>

Local security will be improved only if the 2 pi's use different user ids and passwords (which would prevent someone/thing that has successfully broken into the Pi running NGINX from working sideways to the other Pi).

However, it may well be that he has done it simply to spread the resource load over the 2 devices.

---

<div class="post-metadata">

**Author:** ![stefano.m](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@stefano.m](https://discourse.nodered.org/u/stefano.m)\
**Post date:** [22 February 2019 15:19 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/17 "2019-02-22T15:19:43Z")

</div>

In fact it was what I supposed ...  
Thank you  
S.

---

<div class="post-metadata">

**Author:** ![DefProc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/defproc/32/1080_2.png) [@DefProc](https://discourse.nodered.org/u/DefProc)\
**Post date:** [22 February 2019 17:37 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/18 "2019-02-22T17:37:59Z")

</div>

My go-to option at the moment is to use [Zerotier](https://www.zerotier.com/), installed on both devices and linked to the same private network space, to make a RPi remotely accessible.

---

<div class="post-metadata">

**Author:** ![thatcadguy](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/thatcadguy/32/5273_2.png) [@thatcadguy](https://discourse.nodered.org/u/thatcadguy)\
**Post date:** [22 February 2019 22:55 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/19 "2019-02-22T22:55:00Z")

</div>

If you want to go the VPN route: check your home router, it might have VPN capabilities built-in. If you're the only one who's going to use this, you could use static-key encryption (doesn't require a certificate), which you can get up and running in minutes: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)

PiVPN is based on OpenVPN, which is definitely still maintained and isn't terribly difficult to get running.

If you don't want to do VPN, I'd do this:

1. Pick a random high number port for your router to forward to port 1880 on your Pi
2. Get an SSL cert either from Let's Encrypt (can be a pain) or just make a self-signed one using a tool like mkcert (you'll get security errors in some browsers, but it's still secure)
3. Enable https by filling out that section in settings.js
4. Also enable adminAuth, httpNodeAuth, and httpStaticAuth security measures in settings.js

[https://nodered.org/docs/security](https://nodered.org/docs/security)

HTH

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [22 February 2019 23:05 UTC](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161/20 "2019-02-22T23:05:12Z")

</div>

> [@thatcadguy](#):
>
> Let's Encrypt (can be a pain)

Not really a pain any more.

> **[How to create secure certificates](https://it.knightnet.org.uk/kb/nr-qa/https-valid-certificates/)**
>
> Generate certificates for Node-RED that are trusted by all modern browsers. This will let you access Node-RED (and other services) over an encrypted HTTPS link.

[Next page](https://discourse.nodered.org/t/remote-access-for-my-dashboard/8161.md?page=2)
