# Web Server - for my customers?

**URL:** <https://discourse.nodered.org/t/web-server-for-my-customers/95828>\
**Category:** General\
**Created:** [6 March 2025 14:39 UTC](https://discourse.nodered.org/t/web-server-for-my-customers/95828 "2025-03-06T14:39:54Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [6 March 2025 19:46 UTC](https://discourse.nodered.org/t/web-server-for-my-customers/95828/4 "2025-03-06T19:46:21Z")

</div>

> [@thebaldgeek](#):
>
> I think most here would recommend a VPN only access for your customers

👆

Always!!!

Node RED - is a target for hackers, so please use the strongest/safest methods possible.

If you search these forums - you will find many (unfortunate) stories of Node RED being hacked, and by extension - the systems it is attached to.

Its not a weakness of Node RED - more so the user implementing it, and foolishly exposing it to the public, without implementing the correct security measures.

See : [Safely accessing Node-RED over the Internet](https://discourse.nodered.org/t/safely-accessing-node-red-over-the-internet/45024)

In essence - Don't open Port 1880, and instead create a tunnel for specific source connections.

---

_[View the full topic](https://discourse.nodered.org/t/web-server-for-my-customers/95828)._
