How to access Home Assistant and your internal network with Twingate. No port forwarding needed!

แชร์
ฝัง
  • เผยแพร่เมื่อ 26 มิ.ย. 2024
  • Use Twingate's simple setup to connect to your local network using the ZERO TRUST method. Keep your local network resources and only allow access to hosts and ports that need it--and to only those that need it.
    Discord: / discord
    If you would like to support me:
    Buy me a beverage: ko-fi.com/mostlychris
    Become a patron: / mostlychris
    Products I reference in my videos (Contains affiliate links)
    www.mostlychris.com/my-smart-...
    www.xsplit.com?ref=chriswest&discount=mostlychri&pp=stripe_affiliate
    DISCLAIMER: Some of the links above take you to affiliate sites that may or may not pay a small commission to me. It doesn't increase the cost to you, but it does help support me in making these videos.
    This video is sponsored by Twingate
    Snail Mail to Send Stuff:
    Mostlychris
    24165 IH-10 West
    STE 217 #164
    San Antonio, TX 78257
    00:00 Intro
    00:44 What is Twingate
    03:39 Home Assistant and Twingate
    05:41 Set up Twingate Connector
    07:49 Twingate Architecture Overview
    11:33 Add Local Resources
    13:14 Windows Twingate Client Setup
    16:20 Add Additional Resources
    17:07 Twingate FAQs
    18:02 Using Private Local DNS
    20:26 Home Assistant Companion App
    23:04 Private IP on Public DNS Servers
    24:07 Final Thoughts
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 39

  • @kal6392
    @kal6392 2 หลายเดือนก่อน

    Wow!! Great video. Thank you sir.

  • @ChrisValcke
    @ChrisValcke 2 ปีที่แล้ว

    can't wait to see you do the cloudflared alternative :)

    • @mostlychris
      @mostlychris  2 ปีที่แล้ว +1

      Lots of requests for that. I'll get on it.

  • @johnnynobels
    @johnnynobels 2 ปีที่แล้ว

    Hi Chris, Many thanks for sharing. I am happily using tailscale. Integration with home assistant seems much easier to me. I can advise that solution if users only need external access to home assistant.

    • @mostlychris
      @mostlychris  2 ปีที่แล้ว

      Tailscale is good as a VPN solution. Twingate is good for securing individual resources. I use them both.

  • @tokoiaoben3842
    @tokoiaoben3842 ปีที่แล้ว

    Great tutorial. Maybe this the solution for my SIP Clients to make calls over the Internet to our local PBX installed in our Office LAN. We have a bunch of SIP Client extensions in our LAN and I've been trying to setup port-forward for our remote branch offices to call our local extensions. I've not able to it setup with port-forward on my pfsense firewall.

  • @imranghafoor7639
    @imranghafoor7639 2 ปีที่แล้ว

    Hi
    I am completely new to HA and not too technically minded. I watched so many tutorials to help me get setup. I have to say I love your videos, they are so easy to follow and you always explain everything so clearly.
    I am running ha as x86 image on a laptop so I don't think I can run twingate on this. The only other always on device at home is an android tablet. Is it possible to setup twingate on android or what would you recommend as the easiest remote access solution in this situation? I don't really want to go the paid nabu casa route yet as I am just starting and don't actually have that much use for it.
    Thanks

    • @mostlychris
      @mostlychris  2 ปีที่แล้ว

      I have a video coming out very soon (as of this comment) that has my top 5 connection options for Home Assistant. Give that a watch (subscribe so you get notified).

  • @Shaq2k
    @Shaq2k ปีที่แล้ว

    Hi. Do you still use this yourself?

  • @jmr
    @jmr 2 ปีที่แล้ว

    You didn't overcomplicate it IMHO. I really like what I see so far. A little more research before I decide whether to set it up.
    EDIT: Not sure if you did Cloudflare Tunnel but that would be a good way to round out this "series"?

    • @mostlychris
      @mostlychris  2 ปีที่แล้ว

      Thanks for the feedback. I can get "wordy" sometimes! I have not done anything with the Cloudflare stuff other than my original video a few weeks ago. I do have it listed on my idea page though.

    • @jmr
      @jmr 2 ปีที่แล้ว

      @@mostlychris Cloudflare Tunnel looks great for HA since it doesn't require an extra application running on the end users device with the one caveat it requires a domain. I already hear grumbling in the comments. 🤣 Another possible idea would be a comparison of some of the options. I've seen a few questions over "Why this way".

    • @mostlychris
      @mostlychris  2 ปีที่แล้ว

      Good points. Maybe everyone should just register a domain just in case they want to do something with it in the future 😉

  • @fredamn76
    @fredamn76 2 ปีที่แล้ว +3

    Has Twingates service been security audited?

    • @Twingate
      @Twingate 2 ปีที่แล้ว +4

      Hi there, we have SOC2 and you can access our security white paper here lp.twingate.com/hubfs/White%20Papers/Twingate-Security-Whitepaper.pdf

    • @mostlychris
      @mostlychris  2 ปีที่แล้ว +1

      Thanks for the question fedamn76 and thanks Twingate for the answer!

  • @wildlifeamateur
    @wildlifeamateur 2 ปีที่แล้ว

    no https if you open homeassistant true twingate? is it not insecure?

    • @jmr
      @jmr 2 ปีที่แล้ว

      That's a good question. I suspect all the encryption is handled by client app on the device. It's likely agnostic as to whether it passes http or https the same as a VPN. The big question would be whether it gets decrypted in the Twingate servers. You could probably just use https on top of this solution.

    • @krdesigns
      @krdesigns 2 ปีที่แล้ว +1

      you are connecting via home network so https not necessary required. The connection between twingate on the other hand is secure since its require token. So that should be the explanations. BTW why not use nabucasa instead? much easier hahahahahaha

    • @mostlychris
      @mostlychris  2 ปีที่แล้ว +2

      Twingate creates a TLS tunnel between the client device and the remote network so even if your HA is not SSL encrypted, the traffic is flowing over an encrypted layer between your client and the remote network.

    • @wildlifeamateur
      @wildlifeamateur 2 ปีที่แล้ว +1

      @@mostlychris Thank you.

  • @theLEFTY15
    @theLEFTY15 2 ปีที่แล้ว +4

    What’s the difference between this and Tailscale? Tailscale seems much easier to set up. Curious why choose this over the other?

    • @redstormsju777
      @redstormsju777 2 ปีที่แล้ว

      I’m thinking the same. It even seems very similar

    • @jmr
      @jmr 2 ปีที่แล้ว

      I'm now looking at Cloudflare Tunnel. It's also very similar.

    • @jmr
      @jmr 2 ปีที่แล้ว +6

      I just looked up Tailscale. That's a VPN. From what I see the big difference is Twingate has the ability to restrict what resources the client has access to by user group. You could restrict access to specific ports and IP addresses in the network. For instance you may want to access the whole network as an admin but only give access to HomeAssistant or Plex to other users. Unless I missed something every device you log into Tailscale has access to ever other device you log in just like they are on the same network.

    • @theLEFTY15
      @theLEFTY15 2 ปีที่แล้ว +1

      @@jmr I see! This is a great information. That makes sense and I do see the value of specific ip certain access. That's quite cool for sure.

    • @mostlychris
      @mostlychris  2 ปีที่แล้ว +1

      Tailscale is a VPN solution, albeit a zero config vpn. Twingate is a resource access option that allows you to make very specific resource ACLs for stuff inside a remote network.

  • @SanjayAroraIN
    @SanjayAroraIN ปีที่แล้ว

    What stops Twingate itself from being the Man in the Middle attacker?

    • @mostlychris
      @mostlychris  ปีที่แล้ว

      Anything can happen. Company reputations are built on trust so if Twingate does something to lose consumer trust, it'll be reflected in their business. Also, each person has to make choices based on their personal comfort level with security.

  • @oneito947
    @oneito947 2 ปีที่แล้ว

    shouldnt zero trust security solutions be self hosted

    • @mostlychris
      @mostlychris  2 ปีที่แล้ว

      Depends. Whatever you use, you need to research it. Twingate has a white paper on their security posture so one can have an understanding of any risks that might be associated with the platform.

  • @we300b
    @we300b 2 ปีที่แล้ว

    disadvantage is slow !!!!

    • @mostlychris
      @mostlychris  2 ปีที่แล้ว +1

      Slow how? I was fast in the testing I did.