WireGuard VPN: Private Home Access Without Exposing Your HA Panel
WireGuard is a free, modern VPN protocol that puts your phone virtually back on your home network, rather than exposing Home Assistant to the internet at all. This lesson covers what's needed, where to run it, and its one real limitation: CGNAT.
What this lesson doesn't do
This lesson doesn't provide router-specific click-by-click instructions, every router and every WireGuard add-on's interface differs slightly, and this lesson instead gives you the concepts and the general flow so any specific instructions you find make sense. It doesn't cover Tailscale, WireGuard's easier CGNAT-friendly cousin, that's Lesson 4 immediately after this one. Its job is explaining what a VPN actually does for Home Assistant specifically, and helping you decide honestly whether it's the right fit before you invest the setup time.
What a VPN means in the context of Home Assistant
A VPN, Virtual Private Network, creates an encrypted tunnel between your phone or laptop and your home network, making your device behave as though it's physically plugged in at home, regardless of where you actually are. Unlike Nabu Casa or Cloudflare Tunnel, which expose Home Assistant itself to the internet through a controlled, encrypted path, a VPN takes the opposite approach entirely, it exposes nothing, your Home Assistant server never becomes reachable from the public internet at all, only from devices that have successfully joined your private VPN tunnel first.
VPN versus Nabu Casa: a genuinely different model
With Nabu Casa, you reach Home Assistant specifically and only Home Assistant, through a dedicated, purpose-built address. With a VPN, once connected, your device sees your entire home network, printer, NAS, other smart home devices, exactly as if you'd walked in the front door, and you reach Home Assistant the normal way, homeassistant.local:8123, because to your device, you're effectively home. This is both the VPN's biggest strength, one setup gives you everything, not just Home Assistant, and its biggest tradeoff, it requires more setup and understanding than Nabu Casa's two-click activation from the previous lesson.
What you need before starting
Setting up WireGuard requires three things: a normal, non-CGNAT public IP address, or a router that supports UPnP or manual port forwarding for the VPN's own port, a WireGuard server running somewhere on your network, and a WireGuard client app installed on each device you want connecting remotely. Unlike the integrations and add-ons covered so far in this course, this is the first genuinely networking-heavy setup in this module, worth budgeting a bit more time and patience for than Nabu Casa's setup took in the previous lesson.
Where to run WireGuard
You have real choices here. Many consumer routers, including several popular models covered generally in Module 2, include built-in WireGuard server support directly in their admin interface, often the simplest option since port forwarding happens automatically as part of enabling it. On HAOS, a WireGuard add-on is available from the Add-on Store, following the same install-and-configure pattern from Module 6. On Container, a small dedicated WireGuard Docker container works well alongside your existing setup. Running it on your router specifically has one genuine advantage worth knowing, it gives connected VPN clients access to your entire home network by design, exactly matching the LAN-equivalent behavior this lesson has been describing.
How the flow actually works
Setting up WireGuard generally follows the same shape regardless of where you run the server: generate a server configuration with its own cryptographic keys, generate one client configuration per device you want connecting, each with its own separate keys, install the WireGuard app on that device and import its configuration, usually by scanning a QR code the server generates, and forward the VPN's chosen port, commonly a random high port rather than anything predictable, through your router if it isn't running there directly. Once connected, toggling the VPN on in the app puts your device virtually on your home network within seconds, and toggling it off returns you to normal internet access exactly as before.
When to choose a VPN
A VPN is the right choice if you want access to your entire home network, not just Home Assistant, if you're comfortable with a bit more setup in exchange for zero recurring cost, if you have a normal public IP or a router that handles port forwarding cleanly, or if you specifically want your traffic staying entirely within infrastructure you control rather than routed through any third-party service. Readers with some general networking comfort, or anyone who's already set up a VPN for another purpose, will likely find WireGuard specifically the fastest and most modern option among the free choices.
When not to choose a VPN
If you're behind CGNAT, classic WireGuard alone genuinely cannot work, there's no public IP for the port forward to attach to, no matter how carefully you configure it, skip straight to Lesson 4's Tailscale instead. If the setup steps in this lesson feel like more than you want to take on, Nabu Casa's two-click activation from Lesson 2 remains a completely reasonable choice, there's no requirement to use every method in this module. And if you only ever want Home Assistant specifically, not your whole network, a purpose-built option like Nabu Casa or Cloudflare Tunnel is arguably a cleaner fit for that narrower goal.
WireGuard's security model
WireGuard is built around modern, well-reviewed cryptography and a deliberately small codebase, widely regarded by security researchers as one of the most trustworthy VPN protocols available today, a significant part of why this course recommends it over older alternatives like OpenVPN. Each device's client configuration contains a unique private key, and only devices holding a matching, explicitly authorized key can join your VPN at all, unlike a password that could theoretically be guessed or brute-forced, WireGuard's cryptographic keys make unauthorized access considerably harder in practice. Treat each device's configuration file the same way you'd treat a password, never share it, and revoke it from the server immediately if a device is ever lost or replaced.
VPN access for the rest of the household
Each device needs its own separate client configuration, generated individually rather than shared, exactly the same discipline WireGuard's security model asks for. This means setting up a VPN for a household of four means generating and distributing four separate configurations, one per phone, a bit more upfront effort than Nabu Casa's single subscription covering every family member automatically, but with the advantage that each configuration can be individually revoked later without affecting anyone else's access, useful if a family member's phone is ever lost.
Honestly, about CGNAT
This lesson has mentioned CGNAT several times deliberately, because it's genuinely the single most common reason WireGuard setups fail for readers of this course, and it's worth being direct about it here rather than burying it. If Lesson 1's CGNAT check showed your public IP differs between your router and an external site, classic WireGuard as described in this lesson will not work, full stop, no configuration change fixes it, since the fundamental problem is that no inbound connection can reach your router at all. This isn't a failure of your setup, it's a structural limitation of the network your ISP provides, and Lesson 4's Tailscale exists specifically to solve exactly this situation using the same underlying WireGuard protocol.
The VPN's own port: don't confuse it with 8123
The port you forward for WireGuard is entirely separate from Home Assistant's port 8123 from Lesson 1, and this distinction trips people up occasionally. You're forwarding traffic to your VPN server, not to Home Assistant directly, and only after the VPN connection is successfully established does your device reach Home Assistant on port 8123, now as if it were on your local network. Forwarding port 8123 itself would defeat the entire purpose of this lesson, that's the exact port forwarding this course steered away from back in Lesson 1.
VPN and other services at home
Because a VPN puts your device on your whole home network rather than just Home Assistant, it's genuinely useful beyond this course's scope too, reaching a NAS, a printer, or any other self-hosted service at home the exact same way. This is a real advantage worth weighing if you already run or plan to run other services beyond Home Assistant, one VPN setup covers everything, rather than needing a separate remote access solution per service the way Nabu Casa's Remote UI is scoped specifically to Home Assistant alone.
Common questions
Where do I find setup instructions for my specific router? Search your router model plus "WireGuard setup," most popular consumer router brands publish official guides. What if my router doesn't support WireGuard at all? Run it on HAOS as an add-on or Container as a small dedicated container instead, both work identically from the client's perspective. Does a VPN slow down my connection? Modern WireGuard adds genuinely negligible overhead for typical Home Assistant use, dashboards and control commands, you're very unlikely to notice any real difference in practice.
Where to find instructions for your specific hardware
Because router interfaces and add-on interfaces genuinely vary, this lesson intentionally stayed at the conceptual level rather than walking through one specific vendor's exact menus, which would be outdated or wrong for a meaningful share of readers. Your router manufacturer's own support site is the most reliable source for router-based setup, and the WireGuard add-on's own documentation page, reached from its listing in the Add-on Store, covers the HAOS route in detail. Both sources will make far more sense now that this lesson has covered the underlying concepts, servers, clients, keys, ports, they're built on.
Testing once you have a VPN running
Once set up, the real test is turning off your phone's WiFi entirely, connecting through mobile data alone, enabling the VPN, and confirming homeassistant.local:8123 or your server's local IP loads exactly as it would at home. If it does, your VPN is genuinely working end to end, and you now have full remote access to your entire home network, not just Home Assistant, using free, self-hosted infrastructure you control completely and entirely on your own terms.
A decision matrix: is a VPN for me
Not behind CGNAT, comfortable with a bit more setup, want access to more than just Home Assistant, and don't want a subscription: WireGuard is likely your best fit. Behind CGNAT but everything else applies: skip to Tailscale in Lesson 4, same protocol, different transport. Want the simplest possible setup and don't mind paying: Nabu Casa from Lesson 2 remains hard to beat. There's no wrong answer here, only the option that genuinely matches your actual situation, your CGNAT status, and your patience for setup.
A short exercise before moving on
If you're not behind CGNAT and WireGuard appeals to you, check whether your router has built-in WireGuard support first, under its VPN or advanced networking settings, before setting up an add-on separately. If it does, that's genuinely the fastest and most reliable path to a working VPN, often just a few toggles and a generated QR code away from your very first connected device.
A short reminder from the first two lessons
Whichever way you run WireGuard, the security baseline from Lesson 1 still applies in full, a strong Home Assistant password and two-factor authentication remain essential, since a compromised device with an active VPN connection would otherwise have exactly the same access to your entire home network as you do sitting comfortably on your own couch at home.
Updating and maintaining your VPN over time
Whichever route you chose, WireGuard on your router, HAOS, or Container, keeping it updated matters just as much as any other piece of your setup. Router firmware updates typically bundle WireGuard updates automatically, one more reason to keep your router's firmware current, a habit worth building alongside the Home Assistant update discipline Module 23 covers in depth. The HAOS add-on and Container image both update through the exact same channels as everything else in your system, no special process required, just the same periodic-check habit this course has consistently encouraged since Module 6.
Key takeaways
A VPN puts your whole home network within reach, not just Home Assistant.
Classic WireGuard cannot work behind CGNAT, no configuration change fixes it.
Run it on your router, HAOS, or Container, all three work identically for clients.
Each device needs its own configuration, treat it like a password.
If you're behind CGNAT and none of the workarounds above appeal to you, Lesson 4 covers Tailscale next, built on that same underlying protocol but without the port forwarding requirement standing in your way.