Alexander Janzen · IT infrastructure
DE EN
Blog · 25 August 2026 · 6 minute read

Remote access without open ports

How I built access from the outside without a single port forwarding rule — and why an open port is found within minutes.

It took me a while to understand that a port forwarding rule on the router is not a small setting; it is an invitation. For years I did what many people do: I wanted to reach my files and my services while I was away. So I set up a forwarding rule, put a password in front of it, and reassured myself that I was not telling anyone about it.

The address at which my connection was reachable still appeared in every access log the other side kept. Setting up a forwarding rule publishes it — not on purpose, but effectively. Since then one simple sentence applies to me: nobody reaches a service directly from the outside. There is no open port at my connection any more, and I still have full access.

Why open ports are a risk

An open port is a permanently running, globally reachable expectation of a connection. The service waiting there is itself the attack surface: every library, every feature, every version I installed has a say. I do not have to believe that anyone is interested in me specifically. It is enough that the tools work automatically and treat my address like any other.

The case in the hotel wifi

One example I think about often. On a winter evening I sat in a hotel room and worked on a file on my storage at home over the guest wifi. The connection worked reliably, which was pleasant — and that is exactly why I was inattentive. The sign-in travelled in the clear through a foreign router, not through a tunnel. Anyone sitting in the same network running a listening tool would have seen me sign in. No password in the world helps when it crosses someone else's equipment in plain text.

A second case was less dramatic and more instructive. An acquaintance had a test environment on an old machine and opened access to it from the outside so he could check on it while travelling. Within two days requests arrived at an address he had never published — his connection had ended up in a search engine that lists exactly such services. The machine itself was harmless; the pattern was not. This does not happen because someone is looking for you in particular, but because automated collectors work through the whole reachable network.

  • I deleted every forwarding rule on the router and checked that no old one had survived.
  • Access now runs only through a tunnel I build myself — no service is visible from the outside.
  • Every interface is preceded by a login, and that login requires a second factor.

Why an open port is found within minutes

It helps to grasp the speed. There are search engines that do nothing but walk the reachable network and note what answers there — including the service, its version and its certificate. On top of that come countless bots that work through individual address ranges systematically. A single connection is not an unremarkable speck of noise; it is a line in a catalogue. Depending on the address range, a forwarding rule is recorded within a few hours, sometimes faster.

  • Address ranges are checked as a whole, not picked one by one.
  • A service that answers is identified, named and noted with its version.
  • Once noted, it is called again and again — old entries stay.
  • A service that is not kept up to date stands out on every one of those calls.

The tunnel replaces the forwarding rule

The way out is unspectacular: instead of opening a service, I establish a connection that goes from the inside out. WireGuard forms a small private network between my devices; I open nothing at the router, because the encrypted conversation starts from within. For the services I want to reach in a browser I use Cloudflare Tunnel as well: the tunnel agent builds the connection outwards, and incoming requests come back over that existing line. My router still knows no incoming forwarding rule at all.

Diagram: two paths — above an open port on the router that is found within minutes; below a tunnel built from the inside with a sign-in and a second factor
No port exposed, remote access anyway. Above, the path through a port forward — an invitation that is found within minutes. Below, the path through a tunnel: built from the inside, with a sign-in and a second factor in front.

Identity before the interface

A tunnel alone is not enough, because it only provides the line; it does not decide who may knock. So an Nginx Proxy Manager sits in front of the interfaces, accepting and distributing the requests, with Authelia as the gatekeeper ahead of it. Only someone who has signed in and is recognised as authorised gets any answer at all. Without that layer a tunnel would still offer the services — just somewhere else. Checking identity belongs in front of the interface, not inside it.

The second factor

The most important part for me is the second factor. A password can leak, through an old login, out of someone else's database or through a rogue access point in open wifi. A second factor generated on a separate device cannot be read along with it, and it is of no use to anyone who does not hold it. Since I take this seriously I look at logins differently: a single password is only half a lock to me.

Devices and sessions that expire

I added two things later, and both have helped. First, sessions are time-limited now: signing in does not last forever but for a fixed period, after which a new login is required. Second, I can see the signed-in devices and end a foreign session. An access that stands out is no longer just a log entry but something I can stop immediately. I do not feel safe because I can see everything, but because I know what happened — and can act on it.

What I take from it

The main lesson was uncomfortable: convenience is the real mistake. Every forwarding rule I used to set up was a compromise with my peace of mind. Today remote access is something I no longer think about: I switch it on, the tunnel is up, the login asks for the second factor, and nobody else sees my connection as a service. The route is a little longer, but it does not end at someone else's equipment reading my login.

TL;DR I deleted every port forwarding rule and run access from the inside through a tunnel. Every interface is preceded by a login and a second factor, and sessions expire. An open port, by contrast, is found within minutes and called again and again. Convenient was yesterday — today it is safer.

← All posts