noobtunnel

Private mesh or public tunnel?

A private device connection and a publicly published website solve different problems. noobtunnel supports both, but publishing a resource changes who can reach it and where traffic is handled.

The private mesh path

Each enrolled agent gets a private mesh address. A client on another enrolled device can connect to that address without a public domain. WireGuard carries traffic between the agents. When NAT and firewall conditions permit, the agents communicate directly. Otherwise, a POP relays their mesh traffic.

For example, if you want to access a development service on your own second device, start with its mesh address. Test the application's port from the enrolled client. The application must listen on an address the agent can reach; a process bound only to loopback is not automatically reachable through its mesh address.

A direct connection avoids the relay's shared capacity, but its speed still depends on both devices and internet connections. A relayed connection adds the route through the POP and is subject to the hosted service's relay allowance. A successful agent control connection does not by itself prove that the application's listening port is reachable.

The public publishing path

A published resource accepts outside connections at a public exit and forwards them through an agent to the configured backend. Visitors do not need to enroll an agent. For a website, the path is visitor โ†’ public exit / POP proxy โ†’ agent โ†’ backend. TCP and UDP resources expose their assigned public ports.

This is useful for a website, webhook receiver or service intended for people outside your mesh. It also makes the service an internet-facing endpoint. Select only the required port, configure access controls and verify from a device outside your private network. A free subdomain is still a public address.

Understand HTTPS termination

For published HTTPS resources, the POP can terminate the visitor's HTTPS connection and proxy the request onward. WireGuard protects the tunnel segment, but the proxy handles the request at that termination point. The backend protocol and its certificate settings are separate from the visitor-facing certificate. Do not describe this as a single end-to-end HTTPS session unless that is how your particular service is configured.

Choose a path

Use mesh access for devices you control when public reachability is unnecessary. Publish a resource when outside clients need access, and treat its backend as an internet service. If a connection fails, follow the troubleshooting guide instead of opening unrelated firewall ports. See Publish a service safely for the public setup workflow.