The networkEvery page
VPN
The VPN module runs a WireGuard tunnel. Set one up and a phone or a laptop somewhere else reaches your home network as though it were at home. It is switched on and off on the Modules page.
The page says how the tunnel is โ "The tunnel is up: devices dial in on UDP 51820. 2 of 3 devices seen in the last few minutes." โ then the devices, Over the tunnel, and the settings.
Devices that dial in
Add a device makes its configuration, shown once as a file and a QR code for the WireGuard app. Its private key is not kept on the panel. Each device's row says when it was last seen and how much it carried.
Devices dial in on a UDP port, so on a router that port is opened from the internet; behind another router, forward it there to this machine.
Dialing out instead
The tunnel can be the other way round: this machine dials out to a VPN elsewhere, from a configuration you import. Then no port is opened.
Over the tunnel
With a tunnel that dials out, the devices you tick reach the internet through it, and the rest through your own line. A tunnel that carries nothing but its own network can't take devices: they would lose the internet.
Settings
The tunnel up or down, its address, its key (the public half, safe to share), what has to reach it, and deleting it. Every change waits to be kept.
The tunnel's private keys never reach the page. After a restart the tunnel comes up by itself, unless it was taken down on this page.
Switching it off
Switching the VPN off on the Modules page takes the tunnel down and remembers whether it was up; switching it on brings it back as it was. It is refused while you are connected through the tunnel, since it would cut you off.