Connection paths
A path to your server, with the audience you choose.
Your files do not need a public front door.
- Your laptop or phoneSupported enrolled device→WireGuard
- Fibmesh routing nodePermitted private path→WireGuard
- Home server / gatewayApproved service or LAN target
Reach a home dashboard, server or NAS privately while away. A gateway can reach supported equipment that cannot run an agent.
Behind a gateway, equipment keeps its local address. File permissions and application logins remain necessary; networking does not supply backups.
Explore private storage →Several apps. Separate links. One host.
- VisitorsChoose a public hostname→HTTPS
- Publish gatewayHostname selects the app→WireGuard
- Connected home serverTunnel to the host→App listener
- Web app A or BDifferent configured ports
Publish gives selected web applications independent addresses without exposing the server’s administration interface.
Only intentionally selected web listeners belong here; non-HTTP services need a different connection model.
Explore web publication →Run a service on your own hardware.
- Internet clientConnects to the assigned address→Service traffic
- Fibmesh public deliveryFirewall + serving location→WireGuard
- Your serverPublic IP delivered through the tunnel
Public IPs can deliver an address directly to a supported device without address translation. You choose the services allowed through.
Replies to incoming Fibmesh traffic must use the Fibmesh path. Unrelated outgoing traffic can retain the existing ISP route under the appropriate configuration.
Explore Device IPs →Put it to work
Your home server can do more than stay at home.
A NAS, small server or rented machine can host useful services without moving every workload into a managed cloud. Fibmesh supplies the connection. You keep choosing the hardware, software and people who can use it.
Reach your private tools
Use Networks to open a home dashboard, use a remote shell or reach files from a supported enrolled device. A gateway can provide a path to approved NAS and LAN resources.
Private storage access →Host for an outside audience
Use Public IPs when clients need an address and protocol-level access. Publish is the alternative for selected browser apps and HTTP APIs with their own links.
Compare links and addresses →Move a workload onto your own server
A Fibmesh public address can help keep an internet-facing service reachable on infrastructure you operate. Plan data migration, capacity and recovery alongside connectivity.
Your own infrastructure →For a provider allowlist, compare an assigned public source with an Outbound exit before adding another service. Current Outbound profiles use full tunnel; confirm the effect on the host’s other traffic. Compare the connection options →

Your first working result
Your own server. A deliberate audience.
Start with a service you already run. Choose private access for your devices or an appropriate public path for outside users, keeping administration separate.
- Open the service from another internet connection
- Verify the application login and intended audience
- Retain a local way to recover the server
A practical first deployment
Choose the first service people need.
Check the service locally
Confirm it works on the intended address and port. Decide whether the application is private, public, or private for administration with a separate public listener.
Choose direct or gateway delivery
Use a supported agent on the server, or a supported gateway for equipment that cannot run it. Record local routes and firewall settings before making changes.
Test from outside
Try the real client on another internet connection. Check login, incoming rules, outgoing source where relevant, and the recovery procedure after a restart.
Questions, answered
Before you connect.
Can this work behind ISP NAT or CGNAT?
Tunnel delivery can provide reachability without a conventional inbound port forward on the ISP router, provided the underlying connection permits the required WireGuard traffic. Local network restrictions still need testing.
Will moving out of a cloud always save money?
No. Include hardware, power, uplink capacity, maintenance, backups and downtime in the comparison. Fibmesh addresses connectivity; it does not migrate data or replace the rest of your hosting operation.
Can I get an IPv6-only assignment or a whole subnet?
Public IPs includes address-family choices; Routed Subnets provides separate IPv4 or IPv6 allocations, with IPv6 sizes from /48 through /64. Availability is invitation-led. IPv6-only service needs an explicit policy for IPv4 traffic. Explore Routed Subnets.
Does private access make a remote NAS feel like a local disk?
It provides a routed path, not local-disk performance or a broadcast LAN. File transfers depend on latency and bandwidth; sharing protocols, file locks and backup software still matter.
Start with a service you know well. Keep a local way to administer the host while testing the remote connection.
Plan your first deployment →