You should NOT use Cloudflare Tunnel (if you do this...)

You should NOT use Cloudflare Tunnel (if you do this...)

Christian Lempa

1 год назад

230,139 Просмотров

Ссылки и html тэги не поддерживаются


PantsGoneWrong - 28.11.2023 02:43

Not only do CF tunnels convey your data unencrypted through CF, but if you use their traditional DNS and choose CF proxy to "hide" your IP, your data is again in clear text within the proxy handling path.

Robert Anthony Pitera
Robert Anthony Pitera - 26.11.2023 16:57

Was about to deploy Cloudflare and thanks to searching for deployment tutorials, the algorithm served me this video. Score one for YT - this was an excellent video I'd likely have otherwise missed.

I still think it's right for my use case, but this video was invaluable towards a better understanding of what I was doing.. It was thoughtfully laid out well explained with just enough humor to make it fun to watch. Nice job; I subbed after watching it. Thanks!

I Cheema
I Cheema - 25.11.2023 07:44

i just want to use their international network to reach my resources when international

rogue particle
rogue particle - 22.11.2023 04:10

do you have any videos on how to set up a webserver on a raspberry pi and have secure certificates etc that can be accessed externally and not open up your home to potential cyber attack?

Alex - 19.11.2023 15:23

amazing as always

DerBauer - 18.11.2023 08:26

What about the new ECH from cloudflare??!

Ragnar Skudlik
Ragnar Skudlik - 15.11.2023 21:30

Sehr schön aufbereitet, Fleischmützen der IT ftw :-)

Chance F
Chance F - 05.11.2023 00:48

100% get what your saying and respect the idea about a what we should use video to fallow this up

xx mike
xx mike - 04.11.2023 00:37

So what method do you recommend for remote access to home network? VPN?

Parteek - 16.10.2023 20:21

lol, the same guy did a full advertised video on twingate 😄

kodream - 16.10.2023 19:28

Could you make video with alternative way to expose internal services without public IP(CGNAT)?

I currently rent VPS with public IP and with ZeroTier (will setup my own WireGuard at some point) connect to dedicated VM at home. then on that VPS I redirect all traffic on ports 80 and 443 to my reverse proxy VM with IPtable rules. It was a bit of a pain to get it working at first before I figured out the correct IPtable rules. But works fine since then.

Pyth0nym - 01.10.2023 20:58

Do you think tailgate is a better solution than cloudflare?

Steve Bryant
Steve Bryant - 26.09.2023 17:56

I set up a DMZ vLan with Cloudflare and pf-Sense it's much more complicated to admin but at least the cloudflare vm doesn't have full network access by default just cost a bit of hair ripping during troubleshooting and setup lol

CAMOBAP - 18.09.2023 08:37

You Germans are craze about your data (c)

DoctorWonka - 13.09.2023 05:21


Max Mustermann
Max Mustermann - 11.09.2023 17:12

Why twingate has not these privacy issues? I also connect to twingate and and the connector connects to twingate. So it’s the same, or what does twingate differently?

InsaiyanTech - 08.09.2023 10:54

If I have NordVPN configured through my router will this have an issue with cloudflare? I’m just trying to have the safest way to connect to my nas outside my network

00000a0009 - 06.09.2023 01:11

So if I have a wordpress container with a small website and I run the tunnel inside the docker I should be safe. Am I right?

Soubinan - 03.09.2023 04:03

The reason why self-hostable solutions like boundary or teleport in a free tier cloud are way better to use. When you want to businees things.

Sala polivalenta
Sala polivalenta - 30.08.2023 23:20

Very well explained. I use one cf tunnel with docker but is running on a oracle VPS and from there I am sending the traffic to the homeserver with haproxy through a wireguard tunnel. cf can see what I am doing on that VPS but can't see my homeserver, this the difference. I am glad that you have exposed the catch behind the hype of those cf tunnels from security perspective, congratulations for this video!

SkyBlaze - 27.08.2023 10:00

what are the 50 limit their ? can only 50 user per website ?

Nasir Rahimi
Nasir Rahimi - 27.08.2023 04:50

I dislike this

Alexandra Groza
Alexandra Groza - 24.08.2023 23:19


Maciej Stachura
Maciej Stachura - 24.08.2023 21:28

Thanks for this clarification. I'm new to homelab, but watching some other yt videos I asked myself: why configuring properly my firewall and control its traffic is less secure than installing 3rd party software in my home network having no control over this software. For me it sounded like installing a backdoor (I know I'm exaggerating a bit).

Cheeba Digga
Cheeba Digga - 21.08.2023 19:52

Opening a single port which is protected via public key pairs and maybe username/password (aka VPNs) is still more secure than anything else IMHO.

Flesz - 21.08.2023 16:26

my family is currently in a country which filters internet traffic . I am in UK and tested with them access to any UK server and it's all timing out. However access to the cloudflare test proxied website works fine. So I am thinking of using cloudflare tunnel to the anyconnect server , do you think that would work ?
I want the initial IP to be the cloudflare IP which appears not to be blocked from the filtered country

Amr Hegazy
Amr Hegazy - 21.08.2023 13:59

what about magic wan form Cloudflare I think it will be good for security reason

Sacha Dmitriev
Sacha Dmitriev - 20.08.2023 22:40

Cloudflare simply break the basics about SSL between the client and the server. Period.
If someone wants to host something, he have to know about the security basics and not rely on a third party company. If you want to secure access to your internal resources, just do MTLS.

abdu232 - 13.08.2023 18:37

What is the best solution?! Please help

nikolay - 12.08.2023 23:01

Curious what your thoughts on cloudflare spectrum are

Roberto Ramirez
Roberto Ramirez - 08.08.2023 05:50

so which on is the best, zerotier, twingate or cloudfare ?

Lateef Tech
Lateef Tech - 07.08.2023 22:15


frogface - 07.08.2023 19:04

Thank you I actually didn't think about this. I was looking for a simple way to allow my wife to access our server without too much configuration on her phone snd decided to give cloudflare a try and boy it's so much easier. But I decided to configure openvpn and configure our phones so we can connect to our home network. Maybe until I find a way to segregate or limit the traffic is being passed through cloudflare?

Nicht Verfolgen
Nicht Verfolgen - 31.07.2023 04:19

tl:dr Privacy ... duh

How lame

My Anime For Life
My Anime For Life - 24.07.2023 07:24

Can you point out some other options similar to cloudflare tunnel which have similar services.

Adriaan Schep
Adriaan Schep - 22.07.2023 16:19

cloudflare tunnel is great. But just dont dump it straight into the main homelab lan.

Seperate internet facing services in a seperate DMZ compared to "LAN/VPN only" services.

Eric Severance
Eric Severance - 18.07.2023 03:52

I've been burned too many times by cloud hosted services. As more and more folks use their free tier, I suspect they'll eventually need to start charging for it or discontinue it entirely. I've been basically doing the same Zero Trust thing with a reverse proxy on my own network. It'll always be free, it'll always be more private, and a direct connection will always be faster and more reliable.

I've never understood how they can market their product as having end-to-end encryption when it only has point-to-point encryption.

Alphonse Marcus
Alphonse Marcus - 15.07.2023 23:15

why not just add an extra layer of encryption before sending stuff through cloudflare? excellent video btw

A Person
A Person - 15.07.2023 04:53

What is your alternative?

Ghjaf6c4v5v - 14.07.2023 22:33

Cloudflare is semi trustable compared tho google.

EVE LBS Studio
EVE LBS Studio - 12.07.2023 14:56

Sound ike your describing a vpn (to me at least).

For me I am looking at it ad I switched to a cheaper isp that doesn't provide static ip addresses (found out after I signed up).

Rui Fung Yip
Rui Fung Yip - 09.07.2023 12:28

Personally, my deployment of cloudflare tunnels is by deploying it as a sidecar container on my external ingress traefik instances.

I run 2 sets of traefik deployments in my local k8s cluster, one that's exposed to internet via cloudflare tunnels, and one that's local only. Gives me pretty good control of what gets exposed where by setting the correct ingressClassName and external-dns annotations on my ingress resources. Security is enforced by the CNI via Network Policies, and the cloudflared daemon isn't initialized with cloud config, just a straight "direct all traffic to traefik on localhost" rule static configuration.

It's pretty good for punching through CGNAT while being directly accessible online. Similar things would be ngrok I guess. Tailscale funnel is nice, but a bit restrictive since you can't use your own domains.

As for bypassing the network firewalls and whatnot, that's a pretty easy workaround. Deploy the cloudflared tunnel on a separate VLAN/subnet where it has to go through the router to reach the services, then it's traffic will be monitored by the firewall / security appliance. (Though in most homelab setups it does mean the traffic will transit the router twice so... tradeoffs.)

Thomas Tomiczek
Thomas Tomiczek - 09.07.2023 11:29

One fundamental mistake.- Here is how to use CloudFlare Tunnel withouit opening your internal network: Put the whole shebank into a DMZ - server endpoints and the cloudflare app. Done, isolated.

Carlos Escalante
Carlos Escalante - 08.07.2023 19:30

clickbait for sure

Gareth Beard
Gareth Beard - 06.07.2023 21:10

Cloudflare provide data localisation for GDPR etc requirements.

suhaib raheem
suhaib raheem - 05.07.2023 12:30

great video, is their any good CDN service that I can get for free as Cloudflare ??

pnewman1112 - 05.07.2023 02:07

Has anyone measured, from the web browser's standpoint, how much latency CF adds to the round-trip transaction? Is it 10s or 100s of milliseconds?

Chris Umali
Chris Umali - 28.06.2023 01:05

Thanks for the info and video, have a great day
