Quick Summary (TL;DR):
For most Home Assistant users, Nabu Casa Home Assistant Cloud—being renamed Home Assistant Link in December 2026—is the easiest remote-access option because it needs no router port forwarding, creates a secure remote URL automatically and integrates directly with Home Assistant. In the EU it currently costs €7.50/month or €75/year and also includes features such as off-site backups, Alexa/Google Assistant integration and cloud voice processing. Tailscale is the strongest private-network alternative for technical users: its Personal plan is currently free for up to six users with unlimited user devices, it works through NAT/CGNAT without normal inbound port forwarding, and only authorised tailnet devices can reach Home Assistant. WireGuard gives you the most direct self-hosted VPN model but normally requires a publicly reachable WireGuard server, UDP port forwarding, key management and more network administration. Cloudflare Tunnel is different again: it publishes Home Assistant through an outbound-only tunnel to a hostname without opening router ports, and Cloudflare Access can add identity-aware access control, but it is a reverse-proxy architecture rather than a private VPN. Choose Nabu Casa/Home Assistant Link for minimum maintenance, Tailscale for private remote access without exposing a public Home Assistant URL, WireGuard for maximum self-hosted control, and Cloudflare Tunnel when you specifically want a managed public hostname/reverse-proxy architecture.
Nabu Casa vs Tailscale vs WireGuard vs Cloudflare Tunnel at a Glance
| Option | Remote-access model | Inbound router port? | Remote client required? | Best fit |
|---|---|---|---|---|
| Nabu Casa / Home Assistant Link | Official managed HA remote-access service | No | No separate VPN client | Most Home Assistant users |
| Tailscale | Private WireGuard-based mesh VPN | Normally no | Yes, or access through a tailnet/subnet-router design | Private technical access |
| WireGuard | Self-hosted VPN | Usually yes | Yes | Maximum control and self-hosting |
| Cloudflare Tunnel | Outbound reverse tunnel / published application | No | No VPN client for a public hostname | Managed hostname and proxy controls |
A Note About the Nabu Casa Name Change
Nabu Casa announced on 2 October 2026 that Home Assistant Cloud is becoming Home Assistant Link. The company says the new name becomes official with the Home Assistant 2026.12 release on 2 December.
During the transition, documentation and Home Assistant screens may still say Home Assistant Cloud. This article therefore uses “Nabu Casa / Home Assistant Link” where the distinction matters.
The service is still optional. Home Assistant continues to run locally if the subscription is not present or the internet connection is unavailable.
Nabu Casa / Home Assistant Link: The Official Easy Option
Home Assistant’s own remote-access documentation describes its managed service as the easiest and safest option for most users.
Setup is deliberately simple:
- Open Settings → Home Assistant Cloud.
- Sign in or start the trial.
- Enable Remote access.
- Home Assistant creates a unique remote URL.
No router port forwarding is required and Home Assistant states that traffic between the remote device and your home is encrypted automatically.
What the Nabu Casa Subscription Includes
The subscription is broader than a remote-access tunnel. Current Home Assistant/Nabu Casa documentation lists benefits including:
- Secure remote Home Assistant access.
- Off-site Home Assistant backup location.
- Google Assistant integration.
- Amazon Alexa integration.
- Speech-to-text and text-to-speech services.
- Improved media/WebRTC services.
- Nabu Casa support for subscription features.
- Funding for Home Assistant and related open-home projects.
As of October 2026, Nabu Casa lists EU pricing at €7.50 per month or €75 per year, including VAT.
Why Nabu Casa Is Different from a VPN
Home Assistant Link is not a general VPN into your home LAN.
It gives remote access to Home Assistant and related subscription services. It does not automatically make your NAS, printer, router administration page or every local device reachable from your phone.
If your real requirement is “I want secure remote access to several private home-network services”, Tailscale or WireGuard is a more natural architecture.
Tailscale: Private Remote Access Without Traditional Port Forwarding
Tailscale builds a private mesh network using WireGuard-based encrypted connections plus its own identity, NAT traversal, routing and access-control services.
Tailscale’s current documentation states that tailnet connections can work across firewalls and NAT without normal port-forwarding configuration. When direct peer-to-peer connectivity is not possible, Tailscale can use relay infrastructure.
This makes Tailscale particularly attractive when your ISP uses CGNAT and you cannot accept unsolicited inbound IPv4 connections.
Tailscale Personal Is Currently Free for Typical Home Use
Tailscale changed its pricing in April 2026. Its current Personal plan is listed at $0 and includes:
- Up to six users.
- Unlimited user devices.
- Access to most Tailscale features.
- A limited number of ACL groups and tagged resources.
Check current plan limits before designing a larger family or multi-site network, because pricing and included features can change.
How Tailscale Reaches Home Assistant
There are two common designs.
Tailscale directly on the Home Assistant host
For Home Assistant OS, a maintained Home Assistant Community App can install Tailscale on the Home Assistant system. Your remote phone or laptop also runs Tailscale and connects through the private tailnet.
Phone with Tailscale
↓
encrypted tailnet
↓
Home Assistant with Tailscale
Use another device as a Tailscale subnet router
Alternatively, run Tailscale on a router, mini PC or server and advertise the home LAN as a Tailscale subnet.
Phone with Tailscale
↓
Tailscale subnet router
↓
192.168.x.x home LAN
↓
Home Assistant + NAS + other local devices
This approach is more powerful because one subnet router can provide access to local devices that cannot run Tailscale themselves.
Do Not Confuse the Home Assistant Tailscale Integration with Remote Access
Home Assistant also has an official Tailscale integration, but the integration only monitors tailnet devices and status.
Home Assistant’s documentation explicitly notes that adding the integration does not make Home Assistant reachable over Tailscale. You still need Tailscale running on the Home Assistant device or another appropriate router/gateway.
Tailscale Serve Is Useful but Not Required
Tailscale Serve can publish a local web service securely inside the tailnet. This can provide a convenient HTTPS hostname for Home Assistant without exposing it to the public internet.
Tailscale Funnel is different: Funnel publishes a service to the broader internet. For Home Assistant remote access, private tailnet access is usually the more obvious reason for choosing Tailscale in the first place.
The Main Tailscale Trade-Off: Every Remote User Needs Tailnet Access
Nabu Casa gives you a normal HTTPS URL that can be opened without installing a VPN client.
With a private Tailscale design, the phone, tablet or laptop normally needs the Tailscale client and permission to join the tailnet.
For your own devices that is usually trivial. For guests, family members or third-party integrations, it can be less convenient.
WireGuard: The Fully Self-Hosted VPN Approach
WireGuard is the underlying VPN technology that also forms the encrypted data plane used by Tailscale, but plain WireGuard leaves the network design to you.
You manage:
- Server endpoint.
- Public/private keys.
- Peer configuration.
- IP address assignment.
- Routing.
- Firewall rules.
- DNS if required.
- Port forwarding.
- Dynamic IP changes.
That is both its attraction and its maintenance burden.
Home Assistant Has a Community WireGuard Server App
The current Home Assistant Community WireGuard app runs a WireGuard server on the Home Assistant system and generates client configurations for peers such as phones and laptops.
Its current documentation requires forwarding UDP port 51820 from the router to Home Assistant and configuring an externally reachable hostname/address.
The Community App documentation also now makes an important limitation explicit: it is designed as a WireGuard server, not a client. It is not intended to join an external WireGuard network hosted elsewhere.
Why CGNAT Is a Bigger Problem for Plain WireGuard
A traditional home-hosted WireGuard server normally needs an inbound UDP path from the internet.
If your ISP places you behind carrier-grade NAT and will not provide a public IPv4 address, conventional router port forwarding may not work at all.
Possible solutions include:
- Use native public IPv6 if the entire design supports it.
- Ask the ISP for a public/static address.
- Host WireGuard on a VPS and route through it.
- Use Tailscale instead and let it handle NAT traversal.
Why Some Users Still Prefer Plain WireGuard
- No third-party mesh control plane is required for the VPN data path.
- You control the keys and topology directly.
- It works on many routers, Linux systems and mobile platforms.
- The protocol is simple and widely supported.
- You can expose the entire private LAN through your own routing design.
If you already manage routers, firewall rules and VPN peers, plain WireGuard can be beautifully simple. If you do not, Tailscale removes a great deal of operational work.
Cloudflare Tunnel: A Reverse Proxy, Not a Traditional VPN
Cloudflare Tunnel solves a different problem.
You run the cloudflared daemon inside your network. It opens persistent outbound-only connections to Cloudflare. You then map a public hostname such as:
ha.example.com
↓
Cloudflare
↓
outbound Cloudflare Tunnel
↓
http://home-assistant:8123
Cloudflare currently states that Tunnel requires no inbound ports and no public IP for published applications.
Cloudflare Tunnel Can Work Through CGNAT
Because cloudflared establishes the connection outbound, the home network does not need a publicly reachable IPv4 address.
This makes Cloudflare Tunnel attractive where traditional WireGuard or HTTPS port forwarding is blocked by CGNAT.
A Published Cloudflare Hostname Is Still an Internet-Facing Application
Not opening a router port is valuable, but it does not mean the application ceases to be reachable through the internet.
A standard Cloudflare Tunnel published application maps a public hostname to the local Home Assistant service. Requests arrive through Cloudflare rather than directly at your residential IP.
You can put Cloudflare Access in front of that application so an identity-aware proxy evaluates who is allowed through before the request reaches Home Assistant.
Cloudflare Access Adds Security but Also Another Authentication Layer
Cloudflare Access can require identity-provider authentication, device posture or other policy conditions before allowing access to a self-hosted application.
This is powerful for browser-based administration, but Home Assistant also uses:
- Mobile apps.
- Webhooks.
- API clients.
- Camera and media traffic.
- Third-party integrations.
An extra proxy authentication challenge can therefore require additional policy design. Test the Home Assistant Companion App, webhooks and any external integrations rather than assuming a browser login proves every workflow is compatible.
Cloudflare Tunnel vs Cloudflare Private Networking
Cloudflare also offers private-network access through Cloudflare One/WARP, but that is a different architecture from simply publishing ha.example.com through a Tunnel.
For this comparison:
- Published Cloudflare Tunnel: reverse-proxies a public hostname to Home Assistant.
- Cloudflare private network/WARP: acts more like private network access.
Do not call every Cloudflare Tunnel setup a VPN. It depends on how the tunnel and client access are configured.
Which Options Expose a Public Home Assistant URL?
| Option | Public HA URL? | Who can reach the endpoint? |
|---|---|---|
| Nabu Casa / Link | Managed unique HTTPS URL | Internet reaches Nabu Casa endpoint; HA authentication still applies |
| Tailscale private tailnet | No public URL required | Authorised tailnet devices |
| WireGuard VPN | No public HA URL required | VPN peers |
| Cloudflare Tunnel published app | Yes | Internet via Cloudflare, optionally restricted by Access |
Which Options Need Port Forwarding?
| Option | Normal inbound port forwarding? | CGNAT friendly? |
|---|---|---|
| Nabu Casa / Link | No | Yes |
| Tailscale | Normally no | Yes |
| Plain WireGuard server at home | Usually yes, UDP | Not without another solution |
| Cloudflare Tunnel | No | Yes |
Security Is More Than “No Open Ports”
All four approaches can form part of a secure setup when configured correctly. They simply place trust in different components.
- Nabu Casa: trust the official managed remote-access service plus Home Assistant authentication.
- Tailscale: trust the Tailscale identity/control system while WireGuard protects the encrypted data path.
- WireGuard: you manage endpoints, keys, routing and firewall policy directly.
- Cloudflare Tunnel: trust Cloudflare’s tunnel/proxy infrastructure and any Access identity policies you add.
Whichever method you choose, enable strong Home Assistant authentication and keep Home Assistant, add-ons/apps, VPN software and remote-access components updated.
What About Direct Port Forwarding to Home Assistant?
Home Assistant’s official documentation still describes direct remote access as possible, but warns that simply exposing a port is not secure by itself and that TLS/encryption must be configured properly.
Dynamic public addresses and CGNAT also complicate direct exposure.
For most users choosing among the four approaches in this article, there is little reason to expose Home Assistant’s port directly without a carefully managed TLS/reverse-proxy design.
Mobile App Experience
The practical difference becomes obvious on a phone.
Nabu Casa / Link
The remote URL integrates directly with Home Assistant. There is no separate VPN switch to remember.
Tailscale
The Tailscale client must normally be active. Once connected, Home Assistant behaves like another private network service.
WireGuard
The WireGuard tunnel must be active, either manually or through an always-on/on-demand VPN rule supported by the mobile OS.
Cloudflare Tunnel
A published hostname behaves like an ordinary HTTPS site, but Cloudflare Access policies may introduce another authentication step depending on how you protect the application.
Remote Access to More Than Home Assistant
If Home Assistant is only the beginning, the comparison changes.
Tailscale subnet routers and self-hosted WireGuard can provide private access to:
- NAS administration.
- Proxmox.
- Routers and managed switches.
- Printers.
- IP cameras.
- SSH hosts.
- Other internal web services.
Nabu Casa is intentionally Home Assistant-focused. Cloudflare can publish multiple web applications, but each application needs deliberate routing and security policy.
Our separate NAS-focused guide will compare these approaches for remote file and administration access: Remote NAS Access: Tailscale, WireGuard or the Manufacturer’s App?.
Router Hardware Matters Most for Self-Hosted VPNs
If you want WireGuard or Tailscale routing at the edge of the network, your router becomes part of the remote-access architecture.
A router/firewall platform with enough CPU, supported NICs and good VPN integration can act as the persistent gateway for the whole LAN.
See Best Router Hardware for OPNsense and pfSense for the hardware side of that design.
Cost Comparison
| Option | Software/service cost | Possible extra costs |
|---|---|---|
| Nabu Casa / Link | EU: €7.50/month or €75/year currently | None required for ordinary remote access |
| Tailscale Personal | $0 for current Personal plan limits | Always-on router/mini PC if using subnet routing |
| WireGuard | Open-source software | Public IP, DDNS, compatible router or VPS may cost money |
| Cloudflare Tunnel | Tunnel available on Cloudflare plans; Zero Trust Free exists | Domain registration and optional paid Cloudflare features |
Do not choose purely on subscription price. Maintenance time and failure recovery also have a cost.
Maintenance Burden
| Option | What you maintain | Relative effort |
|---|---|---|
| Nabu Casa / Link | Home Assistant account and normal HA security | Lowest |
| Tailscale | Clients, device authorisation, ACLs/grants, subnet router if used | Low to moderate |
| WireGuard | Keys, server, DNS, ports, routing, firewall, peers | Highest |
| Cloudflare Tunnel | cloudflared, DNS, tunnel routes, Access policies, proxy settings | Moderate |
Which Option Should You Use?
Use Nabu Casa / Home Assistant Link when:
- You want the least configuration.
- You do not want to manage a VPN.
- You also use Alexa, Google Assistant, off-site backups or Nabu Casa voice services.
- You want an official Home Assistant remote-access path.
Use Tailscale when:
- You want Home Assistant to remain private rather than publishing a public URL.
- You need access through CGNAT.
- You also want private access to NAS, Proxmox or other home devices.
- You are happy to run a Tailscale client on your remote devices.
- You want less networking administration than plain WireGuard.
Use plain WireGuard when:
- You want to self-host the VPN design directly.
- You already understand routing, keys and firewall rules.
- You have a usable public endpoint or another server acting as the endpoint.
- You want to avoid relying on a mesh-VPN control service.
Use Cloudflare Tunnel when:
- You want a stable HTTPS hostname without opening inbound ports.
- You already use Cloudflare DNS/Zero Trust.
- You want Cloudflare Access, WAF or proxy controls around the application.
- You are prepared to test Home Assistant app, API, webhook and media behaviour through the extra proxy layer.
Nabu Casa vs Tailscale vs WireGuard vs Cloudflare Tunnel: The Bottom Line
Nabu Casa/Home Assistant Link is the cleanest answer when the requirement is simply “I want Home Assistant to work securely away from home without maintaining networking infrastructure.”
Tailscale is the strongest private-network alternative for many technical home users. It keeps Home Assistant off a public URL, normally works through NAT and CGNAT, and can extend to the NAS and the rest of the LAN.
WireGuard is the most directly self-hosted option, but you take responsibility for endpoint reachability, keys, routes and firewall rules.
Cloudflare Tunnel is best understood as a managed reverse-tunnel/proxy architecture. It solves inbound connectivity elegantly and can add strong identity controls, but it is not automatically equivalent to a private VPN.
For most households, the real choice is therefore Nabu Casa for simplicity versus Tailscale for private multi-device access. WireGuard and Cloudflare Tunnel become more compelling when you already understand and want the infrastructure model they represent.
Continue the Home Assistant and Networking Series
- Home Assistant Hardware Compared: Green vs Raspberry Pi 5 vs Mini PC vs NAS
- Best Router Hardware for OPNsense and pfSense
- Remote NAS Access: Tailscale, WireGuard or the Manufacturer’s App?
Datasheets & External Resources
- Home Assistant – Remote access documentation
- Home Assistant – Home Assistant Cloud / Link
- Nabu Casa – Home Assistant Link
- Nabu Casa – Current regional pricing
- Home Assistant – Tailscale integration
- Tailscale – How the private mesh network works
- Tailscale – Current plans and limits
- Tailscale – Configure a subnet router
- Home Assistant Community App – Tailscale
- Home Assistant Community App – WireGuard
- Cloudflare – Cloudflare Tunnel documentation
- Cloudflare Access – Protect self-hosted web applications