Expert InsightNetwork & Security

Secure Remote Access: Reaching Your Systems Without Opening Everything to the Internet

Remote access can be useful without exposing internal services unnecessarily. Understand VPNs, identity, permissions and why direct port forwarding should not be the default answer.

MBS Integrations · Published

A compact network cabinet beside a desk in a small professional office.

Start with the job someone needs to do.

You may need to check Home Assistant while away, open a file on your NAS, reach an internal business application or arrange remote support. Cameras, dashboards and network management tools can also have legitimate remote users.

Those are different requirements. An employee who needs one business application should not automatically receive the same access as the person maintaining the network. Define the resource, the user and the permitted actions before choosing the connection method.

Publishing a service should be a deliberate decision.

Port forwarding routes traffic arriving at a public address and port to a service inside your network. That service can then receive connections from outside. Its authentication, configuration, updates and exposure become part of your public-facing security boundary.

This is not inherently wrong. Public services can be designed and operated responsibly. But forwarding a port because an app suggests it is a poor substitute for deciding who should connect and how they should prove their identity.

Encryption also needs attention: forwarding a port does not add it. An encrypted remote-access path can let authorised users reach selected internal services without publishing each service individually.

A man working on a laptop at a kitchen table beside a wood-burning stove.
Controlled remote access
Direct exposure

Internet → Public IP / forwarded port → Internal service

A deliberate publishing decision: the exposed service must be secured.
RemotedeviceEncrypted accessVPNAuthenticateduserPermittedresourcesBusinessNASManagementCamerasIoTRemote deviceEncrypted access / VPNAuthenticated userPermitted resourcesBusinessNASManagementCamerasIoT
Example employee permission: Business + NAS. Other resources remain unavailable to this user. Encryption, identity and access rules work together.

Choose an access method you can maintain.

A traditional VPN, a WireGuard-based connection, a managed remote-access product, an appropriate vendor service or an identity-based overlay network may suit the job. There is no single best option for every household or business.

WireGuard supplies an encrypted tunnel using peer keys; account management, permissions and any MFA depend on the surrounding solution. UniFi Teleport offers an invitation-based approach on supported gateways. Identity-based overlays can link permissions to users and devices, while a vendor’s remote service may expose only that application.

Some self-hosted VPNs still need a publicly reachable endpoint and a gateway rule. The distinction is between deliberately exposing a maintained access service and publishing many internal applications. Check compatibility, broadband constraints, client devices and how access will be revoked before selecting a solution.

A working tunnel is not permission to reach everything.

Segmentation and remote-access rules should reinforce one another. A camera viewer may need the viewing service but no management access. A remote employee may need business files without reaching IoT devices. A support account may require one management interface for an agreed task.

Apply permissions to the required resources and ports, not simply to “the whole LAN”. Confirm that the chosen gateway, overlay policy and application permissions enforce the same intention. Then test both what the user can reach and what they cannot.

Our diagram illustrates one employee allowed to reach Business and NAS resources. Management, Cameras and IoT remain muted because this example identity has no permission to use them.

A network gateway and switch with neatly connected Ethernet cables in a communications cupboard.

Keep identity and access under control.

Use individual accounts where available, protect credentials and keys, enable MFA where the selected system supports it, and remove unused access. A lost laptop or departing colleague should have a clear revocation process. Shared credentials make that harder.

Maintain the access service and the applications behind it. Review relevant logs and confirm that backups, updates and recovery arrangements cover the gateway as well as the destination. A VPN does not remove these responsibilities.

Plan remote support as part of the service.

Remote support should have an agreed purpose, named access, appropriate permissions and a clear way to disable it. Time-limited access may suit a one-off visit; an ongoing support arrangement needs documented ownership and periodic review.

That is part of the design work in our Network & Security service. For your business, the aim is useful access that you can understand and maintain, without undocumented permanent backdoors.

Sources & Further Reading

Technical references checked 23 September 2026. Platform features and device support can change.

Planning something similar?

Every home or business starts with different equipment, constraints and goals. We can assess what you already have and design an approach around what actually needs to change.

Discuss Your Project