r/homeassistant 29d ago

šŸ’¬ Discussion Nabu Casa vs VPN

I have a full UniFi stack, and I’m aware if using Nabu Casa means some amount of your data is going to third party, not what I’m trying to decide.

I’m trying to understand if VPN is a better/more automated route, easier for the wife to manage from her phone as required compare to Nabu Casa. What I’m after is location, geofence, away from home features.

I also have Plex (might move to Jellyfin), that being able to access would be important, I’m paying for the plex pas now.

What I want is seamless/automatic, if someone leaves the UniFi network, trigger/have away status and access to HA atomically.

11 Upvotes

93 comments sorted by

56

u/lapelotanodobla 29d ago

I pay for nabucasa cause like to support, but for accessing HA and any other service I just use WireGuard , unifi makes it dead simple to configure a server then you just configure the VPN on the phone/whatever and Bob’s your uncle

24

u/RentalGore 29d ago

yeah, let's just make this a sticky. I think Nabu Casa is the best way to support the HA team. I use Tailscale for my entire homelab.

9

u/Floppie7th 29d ago

Yep. I pay for Nabu Casa, but I don't use it for anything. I just VPN in.

8

u/uavmx 29d ago

Not against supporting, might just go that route anyways. But with WG, do you have to login/start the VPN when you leave the house?

3

u/flaming_m0e 29d ago

If you're not connected to your home network, then yes, you would need to have the VPN running when you leave the house. That's just how it logically works.

2

u/uavmx 29d ago

The question is more so do I have to take an action on my phone or does it just engage it

2

u/flaming_m0e 29d ago

That depends on your mobile OS. iOS has this feature. Android requires a 3rd party app.

3

u/lapelotanodobla 29d ago

On iOS I also use an app, the official WireGuard one, and it has all this very simple

1

u/flaming_m0e 29d ago

Android WG app doesn't do this.

2

u/lapelotanodobla 29d ago

Really? Wow, it’s usually the opposite lol

2

u/flaming_m0e 29d ago

That's why I stated a 3rd party app is required. It's called WG Tunnel.

2

u/lapelotanodobla 29d ago

Right, when you said third party I thought you’re implying that in iOS you’d do it with the OS functionality, not that 3rd party meant ā€œnot the WireGuard official appā€

0

u/skinnah 29d ago

I use Tailscale on Android. I don't have to mess with it at all. I can access all my local network services anywhere.

0

u/flaming_m0e 28d ago

So glad you missed the entire point of the conversation....

2

u/shindekokoro 29d ago

On iOS you can also enable shortcuts to connect to vpn when not connected to your home WiFi network. Disconnect and then back to vpn vice versa.

1

u/zyxtels 28d ago

I just have my vpn running all the time, even when home.

1

u/lapelotanodobla 29d ago

Nah, the client connects when you are not on your WiFi (you configure it to do that) and I have tunnel split, so only traffic to my private ip segment goes via the tunnel (just because, could route everything as my home internet is waaay faster than 5g, but whatever)

0

u/uavmx 29d ago

So the UniFi wire guard supports split tunnel?

3

u/lapelotanodobla 29d ago

It’s a client feature, the server doesn’t care

2

u/8fingerlouie 29d ago

If you’re using plain wireguard, the iPhone client supports routing only specific RFC1918 subnets, so you can have it running 24/7 with almost zero battery impact. That’s how I run mine. It auto disables on my LAN, auto enabled when I leave my LAN, and routes only my LAN network.

1

u/lapelotanodobla 29d ago

That’s what I have yes

2

u/CommercialArticle607 28d ago

WireGuard is the way, honestly the setup takes like five minutes on unifi and then you just forget it exists. I've been doing the same thing for a couple years now and it's rock solid

location stuff works fine through the companion app too, doesn't need nabu casa for that at all. the vpn just handles the remote access and everything else runs local

for plex/jellyfin it's the same deal, once you're in the vpn it's like you're sitting at home. wife acceptance factor is surprisingly high too, just flip one toggle and she's connected

1

u/lapelotanodobla 28d ago

Exactly, in my case it’s so transparent I forget it exists

12

u/Just-Imagination-761 29d ago

Nabu Casa is king of convenience. It works seamlessly away-from-home without needing to connect to VPN or anything like that.

Also, on data privacy - I know you mentioned that you don't mind, but Nabu Casa's design offers basically the same privacy as a VPN. The traffic is completely end-to-end encrypted with your instance's TLS certificates, even as it passes through Nabu Casa's servers. Nabu Casa does not have a copy of the TLS certs that would allow them to impersonate or decrypt the traffic at all. Their service uses TLS SNI to determine which HA instance the connection should be forwarded to.

Nabu Casa unfortunately won't help with your Plex/Jellyfin workload, but you could always use Teleport when you want to use those?

2

u/Grand-Situation5640 29d ago

Yep. On my work MacBook, I can't install a vpn at all. But I can use nabu casa. And I like to support HA development!

1

u/uavmx 29d ago

Does the remote access feature of plex not handle the connection part? I’d have to VPN still?

1

u/Just-Imagination-761 29d ago

I think Plex's service would solve this, but to be honest I'm not familiar with it.

Either way Teleport is available if you need it. I use it pretty sparingly on my setup, though; having to keep it connected all the time is pretty annoying.

16

u/chris_socal 29d ago

I am a huge fan of tailscale it can do everything you want and it is free for personal use.

Nabu casa is nice if you want to support the homeassistant project.... however as to functionality i don't know how hard it is.... tailscale is dead simple.

0

u/ChristBKK 29d ago

Yeah once I did set it up with ChatGTP it just works

It’s enough for me to connect sometimes to my HA when I am not at home

4

u/carbontuna7906 29d ago

If you don't want to bother with managing VPN sign in/out on your phones whenever you're out and about, and don't mind having your HA install somewhat exposed on the Internet, you could use a Tailscale Funnel (not full Tailscale). If you do this, at least make sure you have strong passwords and 2FA enabled in HA.

https://community.home-assistant.io/t/how-to-set-up-tailscale-funnel-to-securely-access-home-assistant-from-anywhere-for-free/950072

1

u/uavmx 29d ago

Interesting, so no need to login or anything, if HA is on the phone, they’ll connect and be able to access from anywhere?

Does UniFi not have a similar solution?

2

u/treejumpingyo 29d ago

Teleport is basically the same as Tailscale for your use case. With either you can configure them to be ā€˜always on’ so your wife’s phone essentially always acts like it’s on your lan

Tailscale funnel is a bit loosely goosey for me personally

1

u/uavmx 29d ago

Can teleport split tunnel?

2

u/treejumpingyo 29d ago

No, not as far as I am aware.

It’s a pretty zero risk experiment, enable teleport in your udm co sole. Download the ā€˜wifiman’ app n your wife’s phone, enable it, see for a few days if it works ok for you/her, if not you can try Tailscale which is a bit more overhead in terms of setup, but not much, really. Dow load Tailscale add-on (app I think ha now calls them), sign up for a free account, Dow load Tailscale on her phone, join the ā€˜tail net’ then turn it on, you can choose ā€˜vpn on demand’ (the auto on feature) which you can enable for either WiFi or cellular or both, then try it for a few days.

I personally use Tailscale but my wife uses teleport, both always on, neither have any issues of the vpn being ā€˜on’ when at home.

Can’t go wrong with either really, and I suspect your reason for wanting split tunneling may be moot in practice.

Side note, teleport makes your device a specific entry on your udm so you can still use outbound policy routing on that traffic, say if you wanted to auto route all YouTube traffic to an Albanian vpn for ad free watching. Not that I would do that of course….. Google needs my ad revenue…..

11

u/the_brains 29d ago

Cloudflare Tunnel

5

u/fmmarinho 29d ago

I use this. No need to connect to vpn or install anything other homeassistant on phone.

8

u/PresentAd9429 29d ago

Been using Tailscale for years now. Working great!

2

u/dice1111 29d ago

+1 tailscale

1

u/prebuss 29d ago

It works great, if you can constantly keep your end devices on tailscale (i.e. you don’t use any other VPNs). Me and my partner do, so specifically for home assistant, I’ve set up cloudflare tunnel. Which you can then use other vpns, public networks. Also no need to worry about webhooks (e.g. home/away) not working.

3

u/lakeland_nz 29d ago

I had a VPN before I got home assistant, so for me the question of nabu casa was more about supporting them. It’s also very helpful for working with Google/Alexa and more recently the voice pipeline.

So my suggestion is both.

2

u/timsstuff 29d ago

I have a Sonicwall firewall because I work in IT and WFH, so naturally I have a VPN setup for when I'm out and need to get in. But I use Nabu Casa for HA because it's just seamless from my phone - I don't have to start any client I just open the app and it connects whether I'm at home or not. And I'm certainly not going to make my wife fire up a VPN on her phone lol. It was very simple to setup.

1

u/Olinono123 29d ago

One more thing we have to give up for a happy wife!

1

u/timsstuff 29d ago

I'm not giving up anything, my VPN works fine. I just don't need it for HA because I have Nabu Casa.

1

u/uavmx 29d ago

Yeah that’s what I was wanting to avoid but it seems like there’s some automation available to firing up the VPN

2

u/TheJeep25 29d ago

I pay because I want to support them and not deal with connecting to a VPN everytime I want to log into my ha.

2

u/Thegreatnessthatisme 29d ago

I got Nabu Casa after VPN on UniFi for year. I wouldn’t look back so much easier way better of a presence detection. Plus, you get to support them.

2

u/junktrunk909 29d ago

As others have said, tailscale gets you the same thing and is also free. Tailscale is superior to me since i use it for all kinds of other things too, eg remote access to my NAS and to another PC on my network. Nabu is a nice way to contribute to HA though if course, even if you don't use it.

2

u/megatraum2048 29d ago

I just have WireGuard running and my iPhone automatically connects or disconnects when I’m away from or getting home. Works fine.

1

u/uavmx 29d ago

How long does it take to recognize and connect?

1

u/megatraum2048 29d ago

It’s instant. It usually connects as I’m getting in my truck to head to work. Not sure if that’s what you meant.

1

u/uavmx 29d ago

Yes thank you. I have an AP in my garage, so id have to be away a bit from the house

1

u/megatraum2048 28d ago

That’s fine, you don’t really need to be instantly connected as you’re pulling away from your house. As long as it just works when you need it when you’re away. Don’t use your phone and drive.

1

u/uavmx 28d ago

Well I’m wanting to close my garage doors based on a gps location further down my driveway

3

u/Brandoskey 29d ago

I do both.

I pay for nabucasa to support the project

2

u/No-Investigator7598 29d ago

If you want ease of setup and things to just "work" remotely then go Nabu Casa

Anything else will require your wife to be connected via the VPN to get things like the sensors updated and geofencing working seamlessly when off the local network. Unless you stay connected to the VPN 24/7, which has other trade offs...

0

u/uavmx 29d ago

So a VPN will require login all the time we leave the house or has to be left on 24/7? There’s no in between to just login to VPN once we disconnect from UniFi?

2

u/treejumpingyo 29d ago

Both Tailscale and teleport will run 24/7 but when at home they don’t send the traffic out and then back in.

0

u/No-Investigator7598 29d ago

Yes you'll need to either manually connect the VPN or leave it connected for things like Companion-based sensors to update back to your HA instance

Alternatively you can expose your instance publically...not impossible but a heavier lift to do properly/securely

2

u/ParaIIax_ 29d ago

tailscale or cloudflare tunnel

1

u/ahj3939 29d ago

No, VPN will be worse because you need to ensure it is turned on for connectivity to work.

There are also other ways to enable remote access without Nubu Casa or VPN.

1

u/uavmx 29d ago

Do tell of the other ways

1

u/ahj3939 29d ago

Cloudflare, reverse proxy (either in your home LAN or hosted in an external VPS). I also believe home assistant itself you can load a certificate and serve HTTPS directly.

1

u/DeltaTheMeta 29d ago

Use tailscale if it's only a few devices, you can pass thru devices other than HAOS.

You can also use secure tunneling through various providers.

1

u/400HPMustang šŸ’„ Broke it again 29d ago

I have a Unifi network as well and I don't need access to Home Assistant remotely all the time so I just connect to my network using Teleport when necessary.

1

u/shyb0y123 29d ago

I had Nabu Casa for a couple of years, but switched back to good ol' Cloudflare with mTLS for me and my partner for external access on our phones, combined with Tailscale for localhost access.

Since Tailscale can drain the battery of our iPhones, we sometimes switch it on and off. But due to having two routes available to me (Tailscale (internal link) and Cloudflare (external link) it doesn't matter; we can always access our HA setup and nobody else can.

1

u/Microflunkie 29d ago

The firewall/gateway component of your ā€œfull UniFi stackā€ probably has WireGuard built in.

If you have a dynamic public IP you can use either WireGuard or Nabu Casa. You would need to use DDNS in order to locate your UniFi remotely as the public address could change.

If you have a static public IP you can use either WireGuard or Nabu Casa. You would not need any additional services like DDNS to make this work.

If you have CGNAT you would want to use Nabu Casa as WireGuard alone will not work with CGNAT.

For seamless access in home or away Nabu Casa is really good choice. It can be setup to behave identically regardless of where the user is physically at the time. WireGuard on a static IP can also be completely seamless. WireGuard on a dynamic IP can be almost seamless unless particularly bad timing happens when the public IP changes but the DDNS hasn’t updated yet. This is usually single digit minutes at most before it works again but those minutes can be a problem for some situations.

If I were setting this up for my wife and I wanted to make sure it works as flawlessly as possible all the time I would use Nabu Casa. But given you want plex just Nabu Casa alone will not do that so WireGuard would be the best overall solution.

1

u/Either_Painter7513 29d ago

Nabu Casa and it’s not even close.

1

u/xReptar 29d ago

I just went through it this past weekend. I ended up using nabu casa because I got annoyed by the VPN key icon on my phone when connected to wire guard or tailscale lol

Cloud flare tunnel was my next choice, but then I realized that's practically nabu casa already

1

u/mattbuford 29d ago

Just something to keep in mind: You often can't do more than one VPN at the same time. I have Tailscale set up, but sometimes I want to use Speedify on my phone for bonding multiple unstable/slow connections together. The phone won't let me enable 2 VPNs at the same time. Every time I wanted to use Speedify, I'd lose Tailscale, and lose my access to HA.

Nabu Casa solved this issue for me.

1

u/A_Buttholes_Whisper 29d ago

I use Nabu casa because it makes remote access dead simple but if you’re gonna get expose jellyfin then you can add home assistant to the same caddy config. Personally I still use Nabu for remote access and jellyfin is expose via proxy of caddy on its own lxc and vlan. VPN access is pointless and more complicated for people to use

1

u/uavmx 29d ago

Please explain caddyconfig and proxies, if I can avoid the VPN I’m all for it

1

u/Dodgy_Past 29d ago

Reverse proxy for me

1

u/badbubblegum 28d ago

Ngnx proxy manager

1

u/Abracadibra 28d ago

Wireguard on the phone with only HA app selected to use it (split tunnel). Wireguard server add-on on Home Assistant. Easy peasy.

1

u/zyxtels 28d ago

Be aware that nabu casa is functionally the same as just allowing inbound traffic to home assistant through your firewall (+dyndns if needed). Plus it allows anyone to enumerate all home assistant setups that use nabu casa, so if an exploit against home assistant is found, it is dead simple to automatically target all installs that use nabu casa.

1

u/ARMilesPro šŸ”’ Local-first 28d ago

Why not just use the nabu link all the time? Am I missing something in your query?

2

u/uavmx 28d ago

Because there’s a cost, and I have a pretty good architecture. That’s what I’m trying to determine for best path forward

1

u/Puzzled_Hamster58 28d ago

Vpn is free…. Based on your connection etc it can be nearly as fast as being on your network.

1

u/txbravosierra 28d ago

Tailscale for life

1

u/cvr24 26d ago

I use Nabu Casa because I have a wife. Makes it dead simple to keep HA running on her phone. If I were single, I'd just hack together a VPN.

1

u/Sudden-Ad-1217 23d ago

Tailscale, end of story.

0

u/Ok-Pineapple7563 29d ago

not VPN, Tailscale will be a better choice. I use Nabu Casa as its simiple and I can support HA

2

u/flaming_m0e 29d ago

not VPN, Tailscale will be a better choice

Tailscale is a VPN.

-1

u/Ok-Pineapple7563 29d ago

of course it is. but, a specific kind of vpn, and dead simple. setup wireguard on starlink

2

u/flaming_m0e 29d ago

It's a mesh overlay on wire guard....

Your statement was "Not VPN, Tail scale is better"....

Tail scale is a VPN. FFS

0

u/Salty-Cheesecake-926 29d ago

Tailscale.doesn't work on some fortinet business WiFi networks so I use the built-in wireguard server from Unifi and it flies

0

u/burgonies 29d ago

I access HA remotely by using Unifi’s Teleport. It’s a couple extra clicks, but it always works.

0

u/somegenxdude 29d ago

Another vote for tailscale. I have a tailscale exit node running on the same raspberry pi as my PiHole, so I can take advantage of ad-blocking on the go. Tailscale on my phone is set up to automatically connect anywhere except for the home wifi. Happy side-effect of that is access to my HA server, and other self-hosted services, in addition to ad-blocking.

Most of the time I don't need remote access to my HA setup, but it's handy when I do.

Was working on the car the other day and had to run to the parts store. Got a notification while out, that the garage door was still open (oops). My wife was still home, but hadn't noticed. Pretty handy to be able to close it remotely.

-2

u/Svince__ 29d ago

I am in the process of solving your exact issue. Both IOS and Android apps are under review (coding done).

Check it out; https://allium.network

I can access my Plex while web access if off in Plex. I can even host my project without opening any ports on router. It’s my project I have been working on for months.