# Away from home

> Watch your cameras and get alerts with pictures away from home, over Tailscale or another VPN, Cloudflare Tunnel and Access, or a reverse proxy — and what still works when your server can't be reached.

Fregata Mobile talks to your NVR directly. There's no Fregata cloud in between, so to watch your
cameras away from home your iPhone needs a way to reach your server from outside. Give the app
that address under **Away**, in the welcome walkthrough or in **Settings › Connection**, and it
uses it whenever the home address doesn't answer.

## What needs the Away address

| | At home only | With an Away address |
|---|---|---|
| Alerts arrive | ✓ | ✓ |
| The picture and clip in an alert | At home only | ✓ |
| Your own alert wording | At home only | ✓ |
| Live view, recordings, Review, Explore | At home only | ✓ |
| Widgets and the Apple Watch | At home only | ✓ |

Alerts reach your iPhone however it's connected, because they travel through Apple's push
service. Everything else comes from your server, so your iPhone has to reach it. When it can't,
an alert still arrives, in Frigate's own wording and without a picture.

## Choose a route

### Tailscale or another VPN

The simplest and safest: your server stays off the internet, and your iPhone joins your home
network from wherever it is.

1. Install Tailscale (or your VPN) on the machine running Frigate and on your iPhone, and sign both in to the same account.
2. Find the server's Tailscale address, such as `100.101.102.103` or its MagicDNS name.
3. In **Settings › Connection**, put `https://`, that address and Frigate's port under **Away**, for example `https://100.101.102.103:8971`.
4. Tap **Test connection** with the VPN on and Wi-Fi off. The **Away** result should say **Connected**.

The VPN has to be connected for the app to reach the server. Tailscale's **VPN On Demand**
keeps it connected without your having to think about it.

Because a VPN encrypts everything it carries, an `http://` address is acceptable over one. The
app notes when an **Away** address uses `http://`, as a reminder for the routes that don't.

### Cloudflare Tunnel

A tunnel gives your server a public `https://` address without opening a port on your router.

1. Point a Cloudflare Tunnel at Frigate's port 8971, which signs people in, never port 5000, which doesn't.
2. Put the tunnel's address under **Away**, for example `https://nvr.example.com`.
3. Tap **Test connection** away from your home Wi-Fi.

Cloudflare's certificate is one iOS trusts, so there's no certificate question.

### Cloudflare Access

If you put Cloudflare Access in front of the tunnel, it asks for its own sign-in before Frigate
does, which the app can't fill in. Give the app a service token instead:

1. In Cloudflare Zero Trust, create a service token, and add a policy to your Access application that allows it (the **Service Auth** action).
2. In the app, open **Settings › Connection › Advanced**.
3. Tap **Add a header** and enter `CF-Access-Client-Id` with the token's client ID.
4. Tap **Add a header** again and enter `CF-Access-Client-Secret` with its secret.
5. Tap **Test connection**.

The app sends both headers with every request, including the ones made in the background to put
a picture in an alert. The values are kept in the Keychain, and with iCloud Sync on they reach
your other devices through iCloud Keychain, sometimes a little after the rest of the server's
settings.

**Open in Safari**, on the server status screen, can't send the headers, so Safari shows
Cloudflare's own sign-in instead.

### A reverse proxy

Any reverse proxy in front of Frigate works: nginx, Caddy, Traefik, Nginx Proxy Manager. Proxy
to Frigate's port 8971, and pass WebSocket connections through, which live video and the app's
live updates use. With a certificate from Let's Encrypt or another authority, there's no
certificate question.

If the proxy adds a login page of its own, the app can't get past it, and **Test connection**
says the reply wasn't something it could read. Use custom headers if the proxy supports them,
or a VPN instead.

## Things to know

- **Use Frigate's authenticated port, 8971, for alerts too.** Port 8971 asks for a sign-in;
  port 5000 doesn't, and should never be reachable from the internet. Live view works over 5000,
  but while sign-in is on, alerts registered over it are silently lost: Frigate files them under
  an `anonymous` user that has no account. Sign-in itself can be off for alerts, with one rare
  exception; see [Compatibility](https://mobile.fregata.app/docs/reference/compatibility/#servers).
- **The same address for both?** If your **Away** address also works at home, for example a
  domain your router resolves locally, put it under **Away** and leave **At home** empty.
- **Data use.** Live video uses as much data as the stream you pick. With Frigate, choose a
  smaller stream from the quality chip on the live view (see [Live view](https://mobile.fregata.app/docs/cameras/live/));
  on Fregata NVR, live view opens at a lighter quality away from home by itself. Clips in
  alerts download over mobile data too: **Upgrade to video** in **Settings › Device
  Notification Settings** turns them off.
- **Which address am I using?** **Settings › Connection** shows it under **Now**.
