I was at a conference in Lyon last month when my phone buzzed with a Lumen notification: person detected at the front door. I opened the app, pulled up the live stream, watched a delivery driver leave a package, and went back to my coffee. Total time: about 25 seconds. The guy next to me asked what I was looking at.
The thing is, Frigate NVR is a local-network application. Out of the box, it has no idea that the internet exists. When you leave home, your cameras — and all those AI detections, recordings, and live streams — become inaccessible. You've built this sophisticated home security setup and then you lock yourself out of it every time you walk out the door.
This took me about two hours to fix. Here's exactly what I did.
Why Frigate Is LAN-Only by Default
Frigate runs as a Docker container on your home server — NUC, Raspberry Pi, old PC, whatever you use. It exposes a web interface on port 5000 of that machine's local IP address. As long as your phone is on the same Wi-Fi network, everything works perfectly. Leave that network and the connection dies.
This is by design, not a bug. Frigate doesn't want to be responsible for securing your camera feed against the open internet. That's your job. There are three ways people typically solve it, and they're not all equally good.
Three Options, One Clear Winner
Port forwarding is the first thing people try: poke a hole in your router and expose Frigate directly to the internet. It works. It also means anyone who finds your IP can see your camera feeds — and Frigate's web interface wasn't built to be public-facing. I ran this for about a week before I thought harder about it and turned it off.
Cloudflare Tunnel is a popular free option. You install a small daemon on your server, it punches out to Cloudflare's edge, and you get a public HTTPS URL. The security story is much better. The downside: all your traffic routes through Cloudflare's servers, which adds latency, and live RTSP streams can be flaky because Cloudflare's free tier wasn't built for sustained video throughput. Event thumbnails load fine; live streams can stutter.
Tailscale is what I switched to and haven't looked back from. It creates a private encrypted mesh network between your devices. Your Frigate server and your iPhone both join the same Tailscale network and can talk to each other as if they're on the same LAN — except they're not. The connection is peer-to-peer, end-to-end encrypted, and bypasses Cloudflare entirely. The free tier covers up to 100 devices and three users, which is way more than a home setup needs.
The Actual Setup
I'll keep this brief because Tailscale's own documentation is excellent. The short version:
Install Tailscale on your Frigate server. If you're running Docker, the easiest approach is a separate Tailscale container in your compose file or installing it directly on the host OS — both work. Create a Tailscale account (free), authorize the machine, and it gets a stable 100.x.x.x IP that never changes, even if your server restarts or your ISP reassigns your home IP.
Install Tailscale on your iPhone from the App Store. Log into the same account. Your iPhone is now on the same virtual network as your server. From your phone, you can reach your Frigate instance at http://100.x.x.x:5000 from anywhere in the world, as long as both devices have an internet connection.
That's the entire infrastructure setup. Seriously. No certificates, no dynamic DNS, no nginx config, no firewall rules to manage. Tailscale handles all of it.
Connecting Lumen to Tailscale
In Lumen, open Settings and enter your Frigate host. Instead of your LAN IP (192.168.x.x), use the Tailscale IP (100.x.x.x) with the same port. If you have both saved, Lumen will use whichever one it can reach — local IP when you're home on Wi-Fi, Tailscale IP when you're out.
You can set up two hosts in Lumen: one for your local address and one for the Tailscale address. The app will try them in order and fall through to the next one if the first doesn't respond. In practice, connecting to your Tailscale IP always works regardless of where you are, so a lot of people just use that one for everything and skip the local-only address entirely.
Once it's connected: live streams, event thumbnails, detection history, recordings, two-way audio — everything works exactly the same as it does when you're home. The Tailscale layer is transparent to Lumen. There's no special "remote mode" to toggle.
What the Performance Actually Looks Like
This is the part that surprised me. I expected remote access to feel noticeably slower than local. The reality: for event review, it's imperceptible. Thumbnails and detection snapshots load in under a second over LTE. The Frigate API calls are small JSON payloads and they're fast.
Live streams are a little different. Tailscale is peer-to-peer when both endpoints can negotiate a direct path, which most home routers allow. In that case, the latency is surprisingly low — I see 150–300ms extra compared to local, which is fine for checking whether someone is at my door. If Tailscale has to relay through its DERP servers (because the NAT situation doesn't allow direct connection), it's closer to 500–800ms. Still watchable, but you notice it.
The single most useful thing over remote access isn't live streaming — it's event review. Frigate detects something, Lumen sends you a push notification (this uses Lumen's own notification service, not your Tailscale connection), you tap the notification, and you can see the detection snapshot and recorded clip immediately. That workflow works beautifully even on a weak cellular connection because the payload is just a few frames, not a continuous stream.
A Note on Push Notifications
Lumen's push notifications work independently of your Tailscale or LAN setup. When Frigate detects something, Lumen's companion service (running on your server, communicating with Frigate's MQTT events) sends a push notification through Apple's push infrastructure. This path doesn't go through your Tailscale network — it's outbound from your server, which already has internet access.
This means notifications arrive even if Tailscale is temporarily down. The notification gets there; the live view or recording you'd open from it needs the Tailscale connection to load. In my experience the two are essentially always available at the same time, but it's good to understand the architecture.
When Remote Access Actually Earns Its Keep
Package delivery is the obvious one. I work from a building in Paris, packages get delivered to my house, my neighbor has a key but I like knowing when something arrived. One glance at the Lumen notification and I know the package is there or — more importantly — isn't.
The subtler use case: peace of mind for things you can't control. Left the house in a rush and not sure if you closed the garage? Worried the dog knocked something over? Camera at the back door showing unexpected activity? These are the moments where remote access is the difference between a ten-second check and an hour of anxiety. Having it available makes those scenarios feel less stressful even when nothing is actually wrong.
I also use it to keep an eye on deliveries at my parents' house (they added me to their Tailscale network — the free tier includes multiple users). They have a Frigate camera at their front door, I have Lumen configured with their Tailscale IP, and they don't have to learn any camera app to get the benefit of the system.
Lumen — the Frigate NVR companion for iPhone, Mac, and Apple Watch
Live streams, AI detection events, recordings, geofencing alerts, and two-way audio — all in a native app. Free to download.
Download FreeTwo Hours of Setup, Permanent Payoff
I spent about 90 minutes getting Tailscale running — most of that was reading through their documentation and deciding between the Docker approach and the host install. The actual configuration was maybe 20 commands. Connecting Lumen took five minutes. I haven't touched it since, and it's been working without any intervention for months.
The thing that's underrated about this setup is how it changes how you think about your cameras. Before remote access, I checked Frigate when I was home because that was the only time I could. My home security system was effectively off whenever I wasn't home — which is exactly when you need it most. Now it's just always there. In your pocket. Checking in takes three seconds, and it almost always confirms nothing is wrong. Those three seconds are worth everything they cost.
Still deciding which Frigate app fits your setup? Our side-by-side Frigate app comparison covers native vs. browser-based access and what each option supports for remote monitoring.