Guide

Nextcloud remote access with your own name

Nextcloud is built to be reached from outside, but it is strict about the name it answers to and about proxies. Get those two things right and the rest follows. This guide covers both the All‑in‑One (AIO) install and a manual one.

Updated · Checked against Nextcloud 35 and Nextcloud All-in-One documentation · 5 min read

Ports (AIO, no proxy)
443/TCP, 3478/TCP+UDP for Talk
AIO behind a proxy
APACHE_PORT=11000
Key settings
trusted_domains, trusted_proxies, overwriteprotocol
Time
30–60 minutes

Before you start

  • You need a public IP address – check for CGNAT. If you only need Nextcloud for yourself, a VPN works too, and the desktop and phone apps are happy with it.
  • Pick the name now, for example cloud.yourname.uk.app. Changing Nextcloud’s name later is possible but fiddly.
  • Set up dynamic DNS so home.yourname.uk.app follows your IP (router, NAS, or the cron job in the start guide with your uk.app DDNS token), and add a CNAME record cloud → home.yourname.uk.app.

Route 1: Nextcloud All‑in‑One

AIO runs Nextcloud and everything it needs in containers, managed from a small “mastercontainer” with its own admin page on port 8080.

AIO on its own (no other web server)

If nothing else on your network needs port 443, let AIO handle HTTPS itself. Forward these ports from your router to the AIO machine:

  • 443/TCP – Nextcloud itself (AIO gets its certificate automatically).
  • 443/UDP – optional, for HTTP/3.
  • 3478/TCP and 3478/UDP – only if you enable Nextcloud Talk; it is the TURN server for calls.

Open the AIO interface at https://<LAN IP address>:8080 – by IP address, not by name, as the AIO documentation warns HSTS can lock you out otherwise – accept its self‑signed certificate, enter cloud.yourname.uk.app and let it validate the domain. Validation fails if port 443 doesn’t reach AIO from the internet, so do the router step first. Don’t forward 8080.

AIO behind your existing reverse proxy

If you already run Caddy or Nginx Proxy Manager on 443, start AIO with the Apache port moved, as the AIO reverse‑proxy documentation describes:

AIO environment
# add to the mastercontainer's docker run command (or compose environment)
--env APACHE_PORT=11000 \
--env APACHE_IP_BINDING=0.0.0.0
Caddyfile on the proxy
cloud.yourname.uk.app {
	reverse_proxy 192.168.1.40:11000
}

Use APACHE_IP_BINDING=127.0.0.1 instead if the proxy runs on the same host, and point it at localhost:11000. If the proxy connects from another address, add that address to Nextcloud’s trusted proxies, as the AIO documentation instructs:

sudo docker exec --user www-data -it nextcloud-aio-nextcloud \
  php occ config:system:set trusted_proxies 2 --value=192.168.1.30

Forward 443 to the proxy, not to AIO, plus 3478 to the AIO host if you use Talk.

Route 2: a manual install behind a reverse proxy

With a package, a container you built yourself or a hand install, you configure Nextcloud’s config/config.php. The easiest way is occ, run as the web server user:

occ (Debian/Ubuntu paths)
cd /var/www/nextcloud
sudo -u www-data php occ config:system:set trusted_domains 1 --value=cloud.yourname.uk.app
sudo -u www-data php occ config:system:set trusted_proxies 0 --value=192.168.1.40
sudo -u www-data php occ config:system:set overwriteprotocol --value=https
sudo -u www-data php occ config:system:set overwrite.cli.url --value=https://cloud.yourname.uk.app

What each one does:

  • trusted_domains – the names Nextcloud agrees to answer to. Without your name here you get “Access through untrusted domain”.
  • trusted_proxies – the proxy’s LAN address, so Nextcloud believes the X-Forwarded-For header. This matters for brute‑force protection: otherwise every failed login looks as if it came from the proxy, and Nextcloud throttles everyone.
  • overwriteprotocol – tells Nextcloud that visitors use HTTPS even though the proxy talks to it over HTTP, so links, redirects and the login flow for the apps use https://.
  • overwrite.cli.url – the address used in emails and background jobs.

Note

Keep the existing trusted_domains entry 0 (usually the LAN address) so you can still sign in locally if the proxy is down.

Reverse proxy details that matter for Nextcloud

  • Upload size and timeouts. Caddy has no upload limit by default. Plain Nginx and some Nginx‑based tools default to small request bodies, so raise client_max_body_size (for example 10G) and the read timeout if big uploads fail.
  • HSTS. Nextcloud’s admin overview warns if the Strict-Transport-Security header is missing. On a .app name browsers enforce HTTPS anyway, but adding the header on the proxy clears the warning.
  • CalDAV and CardDAV discovery. If the overview warns about /.well-known/caldav, add redirects on the proxy to /remote.php/dav/.

The HTTPS guide covers the proxy and certificate set‑up itself.

Forward the ports

For most set‑ups: TCP 443 (and 80 if your certificates use HTTP‑01) to the proxy or to AIO, plus 3478 TCP/UDP to the Talk host if you use calls. Router guides: BT, Virgin Media, Sky, TP‑Link, OpenWrt.

Lock it down

  • Install the Two‑Factor TOTP Provider app and require two‑factor sign‑in for administrators (Administration settings → Security).
  • Leave brute‑force protection on – it is on by default – and make sure trusted_proxies is set so it sees real addresses.
  • Use app passwords for the desktop and phone clients rather than your main password.
  • Keep Nextcloud and its apps updated. AIO does this with its update and backup schedule; enable daily backups in the AIO interface.
  • Run Nextcloud’s own check under Administration settings → Overview and the public Nextcloud security scan once you are online.

Check it from outside

  1. Does the name point home? Look up cloud.yourname.uk.app with the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one.
  2. Is the port open from the internet? Run the open port checker against port 443, port 3478. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
  3. Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
  4. Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.

If it doesn’t work

  • “Access through untrusted domain” – add the exact name to trusted_domains.
  • Login loops back to the login page, or apps say “not using HTTPS” – overwriteprotocol is missing.
  • Everyone gets slowed down after a few failed logins – trusted_proxies is missing or wrong, so brute‑force protection is punishing the proxy.
  • AIO domain validation fails – port 443 isn’t reaching AIO from outside. Check with the port checker, and look for double NAT.

A name for your next idea

Give your website, home server or next project a memorable address: yourname.uk.app. Choose your name and check availability before registering.

Find your name

Questions people ask

Can I run Nextcloud on a port other than 443?

The AIO project doesn’t support that: Nextcloud always redirects to 443. With a manual install it can work, but apps and sharing links are much happier on the standard port. If 443 is taken, use a reverse proxy and a separate name.

Do I need to forward port 80?

Only if your certificate method uses HTTP‑01. AIO without a proxy needs only 443 for Nextcloud itself; port 80 is used for the mastercontainer’s optional certificate on 8443.

Is Cloudflare Tunnel a good idea for Nextcloud?

It works, but the AIO documentation lists real limits: 100 MB uploads on the free plan unless chunking is used, a 100‑second request timeout, Talk’s TURN server doesn’t work through it, and TLS is terminated on Cloudflare’s side.

What about the free deSEC name that AIO offers?

It is a good option if you don’t have a domain. If you do, use your own; the steps are the same.

Sources and further reading

We check each guide against the vendor’s own documentation and support forums. If something has changed on your firmware, tell us.

Partners