# Homelab behind DS-Lite

Reaching a TrueNAS homelab from outside without a public IPv4 address: split-horizon DNS, real certificates for internal services, and WireGuard over IPv6.

1. [Split-horizon DNS and a wildcard cert - real TLS for internal-only homelab services](https://knng.de/blog/split-horizon-dns-tls/): How TrueNAS, Pi-hole and Nginx Proxy Manager work together with Cloudflare DNS to give internal-only admin panels a valid certificate without exposing them publicly.
2. [WireGuard behind DS-Lite - wg-easy on TrueNAS, reachable over IPv6](https://knng.de/blog/wireguard-ds-lite/): How I run WireGuard on my TrueNAS with wg-easy behind a DS-Lite connection: an IPv6-only endpoint on my own domain, a split tunnel with Pi-hole as DNS, and finding the right MTU.

