Skip to content
BotServBotServ
OllamaNetworkingRemoteOLLAMA_HOSTOLLAMA_ORIGINSFirewallReverse ProxySecurity

Ollama Network Access: Remote Setup

Make Ollama accessible over network: OLLAMA_HOST, OLLAMA_ORIGINS, firewall, reverse proxy and secure remote configuration.

S

schutzgeist

9 min read
Ollama Network Access: Remote Setup

Setting Up Ollama Network Access: Enable Remote Connections

What this article covers

  • How to reach Ollama from other devices on your network.
  • Which environment variables you need to set.
  • How to configure your firewall correctly.
  • What security risks exist and how to minimize them.
  • How to secure Ollama with reverse proxy, TLS, and VPN.

Introduction: Understanding Ollama network access

By default, Ollama listens only locally after installation. This means only programs running on the same machine can access the API. But once you deploy Ollama on a server or want to use it from a laptop, tablet, or another team member’s device, you need network access. This article walks you through enabling Ollama across your network and which security measures matter most.

Why do you need network access?

Imagine you have a powerful server with a good GPU sitting in your basement. On this server, Ollama runs with a large model like Llama 3.1. Your laptop in the living room has no GPU and would be far too slow for that model. By making Ollama accessible over your network, you can reach the server from your laptop and still get fast responses.

Here’s another scenario: in a team, every developer wants to use the same local AI without each person downloading and running their own model. A central Ollama server on the network solves this. You’ll find more context in Running LLMs locally.

Ollama network access at a glance

Ollama listens only on 127.0.0.1 by default, which is localhost. To make it accessible over your network, you set the OLLAMA_HOST environment variable to 0.0.0.0:11434. Then you open the port in your firewall and configure OLLAMA_ORIGINS if you need browser access. For secure setups, a reverse proxy with TLS or a VPN like Tailscale is recommended.

Who is this article for?

This guide is for beginners making Ollama accessible beyond their local machine for the first time. You don’t need deep networking knowledge, but should be comfortable at the command line. If you haven’t installed Ollama yet, start with the Ollama overview and installation guide.

Key terms for Ollama network access

TermDefinition
OLLAMA_HOSTEnvironment variable that sets the address and port for Ollama
OLLAMA_ORIGINSEnvironment variable for allowed origins in CORS requests
localhostAddress 127.0.0.1, reachable only from your own machine
0.0.0.0Address that listens on all network interfaces
PortNumber identifying a network connection; Ollama uses 11434 by default
FirewallNetwork filter that controls incoming and outgoing connections
CORSCross-Origin Resource Sharing, a mechanism for browser access
Reverse ProxyServer that sits in front of Ollama and forwards requests
TLSEncryption protocol for secure network connections
TailscaleVPN solution for simple and secure network connections

Default behavior: localhost only

After installation, Ollama listens on 127.0.0.1:11434. This means only programs on the same machine can access the API. A request from another device on the network fails because the connection is rejected outright.

You can verify this by checking which addresses Ollama is bound to:

ss -tlnp | grep ollama

On macOS and Windows, use netstat or lsof instead. The output shows that Ollama is bound only to 127.0.0.1. This is a deliberate security measure: no one on the network can access your models without permission.

Step 1: Set OLLAMA_HOST

To make Ollama listen on all network interfaces, set the OLLAMA_HOST environment variable to 0.0.0.0:11434. On Linux, add this to the service file:

sudo systemctl edit ollama

In the editor, add the following:

[Service]
Environment="OLLAMA_HOST=0.0.0.0:11434"

Then reload the configuration and restart the service:

sudo systemctl daemon-reload
sudo systemctl restart ollama

On macOS, set the variable in your shell before starting Ollama:

export OLLAMA_HOST=0.0.0.0:11434
ollama serve

On Windows, use the system environment variables. Open the environment variables settings, add OLLAMA_HOST with the value 0.0.0.0:11434, and restart Ollama.

After this change, Ollama listens on all available network interfaces. Verify this again with ss -tlnp. For more configuration details, see Ollama Configuration.

Step 2: Configure OLLAMA_ORIGINS

If you want to access Ollama from a browser, such as through Open WebUI or a custom web application, you need the OLLAMA_ORIGINS variable. Without it, Ollama blocks requests from a different origin with a CORS error.

Set the allowed origins as a comma-separated list:

[Service]
Environment="OLLAMA_HOST=0.0.0.0:11434"
Environment="OLLAMA_ORIGINS=http://192.168.1.50:3000,http://mein-server:3000"

For testing, you can allow all origins, but this is not recommended for permanent setups:

Environment="OLLAMA_ORIGINS=*"

Restart the service afterward. If you see CORS errors in the browser, OLLAMA_ORIGINS is usually misconfigured.

Step 3: Open the firewall

Even if Ollama is now listening on 0.0.0.0, your firewall may still block incoming connections. You must open port 11434.

Linux with ufw:

sudo ufw allow 11434/tcp
sudo ufw reload

Better to restrict access to your local network instead of opening the port globally:

sudo ufw allow from 192.168.1.0/24 to any port 11434

For more on firewall configuration, see Firewall.

Windows:

New-NetFirewallRule -DisplayName "Ollama" -Direction Inbound -Protocol TCP -LocalPort 11434 -Action Allow

macOS:

The macOS firewall doesn’t block incoming connections by default unless explicitly enabled. If you use a firewall app, add an exception for port 11434 there.

Step 4: Access from other devices

Now you can reach Ollama from another machine on your network. First, find the IP address of your Ollama server:

ip addr

Let’s say the address is 192.168.1.100. Test from another device:

curl http://192.168.1.100:11434/api/tags

If you get a JSON response with your available models, network access works. A simple generation request looks like this:

curl http://192.168.1.100:11434/api/generate -d '{
  "model": "llama3",
  "prompt": "Hello from the network",
  "stream": false
}'

In your browser, you can use Open WebUI and enter http://192.168.1.100:11434 as the Ollama address. For more on the API, see Ollama API.

Security: What You Need to Know

Ollama has no authentication by default. Anyone who reaches the port can load models, send requests, and receive responses. This is acceptable on a local network, but becomes problematic once Ollama is accessible from the internet.

The main risks are:

  • Unauthorized users can consume your models and computing resources.
  • Models may return sensitive information visible to third parties.
  • Misconfigured firewalls can expose Ollama to the entire internet.

Follow these rules to protect your setup:

  1. Never expose Ollama directly to the internet. Always use a firewall, reverse proxy, or VPN.
  2. Restrict port 11434 to trusted networks. Limit access to your LAN or VPN.
  3. Add authentication via reverse proxy. Place Nginx with Basic Auth or an Auth plugin in front.
  4. Use TLS for encrypted connections. Without TLS, requests travel unencrypted across your network.

For more details, see Network Security.

Reverse Proxy with Nginx

A reverse proxy is the most secure way to expose Ollama on your network or over the internet. Nginx accepts requests, verifies permissions, and forwards them to Ollama.

A basic Nginx configuration looks like this:

server {
    listen 80;
    server_name ollama.example.local;

    location / {
        proxy_pass http://127.0.0.1:11434;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # Support streaming
        proxy_buffering off;
        proxy_read_timeout 300s;
    }
}

To add Basic Auth, create a password file:

sudo htpasswd -c /etc/nginx/.htpasswd meinuser

Then add authentication to your Nginx configuration:

auth_basic "Ollama";
auth_basic_user_file /etc/nginx/.htpasswd;

For TLS, use Let’s Encrypt or a self-signed certificate. With certbot, you can set up TLS automatically:

sudo certbot --nginx -d ollama.example.com

Afterward, Ollama is accessible at https://ollama.example.com with authentication and encryption. See Reverse Proxy for more details.

VPN with Tailscale

If you’d rather not expose Ollama through a reverse proxy, a VPN is a good alternative. Tailscale is particularly easy to set up and requires no port forwarding rules.

Here’s how it works:

  1. Install Tailscale on the Ollama server and on all devices that need access.
  2. Sign all devices in with the same Tailscale account.
  3. Set OLLAMA_HOST to the server’s Tailscale IP or to 0.0.0.0:11434.
  4. Access Ollama using the Tailscale IP.
curl http://100.x.y.z:11434/api/tags

Tailscale encrypts the connection automatically. You don’t need a reverse proxy or port forwarding. This is especially convenient if you want to access Ollama from outside your home network. See Tailscale for more.

Common Network Access Pitfalls

  1. OLLAMA_HOST not set. Ollama continues to listen only on localhost, and connections from elsewhere fail.
  2. Firewall blocks the port. Ollama is configured correctly, but your firewall prevents incoming connections.
  3. CORS errors in the browser. OLLAMA_ORIGINS is not set or doesn’t include the correct origin.
  4. Wrong IP address. You’re trying to reach localhost instead of your server’s network IP.
  5. No restart after changes. Environment variables take effect only after restarting the service.
  6. Port already in use. Another service is already using port 11434. Check with ss -tlnp | grep 11434.
  7. Docker port mapping forgotten. With Docker, you must forward the port using -p 11434:11434.
  8. Ollama on WSL2. WSL2 has its own IP address, separate from your Windows IP. You need port forwarding or WSL2 mirror network configuration.

For additional help, see Ollama Troubleshooting.

Hardware, Costs, and Security for Network Access

Network access doesn’t change hardware requirements. Your Ollama server still needs sufficient RAM and ideally a GPU. Accessing devices don’t need their own GPU since computation happens on the server.

Costs come only from hardware and electricity. Ollama itself is free and open source. A reverse proxy with Let’s Encrypt has no cost either. Tailscale is free for personal use with up to 100 devices.

Network access is the most security-critical part of your Ollama setup. Without authentication and encryption, Ollama becomes an open door. Invest time in a reverse proxy or VPN before making Ollama accessible on your network.

Further Reading and Resources on Network Access

FAQ: Ollama Network Access - Common Questions

How do I make Ollama accessible on my network?

Set the environment variable OLLAMA_HOST to 0.0.0.0:11434, open port 11434 in your firewall, and restart the service. Then you can access it from other devices using your server’s IP address.

What does OLLAMA_HOST do?

OLLAMA_HOST specifies the address and port Ollama listens on. The default is 127.0.0.1:11434, which means localhost only. With 0.0.0.0:11434, Ollama listens on all network interfaces.

What is OLLAMA_ORIGINS?

OLLAMA_ORIGINS controls which origins are allowed for browser requests. Without this variable, Ollama blocks CORS requests. Enter your web application addresses as comma-separated values.

How do I access Ollama from the browser?

You need OLLAMA_ORIGINS set to your web application’s origin, for example http://192.168.1.50:3000. Then you can send fetch requests to the Ollama API from JavaScript.

Is Ollama safe without authentication?

No. Ollama has no authentication by default. Anyone who reaches the port can use your models. Use a reverse proxy with Basic Auth or a VPN like Tailscale.

Can I make Ollama accessible over the internet?

Yes, but only with a reverse proxy that has TLS and authentication, or through a VPN. Never expose Ollama directly to the internet without protection.

Which port does Ollama use?

Port 11434 by default. You can change this via OLLAMA_HOST, for example 0.0.0.0:8080 for port 8080.

Why am I getting a CORS error?

Probably because OLLAMA_ORIGINS isn’t set or doesn’t include the origin you’re accessing from. Add your application’s origin and restart Ollama.

Does Ollama work with Tailscale?

Yes. Install Tailscale on your server and accessing devices, set OLLAMA_HOST to 0.0.0.0:11434, and access it via the Tailscale IP. The connection is automatically encrypted.

Do I need to adjust my firewall?

Yes, if other devices need to reach Ollama. Open port 11434 for TCP, ideally restricted to your local network or VPN.

How do I check if Ollama is accessible on my network?

From another device, run curl http://SERVER-IP:11434/api/tags. If you get a JSON response with your models, network access is working.

Can I run multiple Ollama instances on my network?

Yes. Each instance uses its own port and IP address. Set OLLAMA_HOST accordingly and open the necessary ports in your firewall.

References and Further Reading

Back to Blog
Share:

Related Posts