All tutorials

Business deployment

Private relay server on Linux and Raspberry Pi

Install the Remotly relay as a systemd service on any Linux distribution — including low‑power devices like a Raspberry Pi.

Why run your own relay?

Opening your main PC to the internet with port forwarding is a security risk, and leaving it on around the clock wastes power. A small Linux server or Raspberry Pi relay gives you the lowest possible latency, no port forwarding to the PCs you access, less power consumption, no GDPR concerns about third‑party servers and Wake‑on‑LAN from outside your network. Even if the relay is attacked, all data passing through it is encrypted with keys the server never has.

This guide assumes you already have SSH access to the Linux machine and the necessary permissions.

Version 2 of the Remotly Relay Server adds support for TLS and an access password. Even without TLS every connection is end‑to‑end encrypted with RSA-4096 and AES-256; TLS adds a redundant transport layer for strict firewalls at the cost of extra CPU. The access password prevents random users who discover your server's IP and port from using it.

1. Pick the package for your device

Run uname -m on the server and download the package that matches the result:

Raspberry Pi Zero and Raspberry Pi 1 (ARMv6) are not supported.

2. Installation

  1. Connect to the server over SSH (for example with OpenSSH, WinSCP or FileZilla). All following commands run on the server.
  2. Download the package for your architecture, e.g. for ARM64: wget https://downloads.mirillis.com/files/remotly‑relay‑linux‑arm64-v2.zip
  3. Unzip it: unzip remotly‑relay‑linux‑arm64-v2.zip — if unzip is missing, install it with sudo apt‑get update && sudo apt‑get install unzip.
  4. Move the files to /srv/remotly, where the service expects them: sudo mv remotly‑relay /srv/remotly
  5. Set the owner and permissions: sudo chown -R root:root /srv/remotly && sudo chmod -R 755 /srv/remotly. The configuration holds the password, so make it readable for root only: sudo chmod 600 /srv/remotly/config/remotly‑relay.json
uname -m
wget https://downloads.mirillis.com/files/remotly‑relay‑linux‑arm64-v2.zip
unzip remotly‑relay‑linux‑arm64-v2.zip
sudo mv remotly‑relay /srv/remotly
sudo chown -R root:root /srv/remotly
sudo chmod -R 755 /srv/remotly
sudo chmod 600 /srv/remotly/config/remotly‑relay.json

3. Configuration

Edit the configuration: sudo nano /srv/remotly/config/remotly‑relay.json. If possible use the standard HTTPS port 443 — it passes firewalls best.

Non‑TLS configuration:

{
  "tlsEnabled": false,
  "key": "",
  "cert": "",
  "forceTLS": false,
  "domain": "",
  "port": 443,
  "max_bandwidth": 40000000,
  "allowed_bandwidth": 30000000,
  "password": "PasswordPasswordPasswordPassword"
}

TLS configuration (set forceTLS to true to allow only TLS‑encapsulated connections):

{
  "tlsEnabled": true,
  "key": "/etc/letsencrypt/live/relay.example.com/privkey.pem",
  "cert": "/etc/letsencrypt/live/relay.example.com/fullchain.pem",
  "forceTLS": false,
  "domain": "relay.example.com",
  "port": 443,
  "max_bandwidth": 40000000,
  "allowed_bandwidth": 30000000,
  "password": "PasswordPasswordPasswordPassword"
}
  • tlsEnabled — enables additional TLS encryption; valid cert and key paths are required when true.
  • key — absolute path to the certificate's private key in PEM format, e.g. /etc/letsencrypt/live/relay.example.com/privkey.pem.
  • cert — absolute path to the full‑chain certificate in PEM format, e.g. /etc/letsencrypt/live/relay.example.com/fullchain.pem.
  • forceTLS — when true only TLS 1.2 / 1.3 connections are accepted; both client and host must use TLS.
  • domain — domain name assigned to the relay's IP in DNS (recommended, used for SNI).
  • port — port used by the relay for communication.
  • password — at least 32 characters to restrict access; leave empty to run without a password. A shorter non‑empty password prevents the server from starting.

4. Start the service

  1. Register the systemd service: sudo bash /srv/remotly/script/installremotlyrelay.sh
  2. Start it: sudo bash /srv/remotly/script/startremotlyrelay.sh
  3. Check that it runs: systemctl status remotly‑relay should show active (running).
sudo bash /srv/remotly/script/installremotlyrelay.sh
sudo bash /srv/remotly/script/startremotlyrelay.sh
systemctl status remotly‑relay

# to stop
sudo bash /srv/remotly/script/stopremotlyrelay.sh

Then open http://<relay IP>:<port>/connectionTest (or https://<relay domain>:<port>/connectionTest with TLS) in a browser. You should see the message OK.

The service starts with the system. After changing the configuration run the start script again (it restarts the service); stopremotlyrelay.sh stops it. The log is in /srv/remotly/logs/remotly‑relay.log.

5. Registering the relay in your account

Sign in at remotly.com, open Custom Relays and click Add relay server. Provide the IP address, the port(s) from remotly‑relay.json, a device name visible in the apps, the country code and the same password as in the configuration file.

Custom relays panel in the Remotly user panel
Add relay server form

When connecting to another computer with Force Connect Anywhere enabled, you should now see only the country code and name of your private relay.

Troubleshooting

  • connectionTest shows OK but relayed connections fail: your server is probably not reachable from outside your network. Configure port forwarding on your public IP and test from an external browser.
  • connectionTest shows OK but connections go through an official Remotly relay: you have not added the custom relay to your account in the web panel.
  • The relay runs but connectionTest is unreachable: from inside your network, check that the server firewall does not block the relay port; from outside only, fix the port forwarding on your router.

Questions? Visit the Remotly community.

This website uses cookies to improve your experience while you navigate through the website. Out of these, those that are categorized as necessary are stored on your browser and are used to run basic functionalities of the website.

We also use third‑party cookies that help us analyze and understand how you use this website. They will only be stored in your browser with your consent and you have the opportunity to opt out of them. However, opting out may affect your browsing experience.

NecessaryAlways active

Necessary cookies are absolutely necessary for the website to function properly. These cookies ensure basic functionalities and security features of the website on an anonymous basis.

CookieRetention periodDescription
cookie_consent1 yearStores whether or not the user has consented to the use of cookies. It does not store any personal data.
NEXT_LOCALE1 yearStores language setting selected by user.
themeuntil clearedStores the light or dark theme selected by user (browser storage).
hCaptchasessionSet by the hCaptcha service on the contact and order forms to identify bots and protect the website against spam.
device_token6 monthsCookie used for user/device verification.
session_idsession / 1 monthCookie used to keep user session alive.
logged_insession / 1 monthCookie used to keep user session alive.