Blog
Connection Modes Explained: Local Network vs. Cloudflare Tunnel
Tactic Remote supports two connection modes: Local Network for sub-100ms latency on the same Wi-Fi, and Cloudflare Tunnel for secure access from anywhere. Here's how they work and when to use each.
Follow product and engineering updates from this channel.
Browse categoryOne of the most common questions from new Tactic Remote users is: "Should I use Local Network mode or Cloudflare Tunnel?" The answer depends on how and where you work. This post explains both modes in detail — how they differ architecturally, their performance and security characteristics, and how Tactic Remote handles transitions between them.
Two Modes, One Interface
Before diving into the technical details, the most important point: the iPhone app works identically regardless of which connection mode you use. Session management, terminal streaming, approval workflows, push notifications — all of these function the same whether your phone is on the same Wi-Fi as your Mac or on a cellular network across the country.
The connection mode only affects how your iPhone reaches the companion app's API. Everything above the transport layer is identical.
Local Network Mode
Local Network mode is the default and the simplest configuration. Your Mac companion app binds its HTTP/WebSocket server to a port on your local network, and your iPhone connects directly to that IP address and port.
How It Works
- The companion app starts its embedded server on port 48736 (configurable).
- The Mac advertises its local IP address (e.g.,
192.168.1.42:48736). - The iPhone connects to that address over your local Wi-Fi network.
- All communication travels directly between the two devices over the local network — no intermediaries.
Performance
Local Network mode provides the best possible latency because packets travel the shortest possible path: iPhone to router to Mac (or directly via Wi-Fi Direct in some network configurations).
| Metric | Typical Range |
|---|---|
| Connection establishment | 30-80ms |
| Terminal update latency | 40-100ms |
| Approval round-trip | 60-120ms |
| WebSocket ping | 5-20ms |
| Reconnection after brief disconnect | 0.5-1.5s |
These numbers assume a standard home or office Wi-Fi network. Congested networks (conference Wi-Fi, for example) may show higher latency, but Local Network mode typically outperforms tunneled connections on the same network.
Security Profile
Local Network mode's security rests on two layers:
Network isolation. Your local network acts as the perimeter. Only devices on the same network can reach the companion app's port. This is sufficient for most home and office environments.
Token authentication. Every API request requires a bearer token. Even if an attacker is on your local network, they cannot interact with the companion app without the token.
What Local Network mode does not provide: protection against a compromised device on your network that has somehow obtained your token. For environments where you cannot trust the local network (shared coworking spaces, hotel Wi-Fi), Cloudflare Tunnel mode is recommended.
Limitations
- Same network required. Your iPhone and Mac must be on the same Wi-Fi network (or reachable via the same LAN). The moment you leave your home network, the connection drops.
- IP address changes. If your Mac's local IP changes (DHCP lease renewal, reconnecting to Wi-Fi), you need to update the iPhone's connection settings. The QR code flow mitigates this by re-scanning, but it's still a manual step.
- No access from cellular. By definition, cellular data does not route to your home network.
Cloudflare Tunnel Mode
Cloudflare Tunnel mode creates a persistent outbound connection from your Mac to Cloudflare's global edge network. Your iPhone connects to a Cloudflare URL, and Cloudflare routes the traffic back through the tunnel to your Mac.
How It Works
- The companion app launches
cloudflaredas a managed child process with your tunnel credentials. cloudflaredestablishes an outbound connection to Cloudflare's nearest edge server (typically 2-4 simultaneous connections for redundancy).- Your tunnel is reachable at a URL you configured (e.g.,
claude.yourdomain.com). - The iPhone connects to that URL. Cloudflare routes the request through its network to the
cloudflaredprocess on your Mac. cloudflaredforwards the request to the companion app's local server.
The key architectural property: by default your Mac does not require direct inbound internet connections for this flow. The tunnel is outbound-initiated, which means no router port-forwarding rules in the standard setup.
Performance
Cloudflare Tunnel adds measurable latency because traffic routes through Cloudflare's edge network:
| Metric | Typical Range |
|---|---|
| Connection establishment | 150-300ms |
| Terminal update latency | 100-250ms |
| Approval round-trip | 200-400ms |
| WebSocket ping | 40-120ms |
| Reconnection after brief disconnect | 2-4s |
The latency varies based on your geographic distance from the nearest Cloudflare edge server. Cloudflare operates in over 300 cities, so most users in urban areas see latency toward the lower end of these ranges. Users in regions with fewer Cloudflare points of presence may experience higher latency.
In practice, this latency is noticeable during the first few minutes of use but quickly becomes unremarkable. Terminal output still scrolls smoothly, and approval interactions remain responsive enough that most users handle them within 15 seconds of the notification.
Security Profile
Cloudflare Tunnel provides a stronger security posture than Local Network mode in several ways:
Greatly reduced inbound attack surface. In the standard setup, your Mac is not directly exposed as a public internet listener, which reduces port scanning and brute-force exposure.
TLS encryption. All traffic between your iPhone and Cloudflare, and between Cloudflare and your Mac, is encrypted with TLS. Combined with Tactic Remote's token authentication, this provides two independent security layers.
Cloudflare's DDoS and bot protection applies to your tunnel endpoint by default, adding protection against automated attacks.
The tradeoff: traffic transits through Cloudflare's network. While encrypted, this means Cloudflare is a trusted intermediary. For most individual developers, this is an acceptable tradeoff given the convenience. For sensitive environments, consult our Security and Network Hardening guide for additional measures.
Limitations
- Requires a Cloudflare account. You need a free Cloudflare account and a domain managed by Cloudflare. The tunnel itself is free, but the initial DNS configuration takes a few minutes.
- Cloudflare availability dependency. If Cloudflare experiences an outage, tunnel-mode access is unavailable. This is rare (Cloudflare's uptime record is strong) but worth noting.
- Higher latency than local mode. As detailed above, every interaction adds 50-200ms compared to Local Network mode.
The QR Code Connection Flow
Both modes use the same QR code flow for initial pairing, but the QR code contents differ:
Local Network QR code encodes: http://<local-ip>:<port> plus the authentication token.
Cloudflare Tunnel QR code encodes: https://<your-tunnel-domain> plus the authentication token.
The iPhone app detects which mode it's connecting to based on the URL scheme and network characteristics. If the QR code contains a local IP address, the app configures for Local Network mode. If it contains an HTTPS domain, it configures for Cloudflare Tunnel mode.
To switch modes, you generate a new QR code from the companion app's menu bar dropdown and scan it on your iPhone. The app replaces the previous connection configuration. The entire mode switch takes under 10 seconds.
Side-by-Side Comparison
| Factor | Local Network | Cloudflare Tunnel |
|---|---|---|
| Setup complexity | Minimal (automatic) | Moderate (5-10 min) |
| Latency | 40-100ms | 100-250ms |
| Works off-network | No | Yes |
| Requires Cloudflare account | No | Yes |
| Inbound ports required | None (LAN only) | None |
| Third-party trust | None | Cloudflare |
| Cost | Free | Free (Cloudflare free tier) |
| Reconnection speed | 0.5-1.5s | 2-4s |
| Best for | Home/office desk work | Commuting, travel, remote |
Recommended Usage Patterns
Use Local Network mode when you're at your desk or on the same network as your Mac. The lower latency makes terminal streaming noticeably smoother, and there's no third-party dependency.
Use Cloudflare Tunnel mode when you need access from outside your local network — commuting, traveling, working from a different location, or when you want to start a task at home and monitor it from the office.
Use both by configuring Cloudflare Tunnel on your Mac but connecting via Local Network mode when you're home. The companion app can serve both modes simultaneously. Your iPhone can store both connection profiles, and switching between them is a single tap in the app's connection settings.
Many of our users configure Cloudflare Tunnel once as insurance and use Local Network mode day-to-day. When they leave home, they switch to the tunnel profile. This gives them the best latency when available and remote access when needed.
What's Next
We're exploring automatic mode selection that detects when your iPhone is on the same network as your Mac and routes locally, falling back to Cloudflare Tunnel when you leave. This would eliminate manual mode switching entirely. Early testing shows reliable network detection on iOS, but edge cases around VPNs and split-tunnel configurations still need work.
For setup instructions, see Getting Started for Local Network mode and Cloudflare Tunnel Setup for remote access configuration.
Try Tactic Remote
Control your coding Agents from your phone
Connect to Claude Code, Codex, and other Agents on your Mac, Windows, or Linux computer. Check progress and send the next instruction from iPhone or iPad.