Skip to content

Configure OpenClaw Network Hub: Connect and Secure Devices

Setting up networking for your devices often feels like a hurdle. You want your hardware to talk to each other without fighting firewall rules or manual IP configurations. This hub explains how OpenClaw connects, pairs, manages, and secures your devices across localhost, LAN, tailnet, and other private networks.

Most of what you do goes through the Gateway (openclaw gateway). This is a single process that stays running to manage your channel connections and the WebSocket control plane.

  • Loopback first: The Gateway WS defaults to ws://127.0.0.1:18789. You will need tokens if you want to bind to anything other than loopback.
  • One Gateway per host: I recommend this setup. If you need to keep things isolated, you can run multiple gateways with separate profiles and ports (Multiple Gateways).
  • Canvas host: This lives on the same port as the Gateway (/__openclaw__/canvas/, /__openclaw__/a2ui/). It is protected by Gateway auth when you bind it beyond loopback.
  • Remote access: You usually use an SSH tunnel, Tailscale VPN, or similar tools (Remote Access).

Key references for you:

OpenClaw uses specific workflows to ensure your devices trust each other:

Regarding local trust:

  • Local connections (like loopback or the gateway host’s own tailnet address) can be auto‑approved. This keeps your experience smooth when working on the same host.
  • Any clients on a non‑local tailnet or LAN still need you to give explicit pairing approval.

Finding and connecting to your devices happens through these methods:

These resources cover how specific nodes and protocols work:

Keeping your setup safe is a priority. Use these guides to configure and check your security:

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.