Updated: 28 September 2026 · Applies to: Ollama 0.34 on Ubuntu 24.04 / 26.04 LTS

By default Ollama listens on 127.0.0.1:11434, so only programs on the same server can talk to it. To use it from your laptop, another server or a container, you can change where it listens. Read the security note first: Ollama's API does not ask for a login. Anyone who can reach the port can use your GPU and your models.

Safest option: an SSH tunnel (no change needed)

From your own computer, forward the port through SSH. Ollama stays private, and the tunnel is encrypted:

ssh -L 11434:127.0.0.1:11434 user@YOUR-SERVER-IP

While this session is open, http://127.0.0.1:11434 on your computer reaches the server's Ollama.

Let other machines connect

  1. Open the service settings of Ollama:
    sudo systemctl edit ollama
  2. In the editor add these lines above the comment, save and close:
    [Service]
    Environment="OLLAMA_HOST=0.0.0.0:11434"
  3. Restart Ollama:
    sudo systemctl restart ollama
  4. Check that it now listens on all addresses:
    ss -ltnp | grep 11434
    You should see 0.0.0.0:11434.

Then restrict who can connect (important)

Allow only the addresses that need access, and block everyone else. With the Ubuntu firewall (ufw), first make sure your own SSH access stays open:

sudo ufw allow OpenSSH
sudo ufw allow from 203.0.113.10 to any port 11434 proto tcp
sudo ufw enable
sudo ufw status

Replace 203.0.113.10 with the IP address of the machine that may connect, and repeat the second command for each further address. If you already use another firewall, allow only those addresses there.

Ports that Docker publishes with -p can bypass ufw. Do not rely on ufw for containers: publish such ports on 127.0.0.1 only, for example -p 127.0.0.1:3000:8080.

Public access with a password

If you must offer the API on the internet, put a reverse proxy such as Nginx in front of Ollama that adds HTTPS and a login (HTTP basic authentication or an API key check), keep Ollama itself on 127.0.0.1, and open only the proxy's port. Our engineers can set this up for you (see below).

Test from the other machine

curl http://YOUR-SERVER-IP:11434

The answer Ollama is running means the connection works. A timeout means a firewall blocks the port.

Undo it

Run sudo systemctl edit ollama, delete the OLLAMA_HOST line, save and restart the service. Ollama then listens on 127.0.0.1 again.

Frequently asked questions

Do I need OLLAMA_HOST=0.0.0.0 for Open WebUI on the same server?
Not if Open WebUI runs with host networking; see How to install Open WebUI with Docker and connect it to Ollama?. You need it when the container reaches Ollama through the Docker bridge network; see How to fix "Open WebUI cannot connect to Ollama"?.

Can I change the port?
Yes: OLLAMA_HOST=0.0.0.0:8080. Ollama's default is 11434.

Official documentation: Ollama documentation: FAQ.

Want your own private AI without the setup work?

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)