Updated: 28 September 2026 · Applies to: Ollama 0.34 on Ubuntu 24.04 / 26.04 LTS
By default Ollama listens on 127.0.0.1:11434, so only programs on the same server can talk to it. To use it from your laptop, another server or a container, you can change where it listens. Read the security note first: Ollama's API does not ask for a login. Anyone who can reach the port can use your GPU and your models.
Safest option: an SSH tunnel (no change needed)
From your own computer, forward the port through SSH. Ollama stays private, and the tunnel is encrypted:
ssh -L 11434:127.0.0.1:11434 user@YOUR-SERVER-IP
While this session is open, http://127.0.0.1:11434 on your computer reaches the server's Ollama.
Let other machines connect
- Open the service settings of Ollama:
sudo systemctl edit ollama
- In the editor add these lines above the comment, save and close:
[Service] Environment="OLLAMA_HOST=0.0.0.0:11434"
- Restart Ollama:
sudo systemctl restart ollama
- Check that it now listens on all addresses:
ss -ltnp | grep 11434
You should see0.0.0.0:11434.
Then restrict who can connect (important)
Allow only the addresses that need access, and block everyone else. With the Ubuntu firewall (ufw), first make sure your own SSH access stays open:
sudo ufw allow OpenSSH sudo ufw allow from 203.0.113.10 to any port 11434 proto tcp sudo ufw enable sudo ufw status
Replace 203.0.113.10 with the IP address of the machine that may connect, and repeat the second command for each further address. If you already use another firewall, allow only those addresses there.
Ports that Docker publishes with -p can bypass ufw. Do not rely on ufw for containers: publish such ports on 127.0.0.1 only, for example -p 127.0.0.1:3000:8080.
Public access with a password
If you must offer the API on the internet, put a reverse proxy such as Nginx in front of Ollama that adds HTTPS and a login (HTTP basic authentication or an API key check), keep Ollama itself on 127.0.0.1, and open only the proxy's port. Our engineers can set this up for you (see below).
Test from the other machine
curl http://YOUR-SERVER-IP:11434
The answer Ollama is running means the connection works. A timeout means a firewall blocks the port.
Undo it
Run sudo systemctl edit ollama, delete the OLLAMA_HOST line, save and restart the service. Ollama then listens on 127.0.0.1 again.
Frequently asked questions
Do I need OLLAMA_HOST=0.0.0.0 for Open WebUI on the same server?
Not if Open WebUI runs with host networking; see How to install Open WebUI with Docker and connect it to Ollama?. You need it when the container reaches Ollama through the Docker bridge network; see How to fix "Open WebUI cannot connect to Ollama"?.
Can I change the port?
Yes: OLLAMA_HOST=0.0.0.0:8080. Ollama's default is 11434.
Official documentation: Ollama documentation: FAQ.
Want your own private AI without the setup work?
- Private LLM installation: we install and configure Ollama, the GPU driver and a chat interface on your own server.
- GPU dedicated servers: NVIDIA GPU servers for AI inference and training.
- AI implementation services: private LLMs, RAG, n8n automation and API integrations built on your own servers.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
