I'm not sure how to do it

Search/google/wiki I end up down a confusing nginx route which seems to be pulled from the wiki, Native letsencrypt but that's just a cert? where does the authentication bit kick in. it doesn't talk about putting a cert on the accessing device.
Would prefer auth off for local network to make it simpler.
Can someone point me in the rough direction that makes sense and is secure?
I don't want to port forward without some sort of end to end cert or/and authentication going on.