Skip to content
The 31 guidesFREN中文
Guides
Part 3 · guide 1 of 4 Level: Easy Reading time: 10 min Platforms: Linux, Mac and Windows

Tailscale: your private network

Reach your machine from anywhere, a café, a train, your couch, as if it were sitting right next to you. Encrypted, without opening a single port, in five minutes.

In this guide
  1. 01How it works, in one picture
  2. 02The setup, step by step
  3. 03The life-changing bonus: Tailscale SSH
  4. 04Two extras worth knowing (optional)
  5. 05The honest part
  6. 06Frequently asked questions

In short

Tailscale links your devices (mini-PC, laptop, phone) into a private network encrypted with WireGuard, without opening a single port on your router. One command installs it, you log in with a Google, GitHub or Microsoft account, and every machine becomes reachable by name, for example ssh ulrich@mini. The free Personal plan is plenty for personal use: up to 6 users and an unlimited number of personal devices.

Do this first: Installing Linux

Your mini-PC sits at home, behind your router. Great as long as you’re on the same Wi-Fi. But the moment you step out, a café, the train, the office, it becomes unreachable. It lives on a private network, tucked behind your router’s NAT, with no public address of its own.

The 2000s method to fix this is port forwarding on the router: you redirect port 22 to the machine and pray nobody else finds it. Except the entire Internet scans that port nonstop. You’ve just exposed your front door to the planet. Fragile, stressful, to be reconfigured every time you change routers.

Tailscale takes the problem from the other end: instead of opening a breach toward your machine, it builds a private network that links all your devices together. Your mini-PC, your laptop, your phone see each other as if they were on the same cable, wherever they are on Earth. Encrypted end to end (WireGuard runs underneath, a modern, lean and fast protocol), and zero ports open on your router.

You Your laptop via Tailscale
You Your phone via Tailscale
The machine Mini-PC linux · agent · ollama
The relay Cloudflare receives the tunnel, serves your domain over HTTPS
 visits
The world The public your‑app.your‑domain.com
Who talks to whom: your private network via Tailscale, the public via Cloudflare.

How it works, in one picture

Each device gets a stable IP address in a separate range (100.x.y.z). That set of devices is your tailnet: your little personal network. When your laptop wants to talk to the mini-PC, Tailscale establishes a direct, encrypted connection between the two, punching through NATs on its own. The data never passes through Tailscale’s servers: it goes peer-to-peer.

The concrete result: you type ssh ulrich@mini from a train, and it’s as if you were in your living room. No router to configure, no port exposed.

The setup, step by step

0 of 4 steps done Your ticks stay in this browser.

  1. Create a Tailscale account (free)

    Go to tailscale.com and sign up. No password to invent: Tailscale leans on an account you already have, Google, GitHub, or Microsoft. That account is what defines who gets to enter your tailnet. The free plan (Personal) easily covers personal use: up to 6 users and an unlimited number of personal devices (plan checked on October 1, 2026).

  2. Install Tailscale on the mini-PC

    On the machine, one line installs the service:

    # Install the Tailscale client (detects your distro on its own)
    curl -fsSL https://tailscale.com/install.sh | sh
    # Connect the machine to the tailnet
    sudo tailscale up
    

    tailscale up prints an authentication link. Open it in a browser (on any device), log in with your account, and the machine joins the network. It now has its 100.x.y.z address for life.

  3. Install the app on your laptop and your phone

    Grab the Tailscale app on your Mac/PC and your mobile (the site offers the right installer), log in with the same account. Each device you add shows up on the network. To see the list from the mini-PC:

    tailscale status   # lists all your devices and their 100.x.y.z IPs
    
  4. Talk in names with MagicDNS

    Nobody wants to remember 100.118.42.7. MagicDNS gives each device a name. It is on by default for tailnets created since late 2022; check it in the Tailscale admin console (DNS tab) if a name doesn’t answer. Your ssh becomes readable:

    ssh ulrich@mini   # instead of ssh [email protected]
    

The life-changing bonus: Tailscale SSH

Here’s the feature that makes you go “oh, nice.” Normally, doing clean SSH requires generating keys, copying them to the machine, managing their rotation. With Tailscale SSH, the tailnet handles authentication for you.

# Allow SSH managed by the tailnet, leaving your other settings alone
sudo tailscale set --ssh

Why set rather than up? tailscale set only changes the option you name, while tailscale up expects your full list of settings and may complain if one is missing.

From there, you can SSH between your tailnet devices without managing a single key: Tailscale already knows it’s you (your account owns both machines), and it takes care of identity. Handy, magical, and access cuts off instantly if you remove the device from the network.

Two extras worth knowing (optional)

  • Exit node. You can route all your laptop’s traffic through your home machine with sudo tailscale set --advertise-exit-node. You then approve it in the admin console and pick your machine as the exit on the client side (on Linux, the Tailscale docs also explain how to enable IP forwarding). Useful on sketchy public Wi-Fi: you browse as if you were home.
  • Subnet routing. You can expose other devices on your home LAN (a printer, a NAS) to the tailnet without installing Tailscale on them, by declaring the machine as a subnet router. Entirely optional.

The honest part

Tailscale is a third-party coordination service. Your data stays peer-to-peer and encrypted, it never passes through them, but it’s their infrastructure that orchestrates who can reach whom (the directory, authentication, connection setup). For nearly all uses, it’s an excellent trade-off: you gain enormously in simplicity and security against a dependency on a serious player.

If you insist on 100% self-hosted, the alternative is called Headscale: an open-source coordination server you host yourself, compatible with the Tailscale clients. More work, more control. Worth keeping in a corner if total sovereignty is a criterion.

Frequently asked questions

Does my data go through Tailscale's servers?

No. Connections between your devices are direct, peer-to-peer and end-to-end encrypted. Tailscale's servers only handle coordination: the directory, authentication and setting up connections. You rely on them to decide who can reach whom, while your data never passes through them.

Does Tailscale SSH replace securing SSH?

No. Tailscale SSH handles authentication between the devices on your private network without a single key to manage, and access is cut off as soon as you remove a device from the network. Good SSH hygiene is still needed: strong keys, no passwords, root access locked. The private network shrinks the attack surface without making it disappear.

What if my machine's name doesn't respond on Tailscale?

Names come from MagicDNS, which gives each device on the network a name. It is on by default for networks created since late 2022. If a name doesn't respond, check in the Tailscale admin console, under the DNS tab, that MagicDNS is enabled. Meanwhile, the machine's 100.x.y.z address still works.

Can I route all my traffic through my home machine with Tailscale?

Yes, by making the machine an exit node with sudo tailscale set --advertise-exit-node. You then approve it in the admin console and pick it as the exit on your laptop. It's handy on a sketchy public Wi-Fi: you browse as if you were at home.

Is there an alternative to Tailscale without a third-party service?

Yes. Headscale is an open-source coordination server you host yourself, compatible with the Tailscale clients: more work, more control. Hand-configured WireGuard also gives you full control, at the cost of managing keys, IPs and the firewall yourself. And many routers can act as a VPN server, like the Freebox with its built-in WireGuard/OpenVPN server.

Terms in this guide: TailscaleIP addressSSHLinuxOpen source (vs open-weight)

Spotted a mistake?

A command stopped working, a price changed?

Tools change every month. Tell me what is wrong in this chapter and I will fix it and update its date.

Only the page, your message and the optional contact are kept. Nothing else.

Guide 15 of 31 · part 3 no guides read yet Open the list of guides