Tailscale: your private network
Reach your machine from anywhere, a café, a train, your couch, as if it were sitting right next to you. Encrypted, without opening a single port, in five minutes.
In this guide
Guide checked 3 months ago: some commands may have changed. Let us know if so.
In short
Tailscale links your devices (mini-PC, laptop, phone) into a private network encrypted with WireGuard, without opening a single port on your router. One command installs it, you log in with a Google, GitHub or Microsoft account, and every machine becomes reachable by name, for example ssh ulrich@mini. The free Personal plan is plenty for personal use: up to 6 users and an unlimited number of personal devices.
Do this first: Installing Linux
Your mini-PC sits at home, behind your router. Great as long as you’re on the same Wi-Fi. But the moment you step out, a café, the train, the office, it becomes unreachable. It lives on a private network, tucked behind your router’s NAT, with no public address of its own.
The 2000s method to fix this is port forwarding on the router: you redirect port 22 to the machine and pray nobody else finds it. Except the entire Internet scans that port nonstop. You’ve just exposed your front door to the planet. Fragile, stressful, to be reconfigured every time you change routers.
Tailscale takes the problem from the other end: instead of opening a breach toward your machine, it builds a private network that links all your devices together. Your mini-PC, your laptop, your phone see each other as if they were on the same cable, wherever they are on Earth. Encrypted end to end (WireGuard runs underneath, a modern, lean and fast protocol), and zero ports open on your router.
How it works, in one picture
Each device gets a stable IP address in a separate range (100.x.y.z). That set of devices is your tailnet: your little personal network. When your laptop wants to talk to the mini-PC, Tailscale establishes a direct, encrypted connection between the two, punching through NATs on its own. The data never passes through Tailscale’s servers: it goes peer-to-peer.
The concrete result: you type ssh ulrich@mini from a train, and it’s as if you were in your living room. No router to configure, no port exposed.
The setup, step by step
0 of 4 steps done Your ticks stay in this browser.
-
Create a Tailscale account (free)
Go to tailscale.com and sign up. No password to invent: Tailscale leans on an account you already have, Google, GitHub, or Microsoft. That account is what defines who gets to enter your tailnet. The free plan (Personal) easily covers personal use: up to 6 users and an unlimited number of personal devices (plan checked on October 1, 2026).
-
Install Tailscale on the mini-PC
On the machine, one line installs the service:
# Install the Tailscale client (detects your distro on its own) curl -fsSL https://tailscale.com/install.sh | sh # Connect the machine to the tailnet sudo tailscale uptailscale upprints an authentication link. Open it in a browser (on any device), log in with your account, and the machine joins the network. It now has its100.x.y.zaddress for life. -
Install the app on your laptop and your phone
Grab the Tailscale app on your Mac/PC and your mobile (the site offers the right installer), log in with the same account. Each device you add shows up on the network. To see the list from the mini-PC:
tailscale status # lists all your devices and their 100.x.y.z IPs -
Talk in names with MagicDNS
Nobody wants to remember
100.118.42.7. MagicDNS gives each device a name. It is on by default for tailnets created since late 2022; check it in the Tailscale admin console (DNS tab) if a name doesn’t answer. Yoursshbecomes readable:ssh ulrich@mini # instead of ssh [email protected]
The life-changing bonus: Tailscale SSH
Here’s the feature that makes you go “oh, nice.” Normally, doing clean SSH requires generating keys, copying them to the machine, managing their rotation. With Tailscale SSH, the tailnet handles authentication for you.
# Allow SSH managed by the tailnet, leaving your other settings alone
sudo tailscale set --ssh
Why set rather than up? tailscale set only changes the option you name, while tailscale up expects your full list of settings and may complain if one is missing.
From there, you can SSH between your tailnet devices without managing a single key: Tailscale already knows it’s you (your account owns both machines), and it takes care of identity. Handy, magical, and access cuts off instantly if you remove the device from the network.
Two extras worth knowing (optional)
- Exit node. You can route all your laptop’s traffic through your home machine with
sudo tailscale set --advertise-exit-node. You then approve it in the admin console and pick your machine as the exit on the client side (on Linux, the Tailscale docs also explain how to enable IP forwarding). Useful on sketchy public Wi-Fi: you browse as if you were home. - Subnet routing. You can expose other devices on your home LAN (a printer, a NAS) to the tailnet without installing Tailscale on them, by declaring the machine as a subnet router. Entirely optional.
The honest part
Tailscale is a third-party coordination service. Your data stays peer-to-peer and encrypted, it never passes through them, but it’s their infrastructure that orchestrates who can reach whom (the directory, authentication, connection setup). For nearly all uses, it’s an excellent trade-off: you gain enormously in simplicity and security against a dependency on a serious player.
If you insist on 100% self-hosted, the alternative is called Headscale: an open-source coordination server you host yourself, compatible with the Tailscale clients. More work, more control. Worth keeping in a corner if total sovereignty is a criterion.
All the commands in this guide
Frequently asked questions
Does my data go through Tailscale's servers?
No. Connections between your devices are direct, peer-to-peer and end-to-end encrypted. Tailscale's servers only handle coordination: the directory, authentication and setting up connections. You rely on them to decide who can reach whom, while your data never passes through them.
Does Tailscale SSH replace securing SSH?
No. Tailscale SSH handles authentication between the devices on your private network without a single key to manage, and access is cut off as soon as you remove a device from the network. Good SSH hygiene is still needed: strong keys, no passwords, root access locked. The private network shrinks the attack surface without making it disappear.
What if my machine's name doesn't respond on Tailscale?
Names come from MagicDNS, which gives each device on the network a name. It is on by default for networks created since late 2022. If a name doesn't respond, check in the Tailscale admin console, under the DNS tab, that MagicDNS is enabled. Meanwhile, the machine's 100.x.y.z address still works.
Can I route all my traffic through my home machine with Tailscale?
Yes, by making the machine an exit node with sudo tailscale set --advertise-exit-node. You then approve it in the admin console and pick it as the exit on your laptop. It's handy on a sketchy public Wi-Fi: you browse as if you were at home.
Is there an alternative to Tailscale without a third-party service?
Yes. Headscale is an open-source coordination server you host yourself, compatible with the Tailscale clients: more work, more control. Hand-configured WireGuard also gives you full control, at the cost of managing keys, IPs and the firewall yourself. And many routers can act as a VPN server, like the Freebox with its built-in WireGuard/OpenVPN server.
Terms in this guide: TailscaleIP addressSSHLinuxOpen source (vs open-weight)
Spotted a mistake?
A command stopped working, a price changed?
Tools change every month. Tell me what is wrong in this chapter and I will fix it and update its date.