# How to Configure Tailscale for Remote Access: A Complete Guide

> Learn to configure Tailscale for remote access. Install, authenticate, and use Funnel to securely expose services without port forwarding. Get started with this complete guide.

- Repository: [Michael Royal/Self-Hosting-Guide](https://github.com/mikeroyal/Self-Hosting-Guide)
- Tags: how-to-guide
- Published: 2026-06-17

---

**Configure Tailscale for remote access by installing the client on your host, authenticating with your tailnet, and enabling the Funnel feature to expose services like SSH or web UIs securely to the internet without manually configuring router ports.**

Tailscale creates a private WireGuard-based overlay network (a *tailnet*) that assigns stable 100.x addresses to all your devices, enabling direct peer-to-peer communication regardless of NAT or firewall restrictions. This guide walks through the exact steps documented in the `mikeroyal/Self-Hosting-Guide` repository to configure Tailscale for remote access to self-hosted services, from initial installation to exposing specific ports via the public internet.

## Installing Tailscale on Your Host

The first step to configure Tailscale for remote access is installing the client on every device that needs connectivity. According to the Self-Hosting-Guide [`README.md`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/README.md) [line 1197], Tailscale supports Linux, macOS, Windows, and various NAS/Router platforms.

For Linux systems, the official installation script handles repository configuration and service setup automatically:

```bash

# Install Tailscale

curl -fsSL https://tailscale.com/install.sh | sh

# Enable and start the service

sudo systemctl enable --now tailscaled

```

After installation, verify the daemon is running before proceeding to authentication.

## Joining Your Tailnet

Once installed, you must authenticate the device to join your *tailnet*—a private network namespace that Tailscale creates for your organization during first-time login [line 1467].

Run the following command to initiate authentication:

```bash
sudo tailscale up

```

This generates a URL in your terminal. Open it in a browser to log in with your Tailscale account. Upon success, the device receives a stable 100.x IP address.

Verify your assignment with:

```bash
tailscale ip -4

```

By default, every authenticated node can reach every other node in the tailnet. For production environments, restrict access through Access Control Lists (ACLs) in the Tailscale admin console before exposing services.

## Enabling Remote Access with Funnel

To expose a self-hosted service to the wider internet without opening ports on your router, use **Funnel** [line 1471]. This feature creates a public DNS endpoint (e.g., `mydevice.tailnet-name.ts.net`) that forwards traffic from any internet-connected client—even those without Tailscale installed—to your private node.

### Exposing SSH

Enable Funnel for SSH access on port 22:

```bash
sudo tailscale funnel enable --service ssh

```

Check the public endpoint status:

```bash
tailscale funnel status

```

The output displays your public address:

```

ssh: mydevice.tailnet-name.ts.net:22

```

Connect from any machine worldwide:

```bash
ssh user@mydevice.tailnet-name.ts.net -p 22

```

### Exposing Web Services

For HTTP-based applications like Nextcloud or admin panels:

```bash
sudo tailscale funnel enable --service http
tailscale funnel status

# Output includes:

# http: mydevice.tailnet-name.ts.net:80

```

Traffic flows encrypted from the public internet through Tailscale's relay infrastructure to your local service, bypassing NAT and firewall limitations.

## Alternative: Using Tailscale SSH

Instead of exposing port 22 via Funnel, you can delegate SSH authentication entirely to Tailscale [line 1351]. This eliminates the need for open ports and key management.

Enable Tailscale SSH on the host:

```bash
sudo tailscale up --ssh

```

From any other authenticated node in your tailnet, connect using:

```bash
tailscale ssh user@mydevice

```

This method requires the connecting client to have Tailscale installed and authenticated, providing an additional layer of security compared to public Funnel endpoints.

## Summary

- **Install Tailscale** across all devices using the official installer script [line 1197].
- **Authenticate** each device to join your tailnet and receive a stable 100.x address [line 1467].
- **Enable Funnel** on specific ports to create public internet endpoints without router configuration [line 1471].
- **Consider Tailscale SSH** as a zero-configuration alternative to traditional SSH exposure [line 1351].
- All configuration references are documented in the [`README.md`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/README.md) of the `mikeroyal/Self-Hosting-Guide` repository.

## Frequently Asked Questions

### Can I access my Tailscale network without installing the client on every device?

Yes. While full tailnet access requires the client, the **Funnel** feature allows specific services to be reachable via public URLs (e.g., `mydevice.tailnet-name.ts.net`) without the client installed on the connecting machine [line 1471]. However, this exposes only the specific funnel-enabled port, not the entire network.

### What is the difference between Funnel and regular Tailscale connectivity?

Regular Tailscale connectivity requires both the client and authentication to reach 100.x addresses. **Funnel** creates a public DNS endpoint that bridges the internet to your private node, allowing unauthenticated clients to reach specific ports like 22 (SSH) or 80 (HTTP) while traffic remains encrypted over WireGuard.

### Do I need to configure port forwarding on my router?

No. Tailscale uses NAT traversal and relay servers to establish connections. When using Funnel, Tailscale's infrastructure handles the public exposure, meaning you do not need to open ports or configure firewall rules on your local router or firewall.

### How does Tailscale SSH differ from enabling Funnel on port 22?

**Tailscale SSH** [line 1351] requires the connecting client to have Tailscale installed and authenticated to your tailnet, using the `tailscale ssh` command. This keeps the service private to your network. **Funnel on port 22** creates a public internet-accessible SSH endpoint that anyone can attempt to connect to, though you still control authentication via standard SSH keys or passwords.