How to Configure Tailscale for Remote Access: A Complete Guide
Configure Tailscale for remote access by installing the client on your host, authenticating with your tailnet, and enabling the Funnel feature to expose services like SSH or web UIs securely to the internet without manually configuring router ports.
Tailscale creates a private WireGuard-based overlay network (a tailnet) that assigns stable 100.x addresses to all your devices, enabling direct peer-to-peer communication regardless of NAT or firewall restrictions. This guide walks through the exact steps documented in the mikeroyal/Self-Hosting-Guide repository to configure Tailscale for remote access to self-hosted services, from initial installation to exposing specific ports via the public internet.
Installing Tailscale on Your Host
The first step to configure Tailscale for remote access is installing the client on every device that needs connectivity. According to the Self-Hosting-Guide README.md [line 1197], Tailscale supports Linux, macOS, Windows, and various NAS/Router platforms.
For Linux systems, the official installation script handles repository configuration and service setup automatically:
# Install Tailscale
curl -fsSL https://tailscale.com/install.sh | sh
# Enable and start the service
sudo systemctl enable --now tailscaled
After installation, verify the daemon is running before proceeding to authentication.
Joining Your Tailnet
Once installed, you must authenticate the device to join your tailnet—a private network namespace that Tailscale creates for your organization during first-time login [line 1467].
Run the following command to initiate authentication:
sudo tailscale up
This generates a URL in your terminal. Open it in a browser to log in with your Tailscale account. Upon success, the device receives a stable 100.x IP address.
Verify your assignment with:
tailscale ip -4
By default, every authenticated node can reach every other node in the tailnet. For production environments, restrict access through Access Control Lists (ACLs) in the Tailscale admin console before exposing services.
Enabling Remote Access with Funnel
To expose a self-hosted service to the wider internet without opening ports on your router, use Funnel [line 1471]. This feature creates a public DNS endpoint (e.g., mydevice.tailnet-name.ts.net) that forwards traffic from any internet-connected client—even those without Tailscale installed—to your private node.
Exposing SSH
Enable Funnel for SSH access on port 22:
sudo tailscale funnel enable --service ssh
Check the public endpoint status:
tailscale funnel status
The output displays your public address:
ssh: mydevice.tailnet-name.ts.net:22
Connect from any machine worldwide:
ssh user@mydevice.tailnet-name.ts.net -p 22
Exposing Web Services
For HTTP-based applications like Nextcloud or admin panels:
sudo tailscale funnel enable --service http
tailscale funnel status
# Output includes:
# http: mydevice.tailnet-name.ts.net:80
Traffic flows encrypted from the public internet through Tailscale's relay infrastructure to your local service, bypassing NAT and firewall limitations.
Alternative: Using Tailscale SSH
Instead of exposing port 22 via Funnel, you can delegate SSH authentication entirely to Tailscale [line 1351]. This eliminates the need for open ports and key management.
Enable Tailscale SSH on the host:
sudo tailscale up --ssh
From any other authenticated node in your tailnet, connect using:
tailscale ssh user@mydevice
This method requires the connecting client to have Tailscale installed and authenticated, providing an additional layer of security compared to public Funnel endpoints.
Summary
- Install Tailscale across all devices using the official installer script [line 1197].
- Authenticate each device to join your tailnet and receive a stable 100.x address [line 1467].
- Enable Funnel on specific ports to create public internet endpoints without router configuration [line 1471].
- Consider Tailscale SSH as a zero-configuration alternative to traditional SSH exposure [line 1351].
- All configuration references are documented in the
README.mdof themikeroyal/Self-Hosting-Guiderepository.
Frequently Asked Questions
Can I access my Tailscale network without installing the client on every device?
Yes. While full tailnet access requires the client, the Funnel feature allows specific services to be reachable via public URLs (e.g., mydevice.tailnet-name.ts.net) without the client installed on the connecting machine [line 1471]. However, this exposes only the specific funnel-enabled port, not the entire network.
What is the difference between Funnel and regular Tailscale connectivity?
Regular Tailscale connectivity requires both the client and authentication to reach 100.x addresses. Funnel creates a public DNS endpoint that bridges the internet to your private node, allowing unauthenticated clients to reach specific ports like 22 (SSH) or 80 (HTTP) while traffic remains encrypted over WireGuard.
Do I need to configure port forwarding on my router?
No. Tailscale uses NAT traversal and relay servers to establish connections. When using Funnel, Tailscale's infrastructure handles the public exposure, meaning you do not need to open ports or configure firewall rules on your local router or firewall.
How does Tailscale SSH differ from enabling Funnel on port 22?
Tailscale SSH [line 1351] requires the connecting client to have Tailscale installed and authenticated to your tailnet, using the tailscale ssh command. This keeps the service private to your network. Funnel on port 22 creates a public internet-accessible SSH endpoint that anyone can attempt to connect to, though you still control authentication via standard SSH keys or passwords.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →