# How to Configure Tailcat Server to Listen on Specific TCP Ports

> Learn how to configure tailcat server to listen on specific TCP ports using the --serve flag or positional arguments with tailcat serve for granular control over exposed local ports.

- Repository: [Tailscale/tailcat](https://github.com/tailscale/tailcat)
- Tags: how-to-guide
- Published: 2026-09-06

---

**Use the `--serve` flag or positional arguments with `tailcat serve` to specify TCP ports, port ranges, or `all` to control which local ports the server exposes.**

Tailcat's server mode forwards local TCP ports through its secure tunnel, making services accessible across your Tailscale network. This article explains how to configure which ports the server listens on, based on the `tailscale/tailcat` source code.

## Server Mode vs. Forward Mode

Tailcat operates in two distinct modes that affect port configuration:

- **Server mode** — started by `tailcat` (no arguments) or `tailcat serve`, exposes local ports for remote access
- **Forward mode** — started by `tailcat forward`, connects to a server and maps remote ports locally

This article focuses on server mode configuration. Client-side binding is covered briefly for complete network setup.

## Configuring Server Listen Ports with `--serve`

The `--serve` flag controls which TCP ports the tailcat server makes available. In [`cmd/tailcat/tailcat.go`](https://github.com/tailscale/tailcat/blob/main/cmd/tailcat/tailcat.go), the flag is defined at lines 53-56 and parsed by the `serve` subcommand at lines 140-155.

### Supported Port Specifications

| Format | Example | Description |
|--------|---------|-------------|
| Single port | `8080` | Expose one specific port |
| Multiple ports | `8080,8443` | Comma-separated list |
| Port range | `3000-3010` | Inclusive range |
| All ports | `all` | Expose every listening TCP port |

### Examples

Expose specific ports:

```bash
tailcat serve 8080,8443

```

Expose a port range for development servers:

```bash
tailcat serve 3000-3010

```

Expose all local TCP ports (use with caution):

```bash
tailcat serve all

```

The server output displays the generated tailcat address:

```bash
🐈 Server listening with new address: tcABCDEF...

```

## Binding Forwarded Ports to Specific Interfaces

When using `tailcat forward` to access a remote server, the `--bind` flag controls which local address the forwarded port attaches to. By default, tailcat binds to `127.0.0.1` (localhost only).

In [`cmd/tailcat/forward.go`](https://github.com/tailscale/tailcat/blob/main/cmd/tailcat/forward.go) at lines 26-28, the `--bind` flag is defined with a default value of `127.0.0.1`.

Bind to all interfaces for external access:

```bash
tailcat forward --bind=0.0.0.0 tcXYZ123 8080:8080

```

Or bind to a specific interface:

```bash
tailcat forward --bind=192.168.1.10 tcXYZ123 8080:8080

```

## Complete Workflow Example

Start a server exposing ports 8080 and 8443:

```bash

# On server machine

tailcat serve 8080,8443

# 🐈 Server listening with new address: tcABC123...

```

Connect from another machine:

```bash

# On client machine, bind to all interfaces

tailcat forward --bind=0.0.0.0 tcABC123 8080:8080 8443:8443

```

Now services on the server's ports 8080/8443 are reachable at the client's IP on the same ports.

## Source Code Reference

Key files in `tailscale/tailcat` that implement port configuration:

- **[`cmd/tailcat/tailcat.go`](https://github.com/tailscale/tailcat/blob/main/cmd/tailcat/tailcat.go)** — Defines `--serve` flag and `serve` subcommand parsing
- **[`cmd/tailcat/forward.go`](https://github.com/tailscale/tailcat/blob/main/cmd/tailcat/forward.go)** — Implements `--bind` flag for listener address control
- **[`README.md`](https://github.com/tailscale/tailcat/blob/main/README.md)** — User-facing documentation with usage examples

## Summary

- Use `tailcat serve <ports>` to configure which TCP ports the server exposes
- Specify ports as comma-separated values, ranges with `-`, or `all` for every port
- Server mode binds to loopback by default; remote accessibility requires `tailcat forward`
- Control the forward listener address with `--bind` (default `127.0.0.1`, use `0.0.0.0` for all interfaces)
- All configuration flags are defined in the main command handlers in `cmd/tailcat/`

## Frequently Asked Questions

### What is the default port behavior if I run `tailcat` with no arguments?

Running `tailcat` without arguments starts server mode but exposes **no ports** by default. You must specify ports via `--serve` or use `tailcat serve <ports>` to make services accessible.

### Can I expose both UDP and TCP ports with tailcat?

The current `tailscale/tailcat` implementation focuses on **TCP port forwarding**. UDP support is not indicated in the command-line flags or server implementation as analyzed.

### Is there a security risk using `tailcat serve all`?

Yes. The `all` keyword exposes **every TCP port** listening on the server machine, including system services and databases. Use explicit port lists in production environments to minimize attack surface.

### How do I forward ports from a server that doesn't expose them by default?

Tailcat creates the tunnel; you cannot forward a port that the server hasn't exposed via `--serve`. Coordinate with the server administrator to ensure the required ports are listed in their `serve` configuration.