How to Configure Tailcat Server to Listen on Specific TCP Ports

Use the --serve flag or positional arguments with tailcat serve to specify TCP ports, port ranges, or all to control which local ports the server exposes.

Tailcat's server mode forwards local TCP ports through its secure tunnel, making services accessible across your Tailscale network. This article explains how to configure which ports the server listens on, based on the tailscale/tailcat source code.

Server Mode vs. Forward Mode

Tailcat operates in two distinct modes that affect port configuration:

  • Server mode — started by tailcat (no arguments) or tailcat serve, exposes local ports for remote access
  • Forward mode — started by tailcat forward, connects to a server and maps remote ports locally

This article focuses on server mode configuration. Client-side binding is covered briefly for complete network setup.

Configuring Server Listen Ports with --serve

The --serve flag controls which TCP ports the tailcat server makes available. In cmd/tailcat/tailcat.go, the flag is defined at lines 53-56 and parsed by the serve subcommand at lines 140-155.

Supported Port Specifications

Format Example Description
Single port 8080 Expose one specific port
Multiple ports 8080,8443 Comma-separated list
Port range 3000-3010 Inclusive range
All ports all Expose every listening TCP port

Examples

Expose specific ports:

tailcat serve 8080,8443

Expose a port range for development servers:

tailcat serve 3000-3010

Expose all local TCP ports (use with caution):

tailcat serve all

The server output displays the generated tailcat address:

🐈 Server listening with new address: tcABCDEF...

Binding Forwarded Ports to Specific Interfaces

When using tailcat forward to access a remote server, the --bind flag controls which local address the forwarded port attaches to. By default, tailcat binds to 127.0.0.1 (localhost only).

In cmd/tailcat/forward.go at lines 26-28, the --bind flag is defined with a default value of 127.0.0.1.

Bind to all interfaces for external access:

tailcat forward --bind=0.0.0.0 tcXYZ123 8080:8080

Or bind to a specific interface:

tailcat forward --bind=192.168.1.10 tcXYZ123 8080:8080

Complete Workflow Example

Start a server exposing ports 8080 and 8443:


# On server machine

tailcat serve 8080,8443

# 🐈 Server listening with new address: tcABC123...

Connect from another machine:


# On client machine, bind to all interfaces

tailcat forward --bind=0.0.0.0 tcABC123 8080:8080 8443:8443

Now services on the server's ports 8080/8443 are reachable at the client's IP on the same ports.

Source Code Reference

Key files in tailscale/tailcat that implement port configuration:

Summary

  • Use tailcat serve <ports> to configure which TCP ports the server exposes
  • Specify ports as comma-separated values, ranges with -, or all for every port
  • Server mode binds to loopback by default; remote accessibility requires tailcat forward
  • Control the forward listener address with --bind (default 127.0.0.1, use 0.0.0.0 for all interfaces)
  • All configuration flags are defined in the main command handlers in cmd/tailcat/

Frequently Asked Questions

What is the default port behavior if I run tailcat with no arguments?

Running tailcat without arguments starts server mode but exposes no ports by default. You must specify ports via --serve or use tailcat serve <ports> to make services accessible.

Can I expose both UDP and TCP ports with tailcat?

The current tailscale/tailcat implementation focuses on TCP port forwarding. UDP support is not indicated in the command-line flags or server implementation as analyzed.

Is there a security risk using tailcat serve all?

Yes. The all keyword exposes every TCP port listening on the server machine, including system services and databases. Use explicit port lists in production environments to minimize attack surface.

How do I forward ports from a server that doesn't expose them by default?

Tailcat creates the tunnel; you cannot forward a port that the server hasn't exposed via --serve. Coordinate with the server administrator to ensure the required ports are listed in their serve configuration.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →