
How to reach your home server from anywhere with Tailscale
What you’ll get
Private access to services on your home server (or VPS) from laptop and phone: no punching holes in your router, no dynamic DNS headaches. About an hour for a basic mesh; add time if you want subnet routing for the whole LAN.
Before you start
- A machine that’s always on: home server, NAS, Raspberry Pi, or Linux VPS
- Admin on the devices you want to connect (Mac, Windows, Linux, iOS, Android)
- A Tailscale account (free tier covers personal use for most households)
- Services already running on the server (Nextcloud, Vaultwarden, Home Assistant, SSH: anything)
Tailscale builds a WireGuard mesh between your devices. Traffic is encrypted device-to-device. Your services don’t need to be on the public internet.
Steps
1. Sign up and create a tailnet
- Go to tailscale.com and sign up.
- Note your tailnet name (e.g.
yak.ts.net), you’ll see it in the admin console.
2. Install on the server
Linux (most common):
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up
Follow the auth URL in the terminal: log in with the same account.
Synology / TrueNAS / Proxmox: Use Tailscale’s package or Docker image from their docs; same idea: install, authenticate.
Confirm in the admin console, your server should appear with a 100.x.y.z Tailscale IP.
3. Install on your laptop and phone
Download Tailscale from the app store or tailscale.com/download. Sign in with the same account. Each device gets its own 100.x address.
You should now ping the server from your laptop:
ping 100.x.y.z
(use the IP from the admin console)
4. Reach a service by Tailscale IP
If Vaultwarden listens on port 8080 on the server:
http://100.x.y.z:8080
From phone browser on cellular (Wi‑Fi off), if it loads, you’re in. Same for SSH:
ssh user@100.x.y.z
No router config required.
5. Use MagicDNS (easier than memorizing IPs)
Admin console → DNS → Enable MagicDNS
Your machines get names like servername.your-tailnet.ts.net. Use that instead of raw IPs in bookmarks and Bitwarden self-host URLs.
6. Optional: HTTPS with Tailscale Serve
For apps that demand HTTPS (many password managers do):
sudo tailscale serve https / http://127.0.0.1:8080
Tailscale terminates TLS on your tailnet hostname. Check tailscale serve --help for your version: syntax has evolved.
Alternative: reverse proxy with a real domain only on tailnet, or access via HTTP over Tailscale for homelab-only tools.
7. Optional: whole-home subnet routing
Want to reach a printer, camera, or random .local device without Tailscale on each one?
On the server that’s always home:
sudo tailscale up --advertise-routes=192.168.1.0/24
In admin console: Approve routes for that machine. Other Tailscale devices can now hit your LAN IPs while away.
Only do this if you understand the blast radius: your home LAN becomes reachable through that node.
Common mistakes
- Installing Tailscale on two accounts (personal + work) and wondering why devices don’t see each other
- Exposing the same service both on Tailscale and public port 443 “for convenience”
- Forgetting the server after a reboot: enable
tailscaledat boot (systemctl enable tailscaled) - Subnet routing without approving routes in the admin console (silent failure)
Tooling that helps
- Tailscale admin ACLs if you want family read-only vs your full access
- Exit nodes if you want phone traffic to exit through home (travel VPN use case), different feature, same install
- Pairs with Vaultwarden on a VPS or local Nextcloud from our self-hosted list
Wrap-up
Your server is reachable from anywhere you have Tailscale: not anywhere on Earth. That’s the point. Keep services bound to localhost plus Tailscale, test from cellular once, and leave port forwarding off.
Who should skip this: if you need public websites for strangers, use a proper reverse proxy and TLS on a domain: not Tailscale alone.


