What Is Tailscale? A Private Network for Your Devices and Servers
Tailscale builds a private, encrypted network (a tailnet) between your laptops, phones and servers using WireGuard, with no ports to open. How it works, common uses — private SSH, reaching databases and admin tools, home labs — MagicDNS, ACLs, Funnel and Serve, and alternatives like Headscale and plain WireGuard.
Tailscale connects your devices — laptop, phone, servers, a Raspberry Pi at home — into one private network (a "tailnet"). Each device gets a stable private IP address and can reach the others directly and securely, wherever they are, without opening any ports to the internet.
It's built on WireGuard, a modern, fast VPN protocol, with Tailscale handling the hard parts: key exchange, getting through firewalls and NAT, and access control.
How it differs from a traditional VPN
A traditional VPN routes everyone through a central gateway into a network. Tailscale is a mesh: devices connect to each other directly (peer to peer) where possible, using a coordination server only to exchange keys and find each other. When a direct path is impossible, traffic goes through encrypted relays (DERP servers).
You log in with an existing identity provider (Google, Microsoft, GitHub, Okta…) — no separate VPN accounts.
Common uses
Private SSH
Close port 22 to the internet and SSH over Tailscale instead. Bots can't attack what they can't reach. (SSH hardening)
ssh deploy@my-server # via MagicDNS name on the tailnet
Tailscale SSH can go further, authenticating SSH with your tailnet identity and policies instead of managing keys on each server.
Reaching databases and admin tools
Your Postgres, Grafana or admin panel listens only on the Tailscale interface. You reach it from your laptop as if it were local; the internet never sees it. (How to view your Postgres database)
Home labs and self-hosting
Reach a home server from anywhere without port forwarding on your router.
Connecting servers across clouds
Servers at different providers talk privately without public database ports.
Exit nodes
Route your internet traffic through one of your devices — useful on untrusted Wi-Fi. (Man-in-the-middle attacks)
Features worth knowing
- MagicDNS — devices get names like
my-serverinstead of IPs. - ACLs / grants — rules in a policy file about who can reach what: "developers can reach the staging database; only admins can SSH to production". (Principle of least privilege)
- Tags — give servers roles rather than tying them to a person.
- Serve — share a local service with other devices on your tailnet.
- Funnel — expose a local service to the public internet through Tailscale (like a tunnel). (Cloudflare Tunnel, What is ngrok?)
- Subnet routers — reach a whole network (e.g. an office LAN or a VPC) through one device.
Setting it up on a server
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up --ssh
Follow the login link, and the server joins your tailnet. Then bind services to the Tailscale IP, or firewall them so only the tailscale0 interface can reach them:
sudo ufw allow in on tailscale0
sudo ufw deny 22/tcp
Make sure you can connect over Tailscale before closing the public port. (UFW firewall basics)
Pricing and alternatives
Tailscale has a free personal plan and paid plans for teams; check their site for current limits.
- Headscale — open-source, self-hosted implementation of the coordination server.
- Plain WireGuard — free and simple for a few fixed machines, but you manage keys and configs yourself.
- NetBird, ZeroTier — similar mesh-network products.
- Cloudflare Access / Zero Trust — browser-based access to internal web apps, often combined with tunnels.
Things to keep in mind
- Your access depends on your identity provider account — protect it with 2FA. (Two-factor authentication)
- Turn on key expiry and review devices; remove old laptops and phones.
- Write ACLs early; the default can be more permissive than you want for a team.
EasySpawn servers are reachable over SSH, the web and your phone, with databases kept off the public internet, so there are fewer things you need a private network for in the first place. See how it works or join the waitlist.
Related: SSH Hardening · Cloudflare Tunnel Explained · How to Secure a New VPS · SSH Port Forwarding
Keep reading
Writing a systemd Service File for Your App (With Hardening)
A production-ready systemd unit for a Node.js or Python app, explained: Type, User, WorkingDirectory, EnvironmentFile, Restart and backoff, graceful stop, resource limits, logging, and the sandboxing options (ProtectSystem, NoNewPrivileges, PrivateTmp) that limit damage if the app is compromised.
SSH Hardening: Lock Down SSH on Your Server
A practical SSH hardening checklist: key-only authentication, no root login, AllowUsers, modern key types, sshd_config drop-ins, testing safely without locking yourself out, fail2ban, firewall rules or a private network like Tailscale, 2FA, and auditing who has access.