Skip to content

Tailscale

TL;DR / when to use this: Tailscale is the zero-config overlay network I use for LAN access on the go and for exposing a handful of services publicly via Funnel. Use Tailscale when you want mesh networking without maintaining a VPN server; use WireGuard when you want a self-hosted, fully-controlled tunnel.

Flags I use constantly

sudo tailscale up \
  --accept-dns=false \
  --advertise-exit-node \
  --advertise-routes=192.168.4.142/32 \
  --reset
  • --accept-dns=false — keep local DNS (needed for local resolution and split DNS setups)
  • --advertise-exit-node — this node can serve as an exit node
  • --advertise-routes= — publish a LAN subnet/host to the tailnet
  • --reset — clear previously persisted flags so the current set applies cleanly

Funnel

Expose a service on a port to the public internet:

tailscale funnel <port>

If Funnel isn't enabled on your tailnet, the command prints a URL — click it to enable. Note: Funnel does not support CNAME records (custom domains pointing at *.ts.net names don't work), so you get the *.tailscale-funnel.app hostname.

Tailscale vs WireGuard

Tailscale WireGuard
Setup Install + auth, done Self-hosted server, keys, config files
Control Managed control plane (open-source clients) Everything on your box
NAT traversal Trivial (derp + hole punching) Needs port forwarding
Good for Devices on the move, quick mesh A single trusted tunnel to your own server

The two coexist fine: Tailscale for device convenience, WireGuard for a self-hosted tunnel. The GeoIP whitelist in SWAG treats 100.64.0.0/10 (the Tailscale range) as LAN.

See also