Tailscale is a mesh VPN built on WireGuard for admins, help-desk teams and home-lab users who need to reach servers, desktops and private networks without opening inbound firewall ports. The Tailscale download is free and the client is open source (BSD-3-Clause), while the coordination service is shareware (conditionally free): the Personal plan costs nothing for individuals, and business plans are paid, with a free trial for work accounts.
Every device you sign in joins your private network, called a tailnet, and gets a stable 100.x.y.z address. Tailscale handles key exchange, NAT traversal and DNS for you, so a laptop on hotel Wi-Fi can reach an RDP host in the office or an SSH server at home in minutes. Traffic goes directly between devices whenever possible and falls back to encrypted relays when it cannot.
Tailscale at a glance
| Item | Details |
|---|---|
| Latest version | 1.104.1 (7 October 2026) |
| Licence | Shareware (conditionally free): free Personal plan for individuals; paid business plans with a free trial. Client source code BSD-3-Clause |
| Platforms | Windows, macOS, Linux, iOS, Android, ChromeOS, Apple TV, Amazon Fire devices |
| Developer | Tailscale Inc. |
| Official website | tailscale.com |
| Best for | Reaching RDP, VNC and SSH hosts behind NAT; small-office and home-lab remote access without port forwarding |
What it does
- Builds a private WireGuard mesh between your devices and gives each one a fixed tailnet IP that survives network changes.
- Traverses NAT and firewalls automatically; only outbound connections are needed in most networks.
- MagicDNS lets you connect by machine name instead of IP, e.g.
mstsc /v:office-pc. - Subnet routers expose a whole office LAN to the tailnet, so printers, NAS boxes and servers without Tailscale stay reachable.
- Exit nodes send all internet traffic from a laptop through a trusted machine at home or in the office.
- Tailscale SSH authenticates SSH sessions to Linux hosts with tailnet identity instead of distributing keys.
- A central access policy (ACLs, groups, tags) decides which users and devices may talk to which ports.
- Serve and Funnel publish a local service to the tailnet or, with Funnel, to the public internet.
How IT teams use it
Reach an office RDP host without port forwarding
- Install Tailscale on the office PC and on your laptop and sign in to the same tailnet.
- Check the PC’s name and address in the admin console or with
tailscale status. - Connect with Remote Desktop to the machine name or its 100.x address. TCP 3389 never has to be exposed on the office router.
Expose a whole office subnet
- On a Linux box inside the LAN, enable IP forwarding:
echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.d/99-tailscale.conf echo 'net.ipv6.conf.all.forwarding = 1' | sudo tee -a /etc/sysctl.d/99-tailscale.conf sudo sysctl -p /etc/sysctl.d/99-tailscale.conf - Advertise the route:
sudo tailscale set --advertise-routes=192.168.10.0/24 - In the admin console open Machines, select the device, edit Subnets and approve the route (or let
autoApproversin the policy file do it).
Use an office machine as an exit node
- On the Linux machine (with forwarding enabled) run
sudo tailscale set --advertise-exit-node. - Approve it under Edit route settings → Use as exit node.
- On a client:
sudo tailscale set --exit-node=<exit-node-ip> --exit-node-allow-lan-access=true, or pick the exit node from the tray menu on Windows and macOS.
SSH to Linux servers with Tailscale SSH
- On the server run
tailscale set --ssh. - Add an
sshrule to the tailnet policy (source users, destination tags, allowed login names) alongside a network rule; without it, sessions are refused. - Connect from any tailnet device with a normal
ssh user@server.
Install and first run
Windows: run the installer (an MSI is available for deployment), then sign in from the tray icon. Tailscale runs as a service, so remote hosts stay reachable after logoff and reboot.
macOS, iOS, Android: install the app, approve the VPN configuration prompt and sign in.
Linux:
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale upOpen the URL printed by tailscale up to authenticate, then verify with tailscale status and tailscale ip.
Network notes: no inbound ports are required. Direct tunnels use UDP with source port 41641 by default, STUN uses UDP 3478, and coordination and DERP relay traffic use HTTPS on TCP 443 (HTTP 80 is preferred for coordination when available). If peers show as relayed, allowing outbound UDP usually restores direct connections and better latency.
Sign-in goes through an identity provider. Using a public email domain enrols you in the Personal plan; a work domain starts the business trial.
Limitations
- The coordination service is run by Tailscale Inc.; if you need a fully self-hosted control plane you must use a third-party alternative or another tool.
- The Personal plan is aimed at individuals and non-commercial use; teams should plan for a paid business plan after the trial.
- It gives network access, not a screen: you still need an RDP, VNC or SSH client on top.
- Tailscale SSH server runs only on Linux and on macOS with the open-source CLI daemon.
- Behind strict corporate firewalls traffic may stay on DERP relays and be slower than a direct path.
- Some security teams restrict mesh VPNs on managed endpoints; check policy before rolling it out.
Tailscale vs alternatives
WireGuard on its own is free and fully under your control, but you manage keys, endpoints and port forwarding yourself; Tailscale automates all of that on top of the same protocol. ZeroTier is the closest rival: it works at layer 2, supports bridging and has its own free plan. OpenVPN suits classic hub-and-spoke remote access with a gateway you host. For screen sharing, pair any of them with an RDP or VNC client such as Remmina.
FAQ
Is Tailscale free?
The Personal plan is free for individuals and home use. Business use runs on paid plans, which come with a free trial, so Tailscale is best described as shareware (conditionally free).
Where is the Tailscale admin console?
The admin console is the web interface on the official website where you approve devices, routes and exit nodes and edit the access policy. Sign in with the same identity you used in the client.
Tailscale vs WireGuard: which should I use?
Tailscale uses WireGuard for encryption. Choose plain WireGuard for a few static tunnels you want to manage yourself; choose Tailscale when devices move between networks or sit behind NAT and you want central identity and access rules.
What is a Tailscale exit node?
A device that forwards all internet traffic from other tailnet devices, like a traditional full-tunnel VPN. It must be advertised and then approved in the admin console.
What is Tailscale Funnel?
Funnel publishes a local web service from one of your devices to the public internet over HTTPS. Serve does the same but only inside your tailnet.
Does Tailscale need port forwarding?
No. It connects outbound and punches through NAT; when a direct path is impossible it relays traffic over HTTPS.
Last checked against official sources: 8 October 2026 (developer website: tailscale.com). Versions and licence terms change — confirm on the developer's site before deploying in production.
