// Engineering Log

What is Tailscale: a mesh VPN on WireGuard, in simple terms

Published on 2026-09-22

// Fast route

This article belongs to the topic Networking and routing.

What is Tailscale

Tailscale is a service that unites your computers, servers and phones into a single private network over the Internet. Devices get stable internal addresses and connect to each other directly using the WireGuard protocol, no matter where they are or which routers they’re behind. You don’t need to configure tunnels, keys or port forwarding: just install the app and sign in to your account.

Put simply, Tailscale makes it feel as if all your devices are plugged into the same office switch, even if one is at home, another in a data center, and a third in your pocket.

How it works

Tailscale consists of two parts.

Coordination server runs in the Tailscale cloud. When you sign into the app, the device registers in your network (called a tailnet), publishes its WireGuard public key and receives the keys and addresses of other members, as well as access rules. Private keys remain on the devices.

Clients on devices establish direct encrypted connections between each other. If both devices are behind NAT, the clients NAT-traverse: they discover their external addresses and simultaneously send packets toward each other. If a direct connection is impossible, traffic goes through DERP relays. According to Tailscale documentation, they forward already-encrypted packets and cannot decrypt them because private keys never leave the devices. A relay is slower than a direct path, so in most cases DERP is only needed to establish the connection.

User traffic does not flow through the coordination server — it manages the network but does not carry data.

Main features

  • MagicDNS. Devices are reachable by names instead of addresses: ssh nas instead of ssh 100.101.102.103. According to the documentation, in networks created after October 20, 2022, the feature is enabled by default.
  • Access rules (ACL). The policy file describes who can access what, for example “developers see test servers, accounting — only the 1C server”. Important: until rules are defined, the default policy allows all devices in the network to talk to each other.
  • Subnet router. A device with Tailscale exposes an entire local network behind it — printers, cameras, servers that you can’t install the app on.
  • Exit node. A device through which another network member can send all their Internet traffic.
  • Login via Tailscale SSH, sharing individual devices, authorization keys for servers — for automatic connections without interactive login.

Subnet router vs exit node — what’s the difference

These features are often confused, although they solve different tasks.

A subnet router gives access to a private network. For example, an office server runs Tailscale, and behind it is the network 192.168.10.0/24 with a printer and an old server. An employee at home connects to 192.168.10.20, and traffic to the office network goes through that server. The employee’s Internet traffic still goes normally, directly.

bash
# on the server in the office
sudo tailscale set --advertise-routes=192.168.10.0/24

After that the route must be approved in the admin console (Machines section) or pre-approved by the autoApprovers rule in the policy file. On Linux, IP forwarding must also be enabled for routing.

An exit node sends all a device’s Internet traffic out to the Internet. This is useful, for example, on a public Wi-Fi when you want to go out to the Internet via your home or office link.

bash
# on the device that will be the exit node
sudo tailscale set --advertise-exit-node

# on the client
sudo tailscale set --exit-node=100.64.0.5

The exit node also needs to be approved in the console. A device can be both a subnet router and an exit node at the same time.

Pricing — September 2026

According to tailscale.com/pricing:

PlanPriceNotes
Personalfreeup to 6 users, devices unlimited
Standard$8 per user per monthunlimited users
Premium$18 per user per monthadvanced access rules and features for businesses
Enterpriseon requestcustom terms

Pricing is per user (“seat”), not per device. For a home or small team, the free Personal plan is usually sufficient.

For a Russian company it’s important to note: foreign plans cannot be paid with a Russian card — Visa and Mastercard suspended operations in Russia in March 2022. In addition, the coordination server is located abroad and managed by a third-party company. If this is unacceptable, there are options with a self-hosted coordination server — NetBird and Headscale.

How to get started

  1. Install the app on the first device: clients exist for Windows, macOS, Linux, iOS and Android. On Linux — run the installer script from the site, then sudo tailscale up.
  2. Sign in with a Google, Microsoft, GitHub or other supported provider — this creates your network.
  3. Repeat on the other devices. They will immediately see each other by addresses in the 100.x.y.z range and by MagicDNS names.
  4. Configure access rules before production servers join the network.
  5. For headless servers use authorization keys, and for an office network use a subnet router.

Common mistakes

  • Leaving the policy “everyone can do everything”. Any device in the network, including an employee’s personal phone, can see all servers.
  • Confusing subnet router and exit node. Enabling the exit node to reach the office network and then getting all Internet traffic routed through the office.
  • Forgetting to approve the route in the console. The command was run, but there’s no access to the subnet.
  • Overlapping subnets. If home and office both use 192.168.1.0/24, routing will be ambiguous — it’s better to choose a nonstandard office addressing.
  • Storing authorization keys in plaintext in scripts and repositories.

When Tailscale is suitable and when it’s not

Suitable: you need remote access to multiple devices and sites without your own VPN server, there’s no network administrator on the team, and it’s important to get started quickly.

Not suitable: the coordination server must be under your control or located in Russia, you need a layer-2 (L2) network, or you need full control over every setting. For these cases — ZeroTier, NetBird, Headscale or manual WireGuard setup.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Networking and routing

MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.

Typical tasks behind this topic

  • Set up VPN and secure access to office or cloud
  • Fix routing, DNS, or unstable connectivity
  • Configure MikroTik, firewall, and external links

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Reviews

Related reviews

ladohinpy

MikroTik hAP router setup. I'll set up a MikroTik Wi‑Fi router for you.

2025-07-21 · ★ 5/5

An excellent specialist, a savvy expert, and a wonderful person. In an hour he fixed what we'd been racking our brains over for days! I'm sure this won't be the last time we rely on his boundless professionalism.

An excellent specialist, a savvy expert, and a wonderful person. In an hour he fixed for us what we had been scratching our heads over for days! I'm sure this won't be the first time we make use of his boundless …

Ravenor

MikroTik hAP router setup. I'll configure a MikroTik Wi-Fi router for you.

2025-05-28 · ★ 5/5

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply