// Engineering Log
What is Tailscale: a mesh VPN on WireGuard, in simple terms
Published on 2026-09-22
// Fast route
This article belongs to the topic Networking and routing.
What is Tailscale
Tailscale is a service that unites your computers, servers and phones into a single private network over the Internet. Devices get stable internal addresses and connect to each other directly using the WireGuard protocol, no matter where they are or which routers they’re behind. You don’t need to configure tunnels, keys or port forwarding: just install the app and sign in to your account.
Put simply, Tailscale makes it feel as if all your devices are plugged into the same office switch, even if one is at home, another in a data center, and a third in your pocket.
How it works
Tailscale consists of two parts.
Coordination server runs in the Tailscale cloud. When you sign into the app, the device registers in your network (called a tailnet), publishes its WireGuard public key and receives the keys and addresses of other members, as well as access rules. Private keys remain on the devices.
Clients on devices establish direct encrypted connections between each other. If both devices are behind NAT, the clients NAT-traverse: they discover their external addresses and simultaneously send packets toward each other. If a direct connection is impossible, traffic goes through DERP relays. According to Tailscale documentation, they forward already-encrypted packets and cannot decrypt them because private keys never leave the devices. A relay is slower than a direct path, so in most cases DERP is only needed to establish the connection.
User traffic does not flow through the coordination server — it manages the network but does not carry data.
Main features
- MagicDNS. Devices are reachable by names instead of addresses:
ssh nasinstead ofssh 100.101.102.103. According to the documentation, in networks created after October 20, 2022, the feature is enabled by default. - Access rules (ACL). The policy file describes who can access what, for example “developers see test servers, accounting — only the 1C server”. Important: until rules are defined, the default policy allows all devices in the network to talk to each other.
- Subnet router. A device with Tailscale exposes an entire local network behind it — printers, cameras, servers that you can’t install the app on.
- Exit node. A device through which another network member can send all their Internet traffic.
- Login via Tailscale SSH, sharing individual devices, authorization keys for servers — for automatic connections without interactive login.
Subnet router vs exit node — what’s the difference
These features are often confused, although they solve different tasks.
A subnet router gives access to a private network. For example, an office server runs Tailscale, and behind it is the network 192.168.10.0/24 with a printer and an old server. An employee at home connects to 192.168.10.20, and traffic to the office network goes through that server. The employee’s Internet traffic still goes normally, directly.
# on the server in the office
sudo tailscale set --advertise-routes=192.168.10.0/24After that the route must be approved in the admin console (Machines section) or pre-approved by the autoApprovers rule in the policy file. On Linux, IP forwarding must also be enabled for routing.
An exit node sends all a device’s Internet traffic out to the Internet. This is useful, for example, on a public Wi-Fi when you want to go out to the Internet via your home or office link.
# on the device that will be the exit node
sudo tailscale set --advertise-exit-node
# on the client
sudo tailscale set --exit-node=100.64.0.5The exit node also needs to be approved in the console. A device can be both a subnet router and an exit node at the same time.
Pricing — September 2026
According to tailscale.com/pricing:
| Plan | Price | Notes |
|---|---|---|
| Personal | free | up to 6 users, devices unlimited |
| Standard | $8 per user per month | unlimited users |
| Premium | $18 per user per month | advanced access rules and features for businesses |
| Enterprise | on request | custom terms |
Pricing is per user (“seat”), not per device. For a home or small team, the free Personal plan is usually sufficient.
For a Russian company it’s important to note: foreign plans cannot be paid with a Russian card — Visa and Mastercard suspended operations in Russia in March 2022. In addition, the coordination server is located abroad and managed by a third-party company. If this is unacceptable, there are options with a self-hosted coordination server — NetBird and Headscale.
How to get started
- Install the app on the first device: clients exist for Windows, macOS, Linux, iOS and Android. On Linux — run the installer script from the site, then
sudo tailscale up. - Sign in with a Google, Microsoft, GitHub or other supported provider — this creates your network.
- Repeat on the other devices. They will immediately see each other by addresses in the 100.x.y.z range and by MagicDNS names.
- Configure access rules before production servers join the network.
- For headless servers use authorization keys, and for an office network use a subnet router.
Common mistakes
- Leaving the policy “everyone can do everything”. Any device in the network, including an employee’s personal phone, can see all servers.
- Confusing subnet router and exit node. Enabling the exit node to reach the office network and then getting all Internet traffic routed through the office.
- Forgetting to approve the route in the console. The command was run, but there’s no access to the subnet.
- Overlapping subnets. If home and office both use 192.168.1.0/24, routing will be ambiguous — it’s better to choose a nonstandard office addressing.
- Storing authorization keys in plaintext in scripts and repositories.
When Tailscale is suitable and when it’s not
Suitable: you need remote access to multiple devices and sites without your own VPN server, there’s no network administrator on the team, and it’s important to get started quickly.
Not suitable: the coordination server must be under your control or located in Russia, you need a layer-2 (L2) network, or you need full control over every setting. For these cases — ZeroTier, NetBird, Headscale or manual WireGuard setup.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Networking and routing
MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.
Typical tasks behind this topic
- Set up VPN and secure access to office or cloud
- Fix routing, DNS, or unstable connectivity
- Configure MikroTik, firewall, and external links
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Reviews
Related reviews
Huge thanks to Mikhail for the work — I'm very pleased with the result. Special thanks for his recommendations during setup: from my rather muddled brief (I know little about servers), Mikhail, through clarifying questions and suggestions, formed a clear understanding of what the final build would accomplish and how best to organize everything. I recommend him!
Many thanks to Mikhail for the work, I am very pleased with the result. I especially thank him for the recommendations during the setup process — from my rather muddled brief (and I know little about servers) Mikhail, …
MikroTik hAP router setup. I'll set up a MikroTik Wi‑Fi router for you.
2025-07-21 · ★ 5/5
An excellent specialist, a savvy expert, and a wonderful person. In an hour he fixed what we'd been racking our brains over for days! I'm sure this won't be the last time we rely on his boundless professionalism.
An excellent specialist, a savvy expert, and a wonderful person. In an hour he fixed for us what we had been scratching our heads over for days! I'm sure this won't be the first time we make use of his boundless …
MikroTik hAP router setup. I'll configure a MikroTik Wi-Fi router for you.
2025-05-28 · ★ 5/5
A professional approach to the job!
Professional approach to the job!
MikroTik hAP router setup. I'll set up a MikroTik Wi-Fi router for you.
2025-03-31 · ★ 5/5
Knows their stuff, gets things done. Everything was prompt and to the point; I was satisfied with the collaboration.
Knows, can, does. Everything was prompt and to the point; I was satisfied with the collaboration.
MikroTik hAP router setup. I'll set up a MikroTik Wi‑Fi router for you.
2025-03-14 · ★ 5/5
Thanks! We set up the router according to my technical specification, with a full explanation of what we're doing.
Thank you! The router was configured according to my technical specification, with a full explanation of what we are doing
MikroTik hAP router setup. I'll configure a MikroTik Wi‑Fi router for you.
2025-03-09 · ★ 5/5
Everything's great! Thanks! I recommend it.
Everything's great! Thank you! I recommend it
// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related