Remote Access — Tailscale, WireGuard, and Mesh VPNs vs. Port Forwarding

Complete beginner guide to accessing your homelab securely from anywhere, comparing Tailscale mesh VPN, native WireGuard, CGNAT traversal, and subnet routing.

On this page
  1. The Remote Access Dilemma
  2. The Remote Access Hierarchy
  3. What makes Tailscale so powerful?
  4. Step-by-Step: Installing and Connecting with Tailscale
  5. Command & flag breakdown
  6. Advanced Feature: Subnet Routing
  7. Flag breakdown
  8. The Open-Source Alternative: Headscale
  9. Maximum Security: Bind SSH to the VPN interface only

The Remote Access Dilemma

Once you have services running in your homelab (Nextcloud, Home Assistant, Plex, or SSH consoles), you naturally want to access them while away from home on your laptop or smartphone.

Traditionally, people opened ports on their home router (Port Forwarding). However, exposing ports invites continuous internet port scans, dictionary attacks, and exploit probes.

Modern networking replaces messy port forwarding with zero-trust Mesh VPNs.


The Remote Access Hierarchy

text
[ 1. Mesh VPN (Tailscale / Netbird) ] ── Highest Security (Zero open ports, works through CGNAT)
                │
[ 2. Native WireGuard (Single Port) ] ── High Performance (One UDP port forwarded)
                │
[ 3. Reverse Proxy with TLS + 2FA ]   ── Necessary for public-facing websites
                │
[ 4. Raw Port Forwarding ]            ── Dangerous (Never do this for admin panels or SSH!)

What makes Tailscale so powerful?

Tailscale creates a secure, peer-to-peer mesh network (a tailnet) connecting all your devices using the ultra-fast WireGuard cryptographic protocol.

Key advantages:

  • Zero open firewall ports: You do not need to configure port forwarding on your router.
  • Bypasses CGNAT & Firewalls: Using NAT traversal protocols (STUN and encrypted DERP relays), your laptop at a coffee shop connects directly to your home server even if your home ISP uses Carrier-Grade NAT.
  • Private 100.x.y.z IP Addresses: Every device receives a permanent, private IPv4 address accessible only to your authenticated devices.

Step-by-Step: Installing and Connecting with Tailscale

On your Linux home server or Proxmox host:

bash
# 1. Install Tailscale via official script
curl -fsSL https://tailscale.com/install.sh | sh

# 2. Authenticate and bring the VPN interface up
sudo tailscale up

# 3. View your assigned Tailscale IP address
tailscale ip -4

# 4. Check status and connected peers
tailscale status

Command & flag breakdown

  • curl -fsSL ... | sh:
  • -f (fail silently on HTTP errors).
  • -s (silent mode, hides progress bar).
  • -S (shows errors if curl fails).
  • -L (follows redirects).
  • tailscale up: Initializes the tailscale0 network interface and prints an authentication URL in your terminal. Open that URL in your browser to authorize the machine into your account.
  • tailscale ip -4: Displays only the private 100.x.x.x IPv4 address assigned to this node.
  • tailscale status: Lists all active machines on your private tailnet and their online/offline state.

Advanced Feature: Subnet Routing

What if you have devices in your home (like a smart home hub, printer, or IP camera) that cannot install Tailscale directly?

You can configure your Linux server to act as a Subnet Router, granting your remote phone access to your entire home LAN (192.168.1.0/24):

bash
# 1. Enable Linux IP packet forwarding
echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.d/99-tailscale.conf
sudo sysctl -p /etc/sysctl.d/99-tailscale.conf

# 2. Advertise your home LAN subnet
sudo tailscale up --advertise-routes=192.168.1.0/24

Flag breakdown

  • --advertise-routes=192.168.1.0/24: Informs the tailnet that this node can route packets destined for your local home subnet. Once approved in the Tailscale web admin console, your remote phone can connect to http://192.168.1.45 as if you were sitting on your home couch.

The Open-Source Alternative: Headscale

If you prefer not to rely on Tailscale's hosted control plane, Headscale is an open-source, self-hosted implementation of the Tailscale coordination server. It uses the exact same official Tailscale client applications on Linux, macOS, iOS, Android, and Windows, but keeps all coordination keys and metadata on your own sovereign server.


Maximum Security: Bind SSH to the VPN interface only

To make your server completely invisible to internet port scanners:

Edit /etc/ssh/sshd_config:

text
# Replace ListenAddress 0.0.0.0 with your private Tailscale IP:
ListenAddress 100.85.12.34

Restart SSH (sudo systemctl restart ssh). Now, port 22 is completely closed to the outside internet; only devices connected to your private VPN can even initiate an SSH handshake.