Nicholas TongTailscale
09 / 46
Tailscale: the tool that deleted my port forwards
For six years my jump box was a $4 a month VPS in a Dallas datacenter, hostname bayou-1, port 22 open to the entire internet and guarded by fail2ban, a 32-character password, and hope. I checked its auth log maybe weekly, and it was a wall of brute force attempts from somewhere on every single page, thousands per day, none of them clever, all of them persistent. Nothing ever got in. That was luck and a good password, and I knew it, and I kept the box because port forwarding was the only way I knew to reach my machines.
In 2022 I installed Tailscale on it, ran for a month in parallel, then deleted the port forwarding rule on a Tuesday afternoon while a build ran. The free plan costs nothing, indefinitely, for unlimited devices and up to 6 users. The jump box is still there, named after a bayou, and nothing on it faces the internet anymore.
the part everyone gets wrong
People call Tailscale a VPN, and the word does more harm than good. A VPN sends your traffic through a server. Tailscale is a mesh: your devices get WireGuard keys, negotiate direct tunnels with each other, and the traffic goes peer to peer, end to end encrypted, not through Tailscale's infrastructure. When NAT traversal fails, traffic relays through DERP servers, which can't read it. The result isn't "secure remote access." It's "your machines can talk to each other as if the internet didn't exist," which is a different and better thing.
The part everyone also gets wrong is the trust model. The coordination server, the thing that tells your phone where your laptop is, sees your public keys and your device topology: who can reach whom, when connections form. It can't read your traffic, but it can see the shape of your network, and for a long time it could also introduce new nodes into it. Tailnet lock is the fix, and almost nobody I talk to has it on: with lock enabled, the coordination server cannot add a node without a signed approval from a key you hold. That turns "trust Tailscale Inc" into "trust the keys you hold," and it costs one evening.
the mechanics
Install the client, log in with SSO, and every device gets a stable IP on a virtual network. MagicDNS gives them names, so ssh bayou-1 just works from anywhere. ACLs are a JSON file that says which identities reach which machines, default deny, and the free plan gives you 3 ACL groups and 50 tagged resources, enough for a homelab and then some. Tailscale SSH is the feature I use daily: SSH through the tailnet with the session authorized by your ACL policy, no port 22 on the public internet anywhere in the stack.
The free plan's limits are real but generous: 1,000 minutes a month of ephemeral resources for CI runners, 6 users, and access to nearly everything including SSH and subnet routers. There's a Mullvad exit node add-on at $5 a month per 5 devices if you want browsing privacy through the same client. Paid tiers, $8 and $18 per user per month, add flow logs, session recording, and SCIM, which is where the company actually makes money, on teams, not on me.
The clients are open source. The coordination server is not, and Headscale, the community reimplementation, exists for people who can't accept that, at the cost of maintaining your own control plane.
where it breaks
The control plane is a dependency. If Tailscale's coordination servers go down, existing tunnels keep passing traffic, but no new connection can be established and no new device can join. I've lived through one such outage, brief, but it reordered my thinking: during Hurricane Beryl in 2024, when Houston was dark for four days, my tailnet consisted of two phones and a laptop on a hotspot, and the machines I actually wanted to reach were powered off in a closet. The tool can't reach hardware that has no power, and that's the outage nobody budgets for.
The identity model is the other dependency. Your tailnet is anchored to an SSO account, Google or GitHub or Apple, and the security of everything reduces to that account. 2FA on the IdP isn't optional advice here, it's the front door. A phished GitHub session is a phished network, and that's a stronger statement than most VPN vendors would ever make about themselves.
Speed depends on the path. Direct connections are full line rate, but when two strict NATs can't negotiate, traffic falls to DERP relays and throughput drops hard, enough to notice on file transfers. And the free tier's 50 tagged resources are a ceiling you hit around the time you start tagging everything, which is the point of the cap.
My admission, because it costs something: I left bayou-1's old port forwarding rule enabled on the router for eleven months after Tailscale made it pointless, out of superstition, because the backup path felt like safety. It was attack surface, not safety, and I knew that when I wrote this sentence.
what to do
- Install it on two devices, a laptop and one always-on machine, and log in with an SSO account that has 2FA.
- Turn on Tailnet lock before you add your tenth node. Adding it later means re-signing everything.
- Write one default-deny ACL instead of leaving everything open inside the tailnet. One hour, and it's the difference between a mesh and a flat network.
- Delete one port forward from your router this week. One.
- Keep a backup path that doesn't depend on the internet: a screen, a keyboard, and the knowledge that the closet is five steps away.
During the four days Beryl took our power, the tailnet did exactly one useful thing: it let me see, from a relative's house, that my NAS was unreachable because the power was out, which I already knew, from the dark.
Delete the port forward. The auth log will get quieter and you'll never miss it.