I wanted to print to my home printer from my phone while I was out. The printer only talks to the local network, my phone was on mobile data, and I didn’t want to expose anything to the public internet. It turned out Tailscale has a feature for exactly this, called subnet routing, and I had been ignoring it.
The idea: you nominate one always-on machine on your home network. In my case it’s a small Intel N100 mini PC that runs 24/7 anyway. You tell Tailscale that this machine is a gateway to your LAN, say 192.168.1.0/24. After that, any device on your tailnet can reach any address on your home network through it, as though it were plugged into your router. No port forwarding, no dynamic DNS, no holes in the firewall.
Setting it up
On the machine that will act as the router:
sudo tailscale up --advertise-routes=192.168.1.0/24
Use whatever subnet matches your network. 192.168.0.0/24 and 10.0.0.0/24 are the other common ones; your router’s admin page will tell you if you’re not sure.
Then enable IP forwarding so the machine actually passes the traffic through:
# Linux — survives reboots
echo 'net.ipv4.ip_forward = 1' | sudo tee /etc/sysctl.d/99-tailscale.conf
echo 'net.ipv6.conf.all.forwarding = 1' | sudo tee -a /etc/sysctl.d/99-tailscale.conf
sudo sysctl --system
Last step: open the Tailscale admin console, find the machine, and approve the advertised route. This is manual on purpose. Routes don’t go live until you approve them, which is a sensible default.
From then on, with Tailscale connected on my phone, I can open http://192.168.1.x:port for anything on the LAN: the printer’s web interface, dashboards, all of it.
The catch: discovery doesn’t cross subnets
The printer was reachable at its IP address, but my phone couldn’t find it on its own. iPhones discover printers with Bonjour, and Bonjour only works on the local network segment. It can’t see across into the tailnet.
There is no clever fix for this. You add the printer manually by IP address in the manufacturer’s app, and it works fine from then on. One tip: give the printer a DHCP reservation on your router so its address doesn’t drift. Mine moved once and I spent ten confused minutes before I worked out what had happened.
Why not just run WireGuard?
I used to run WireGuard on my router for this. It worked, but Tailscale is less fuss:
- No port forwarding. It gets through NAT on its own. My ISP uses CGNAT, which made inbound WireGuard somewhere between painful and impossible.
- No key management. Every device just signs in. No config files to distribute.
- Free for personal use, up to 100 devices. I will never hit that.
The trade-off is that you’re trusting Tailscale’s coordination server, and the free tier has limits that don’t matter at home. For my purposes — keeping LAN services off the public internet while still reaching them remotely — it’s the right tool.
I use it most weeks now: printing from wherever I happen to be, checking dashboards on the Pi without exposing them, occasionally SSHing into a LAN machine from my phone. Five minutes of setup for that is a fair trade.
As an Amazon Associate, Headless Diaries earns from qualifying purchases made through links on this page.