The Struggles of Accessing a Homelab Server Remotely
You just set up an Ubuntu server at home. You installed everything: Plex, Nextcloud, Home Assistant, and a few Docker containers to experiment with. Everything runs smoothly on your local network. But the moment you step out to a coffee shop, you lose all connection to your server.
Traditionally, the go-to solution was port forwarding on your router combined with Dynamic DNS. However, this comes with major security risks. The second you expose a port to the Internet, your server’s auth logs will be flooded with brute-force scans from botnets worldwide. Worse yet, most ISPs now use CGNAT. Without a dedicated public IP, port forwarding becomes virtually impossible unless you pay extra for a static IP.
Setting up OpenVPN or WireGuard manually is a solid alternative, but generating certificates, configuring routing tables, and maintaining an intermediary VPS takes up far too much time.
How Tailscale Solves This Problem
Imagine Tailscale as an invisible, virtual Ethernet cable connecting your laptop on the road directly to the Ubuntu machine sitting under your desk at home.
Unlike traditional VPNs that route all traffic through a central gateway, Tailscale operates on a Mesh VPN architecture. Devices establish direct peer-to-peer connections with each other.
The platform uses the WireGuard protocol for ultra-low latency encryption (typically adding just 1–3ms over baseline ping times). Tailscale’s biggest advantage is its automatic NAT Traversal. Even if your server and laptop are behind different firewalls and routers, they automatically establish a direct handshake without requiring any router configuration changes.
Step-by-Step Guide to Installing and Configuring Tailscale on Ubuntu
Step 1: Create an Account
Visit the Tailscale website and sign up for a free account using GitHub, Google, or Microsoft. The personal Free plan supports up to 3 users and 100 devices—more than enough for personal homelab needs.
Step 2: Install Tailscale on Ubuntu
Tailscale provides an automated installation script that detects your Ubuntu distribution (with full support for 20.04, 22.04, and 24.04 LTS). Open your terminal and run:
curl -fsSL https://tailscale.com/install.sh | sh
Once installed, start the service and enable it to launch on boot:
sudo systemctl enable --now tailscaled
sudo systemctl status tailscaled
Step 3: Authenticate the Device to Your Tailnet
To connect your Ubuntu machine to your account, start the Tailscale client:
sudo tailscale up
The terminal will display a unique authentication URL:
To authenticate, visit:
https://login.tailscale.com/a/9a8b7c6d5e
Copy this URL, paste it into your browser, sign in with the account created in Step 1, and click Connect to authorize the new node.
Bước 4: Check the Server’s Tailscale IP
After joining your private network (Tailnet), the Ubuntu machine will be assigned a static IP in the 100.x.y.z range (Carrier-Grade NAT range). Check this IP address by running:
tailscale ip -4
This will return an address like 100.85.24.120. You can also view the online/offline status of all other nodes in your network:
tailscale status
Step 5: Install the Client and Test Remote Access
Next, install the Tailscale app on your client device (macOS, Windows, iOS, or Android) and log in with the same account. Both devices are now instantly part of the same virtual LAN.
Open a terminal on your laptop at a coffee shop and SSH directly into your home server:
ssh [email protected]
Similarly, if you are running a Portainer dashboard on port 9000 on the server, simply navigate to http://100.85.24.120:9000 in your browser for seamless access.
Pro Tip: Enable MagicDNS
Memorizing 100.x.y.z IP addresses can be tedious. Navigate to Tailscale Admin Console > DNS and enable MagicDNS. This allows you to connect using your machine’s hostname directly:
ssh user@ubuntu-server
ping ubuntu-server
Conclusion
No router port forwarding, no botnet threats, and no need to pay for an expensive static IP. With Tailscale on Ubuntu, setting up a secure, encrypted tunnel for your entire homelab takes less than 5 minutes.

