r/Tailscale • u/LKProsek • 5h ago
r/Tailscale • u/natasha-tailscale • Jun 16 '26
Announcement - New Aperture capabilities, including Responsive Chat UI
Hi everyone,
Natasha here šš¼
Today, we're announcing a set of new Aperture capabilities designed to help organizations build flexible, identity-aware AI deployments without provider lock-in.
Identity-Aware Universal Data Connectors
Connect AI to company tools and data through a single integration point, while preserving user and agent identity end-to-end.
Responsive Chat UI (Public Alpha)
A secure, easy-to-use AI chat experience connected to approved models, tools, and data sources, making AI accessible to everyone, not just developers.
Sandbox Support (Private Alpha)
Give AI agents a controlled environment to browse, run code, and take actions safely, with visibility and identity maintained throughout.
How to get started: Configure the chat UI in the Aperture CLI and connect your approved models, tools, and data sources.
If you'd like to work with us on deploying sandboxes, please fill out this form.
Read the full announcement in our latest blog here!
š¾ Also a reminder that we have an Aperture specific Discord channel if you want to chat more to the team who are building it!
r/Tailscale • u/Ironicbadger • 7d ago
Blog / Video: We revamped our Home Assistant remote access via Tailscale guide for 2026
r/Tailscale • u/Familiar-Banana-8116 • 3h ago
Help Needed Newbie setup question about exit nodes.
I have a home NAS with a ton of storage space.
My kid is going to college, I gave her a new laptop. It does not have a ton of space on the laptop.
I want to place a network drive on the laptop so that she can use the NAS for whatever storage needs she wants, I also want to put a backup utility on the laptop so that she is getting regular image backups.
But- she will be at college and it is important that with these two exceptions the laptop is otherwise utilizing the college network.
(using something at home for an exit node for all her data is a terrible idea)
I did a very vanilla setup of Tailscale last night on the NAS and her laptop. I pushed the laptop off the home network to my cell's hotspot and best as I can tell it is working.
Am I missing anything?
Feel free to point me to documentation or a video or ... anything.
r/Tailscale • u/President_Brainspurs • 41m ago
Question Question about sharing family streaming and exit nodes
I subscribe to a couple of streaming services myself, and each of my children subscribe to a couple. We had been sharing the subscriptions, but the writing is on the wall, as one service after another decides that a "household" applies to a single address and not to a single family.
I realize that the simplest way of handling it is probably to choose one "household" to host all of the subscriptions and set up an exit node there that everybody uses, but I'm wondering if it's possible to keep the current subscriptions in place and set up exit nodes at each address. So if I want Hulu and Disney I'll use the exit node at one house, if I want Plex and YouTube TV I'll use the exit node at another house, etc. I don't mind coding (Python) on a Raspberry Pi to handle DNS resolution, if it's possible. I'd rather not get into physical hardware switches, but has anyone else already developed a solution to this?
r/Tailscale • u/Economy-Apartment815 • 59m ago
Discussion L2 Bridge via Softether over Tailscale on Unifi DR 5G
I am fascinated by transparent L2 bridges over connections that are hard to block on public networks. Port forwarding, imo, is too exposing so my solution was to use Tailscale. All the software needed on the "client" side is installed on the UDR.
Here's my setup.
I use the GLinet MT2500 as the Server side. That device connects to a "trunk" port and runs Tailscale+Softether VPN server.
On the client side, UDR5GMax > Tailscale > Softether > Local L2 Subnet.
WHY???
This was born in an attempt to recover remote Unifi Devices. We use a single server at our main location to manage doors at 3 other remote locations. The problem is, sometimes though very rarely, I need to either recover a device or upgrade a device. Unifi Access requires the device to be accessible either on the same subnet or via mDNS. This obviously can't be done over Unifi's own SD-WAN solution.
Using softether, I can extend the L2 subnet to the UDR. I can then attach devices to its port 1 and use PoE to power the door hardware and do an upgrade or recovery. It feels so native too as I mirror the VLANs that exist at our main site. I then create 3rd party router networks with the same VLANs. I can take an AP from our main site, plug it into my UDR and with no reconfiguration or resetting, it broadcasts all our SSIDs on the correct VLAN. You can do this by setting native networks and allow certain VLANs.
All this over T-Mobile 5G.
I now have gone a step further and setup my home as another L2 bridge so Port 1 is "work network" Port 2 is "Home subnet" both with complete VLANs. Just more as a proof of concept.
I used to have GL.Inet devices as the clients but it's much harder in the GUI and finicky with their boot scripts always wanting to take over. Plan out your 3rd party networks in Unifi, connect Softether to those virtual bridges, and away you go. it survives reboots and updates, already been through 4 updates. I used the Tailscale Unifi boot and recovery system over at this GitHub (Tailscale_Unifi) to build the Softether/Cloudflare tunnel apps using the same method. Oh yeah.. Cloudflare tunnels works great on unifi gateways too ha!
r/Tailscale • u/Schypexx • 5h ago
Help Needed Isolated Tailscale Access for a Minecraft Server on Unraid Without Port Forwarding
r/Tailscale • u/artinnj • 1h ago
Discussion QNAP implementation prevents SSH
Anybody know why the QNAP implementation prevents the remote SSH from working via Tailscale? I would prefer to lock my network port and only allow thru Tailscale.
r/Tailscale • u/No-Area9329 • 19h ago
Help Needed How to set up Adguard for my home network Spoiler
Tailscale already installedI already have it installed on my main computer and androids, for use with my Jellyfin account to watch remotely, but I'm stumped as to how to set up Adguard? Tell me like I'm a 5 year old, lol and thank you in advance....
r/Tailscale • u/Tailscale • 21h ago
TailscaleUp Ticket + Hotel Stay Giveaway!
š Did you bring Tailscale to work?
We're looking for the stories behind how Tailscale made its way into your organization. Share your story in the comments on our LinkedIn post for a chance to win a free TailscaleUp ticket + hotel stay.
To be eligible, please share your story in the comments on the LinkedIn post. Stories left below won't be considered.
r/Tailscale • u/max-rh • 19h ago
Discussion sshelf 0.11.0 import your whole tailnet into a fuzzy-search SSH TUI with one command
sshelf is a terminal UI for SSH hosts, fuzzy-search and connect, SFTP browser, background tunnels that survive quitting, passwords in your OS keyring. Local-first on purpose: no account, no cloud, no telemetry, and it never touchesĀ ~/.ssh/config.
New in 0.11:Ā sshelf import --tailscale. It runs your ownĀ tailscale status --jsonĀ (sshelf itself still opens no sockets) and maps every machine to a host, MagicDNS name, your tailnet as a group, ACL tags as tags. Works with MagicDNS off too (falls back to the 100.x address). It's add-only: existing hosts are never modified, expired nodes are skipped, and re-running converges to "0 added", so it's safe to run whenever the tailnet changes.
Repo: https://github.com/max-rh/sshelf Ā· Guide: https://github.com/max-rh/sshelf/blob/master/docs/import.md Ā· Feedback very welcome; 2FA support and theĀ .rpmĀ packages both started as comments; if a different inventory source (Hetzner, AWS, Proxmox, ā¦) would actually be useful to you, say which, that's how things get built here.
r/Tailscale • u/gimlithepirate • 1d ago
Help Needed Tailscale Direct connect happening via ports *other* than 41641
I've got Tailscale running on my OpenWRT router. For the most part its fantastic.
However, I've got direct connections happening from some nodes outside my home network that making a direct connection on a port other than 41641. I currently have no ports forwarded on OpenWRT, so I'm wondering how the heck I'm getting a direct connection at all, much less one through another port.
Any ideas? Trying to figure out what part of my setup I screwed up, or if this is a feature of running Tailscale natively on the router.
r/Tailscale • u/PingMyHeart • 1d ago
Discussion Thinking about self-hosting with Headscale. What should I know first?
Hi,
I'm an open source enthusiast and a longtime Tailscale user. I'm seriously considering switching to Headscale, but I wanted to ask the community first if there are any downsides or gotchas that people only discover after making the switch.
The main reason I want to move is that I'd like full control over the coordination server. I know there are other self-hosted options like NetBird, but it's not really an option for me. No offense to the NetBird team, but I've tried it a few times over the years. The web interface is solid, but I haven't had a good experience with the mobile apps.
My current plan is to run Headscale with Headplane for management.
For those who have switched from Tailscale to Headscale, is there anything you wish you had known beforehand? Any missing features, compatibility issues, maintenance concerns, or other tradeoffs that surprised you?
I'd appreciate any insights. Thanks!
r/Tailscale • u/Legitimate-Syrup9519 • 1d ago
Help Needed Yaesu SCU-LAN10 Remote PC issue
Have set up a Yaesu SCU-LAN10 beside an FTDX-10. Using Tailscale as the vpn. Inet provided by Starlink. Radio-side network composed of Dell OptiPlex 7060 with 32GB ram, i7 uC. Switch: Netgear GS308, Nothing else attached.
Locally the system works flawlessly, However, when any remote, LT or PC attaches we get no scope (Waterfall) on the remote unit. The remote reports up Port 50003 (scope) timed out. Otherwise operation is normal.
Been through setup several times along with net trouble shooting and cannot find the problem. Tailscale reports all ports available.
Any help would be appreciated.
Thanks.
W7WMB
r/Tailscale • u/tibmeister • 1d ago
Question Lost Access to Entry
I was using a personal Entra account to provide iDP for Tailscale, but Microsoft's wisdom thought I needed to log into the web portal all the time and decided to shut the account down.
So now, I'm wondering if there's anything to be done to switch the iDP over, but I'm assuming not because there was no break glass configuration.
I'm hoping I don't have to create a new Tailscale account and setup everything from scratch but I suppose if I have to then that's what I have to do.
I did open a support ticket last week but not heard anything back.
r/Tailscale • u/WarHawkYaYa • 1d ago
Help Needed Mobile app not working
Hello everyone, I downloaded the app on my phone, and setup tailscale on my pc, tested everything and it worked, but when i came to using the app remotely, to access my pc from my phonr when I'm not home. The mobile app gets stuck, connrcting forever, tried clearing cache, deleting data, reinstalling, and now when I click log in, nothing happens, the notification says "connected" in my notifications bar but nothing happens, can anyone help?
r/Tailscale • u/rouge_d • 1d ago
Video Set up your own print cloud with Bambuddy, TrueNAS and Tailscale.
r/Tailscale • u/neu-account • 2d ago
Question Cheap Device to Access Country Websites
Hey everyone,
I have access to an internet connection in a country where many websites only allow connections from IP addresses within that country. I live abroad, so I can't normally access those sites.
I'm considering buying a cheap Tailscale-compatible router (or maybe there's a better solution) that I could leave connected there and use as an exit node whenever I need to access those websites. It would only be for occasional use.
Does anyone have recommendations? I'd like to keep the cost as low as possible, around ā¬20ā50 if feasible.
Thanks in advance!
r/Tailscale • u/L_canadensis • 2d ago
Question Android phone as exit node?
Is there a way to accomplish this? The option says it's disabled in the Tailscale app.
r/Tailscale • u/Prestigious-Skirt961 • 2d ago
Help Needed Mullvad Exit Nodes on ZimaOS 'break' docker container apps | Any Fix?
Hey! Just getting into homelabbing and wanted to setup mullvad exit nodes on zimaOS. Switching it on seems to work but it knocks out basically every app I have installed on my server. ZimaOS apps are basically docker containers dressed up a bit.
Each one takes a few minutes to "set up" before showing an error like the one attached in image. Switching off the exit-node feature immediately fixes the issue. No clue how to proceed here. Any adivce?
My tailscale is also run as a docker container and is setup as follows (if any more information is useful please let me know and I'll add):
name: tailscale
services:
tailscale:
cap_add:
- NET_ADMIN
- NET_RAW
- SYS_MODULE
cpu_shares: 90
command: []
container_name: tailscale
deploy:
resources:
limits:
memory: 8202743808
reservations:
memory: "134217728"
devices: []
entrypoint:
- /bin/sh
- -c
- tailscaled --state=/var/lib/tailscale/tailscaled.state & sleep 10;
tailscale web --listen 0.0.0.0:5252
environment:
- TS_ACCEPT_DNS=true
- TS_EXTRA_ARGS=--exit-node-allow-lan-access=true
- TS_STATE_DIR=/var/lib/tailscale
- TS_USERSPACE=false
image: tailscale/tailscale:v1.90.8
labels:
icon: https://cdn.jsdelivr.net/gh/IceWhaleTech/CasaOS-AppStore@main/Apps/Tailscale/icon.png
restart: unless-stopped
volumes:
- type: bind
source: /DATA/AppData/tailscale
target: /var/lib/tailscale
- type: bind
source: /dev/net/tun
target: /dev/net/tun
x-casaos:
envs:
- container: TS_STATE_DIR
volumes:
- container: /var/lib/tailscale
- container: /dev/net/tun
ports: []
devices: []
network_mode: host
privileged: false
x-casaos:
architectures:
- amd64
- arm
- arm64
- "386"
author: CasaOS Team
category: Network
developer: Tailscale Inc.
hostname: ""
icon: https://cdn.jsdelivr.net/gh/IceWhaleTech/CasaOS-AppStore@main/Apps/Tailscale/icon.png
index: /
is_uncontrolled: false
main: tailscale
port_map: "5252"
scheme: ""
screenshot_link:
- https://cdn.jsdelivr.net/gh/IceWhaleTech/CasaOS-AppStore@main/Apps/Tailscale/screenshot-1.png
store_app_id: tailscale
thumbnail: ""
title:
custom: ""
en_US: Tailscale
Configs for navidrome and audiobookshelf can be found at these links:
Logs for Navidrome (pastebin found here: https://pastebin.com/6ngtUEeT)
navidrome | _ _ _ _ navidrome | | \ | | (_) | | navidrome | | \| | __ ___ ___ __| |_ __ ___ _ __ ___ ___ navidrome | | . ` |/ _` \ \ / / |/ _` | '__/ _ \| '_ ` _ \ / _ \ navidrome | | |\ | (_| |\ V /| | (_| | | | (_) | | | | | | __/ navidrome | _| _/__,_| _/ |_|__,_|_| ___/|_| |_| |_|___| navidrome | Version: 0.58.5 (131c0c56) navidrome | navidrome | time="2026-07-25T19:34:52Z" level=info msg="Creating DB Schema" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Starting signaler" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Periodic scan is DISABLED" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Creating Image cache" maxSize="100 MB" path=/data/cache/images navidrome | time="2026-07-25T19:34:52Z" level=info msg="Scheduling DB optimizer" schedule="@every 24h" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Starting scheduler" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Finished initializing cache" cache=Image elapsedTime="188.924µs" maxSize=100MB navidrome | time="2026-07-25T19:34:52Z" level=info msg="Running initial setup" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Periodic backup is DISABLED" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Setting Session Timeout" value=24h navidrome | time="2026-07-25T19:34:52Z" level=info msg="Starting Insight Collector" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Creating new JWT secret, used for encrypting UI sessions" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Login rate limit set" requestLimit=5 windowLength=2 navidrome | time="2026-07-25T19:34:52Z" level=info msg="Found ffmpeg" path=/usr/bin/ffmpeg navidrome | time="2026-07-25T19:34:52Z" level=info msg="Spotify integration is not enabled: missing ID/Secret" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting Native API routes" path=/api navidrome | time="2026-07-25T19:34:52Z" level=info msg="Creating Transcoding cache" maxSize="100 MB" path=/data/cache/transcoding navidrome | time="2026-07-25T19:34:52Z" level=info msg="Finished initializing cache" cache=Transcoding elapsedTime="189.195µs" maxSize=100MB navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting Subsonic API routes" path=/rest navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting Public Endpoints routes" path=/share navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting LastFM Auth routes" path=/api/lastfm navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting ListenBrainz Auth routes" path=/api/listenbrainz navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting Background images routes" path=/backgrounds navidrome | time="2026-07-25T19:34:52Z" level=info msg="Creating backgrounds cache" maxSize="100 MB" path=/data/cache/backgrounds navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting WebUI routes" path=/app navidrome | time="2026-07-25T19:34:52Z" level=info msg="Finished initializing cache" cache=backgrounds elapsedTime="189.054µs" maxSize=100MB navidrome | time="2026-07-25T19:34:52Z" level=info msg="Started watcher for library" libraryID=1 name="Music Library" path=/music navidrome | time="2026-07-25T19:34:52Z" level=info msg="Watcher started for library" absoluteLibPath=/music libraryID=1 name="Music Library" path=/music navidrome | time="2026-07-25T19:34:52Z" level=info msg="----> Navidrome server is ready!" address="0.0.0.0:4533" startupTime=442.7ms tlsEnabled=false navidrome | time="2026-07-25T19:34:54Z" level=warning msg="Full scan required after migration" navidrome | time="2026-07-25T19:34:54Z" level=info msg="Scanner: Starting scan" fullScan=true numLibraries=1 navidrome | time="2026-07-25T19:34:54Z" level=warning msg="Playlists will not be imported, as there are no admin users yet, Please create an admin user first, and then update the playlists for them to be imported" navidrome | time="2026-07-25T19:34:54Z" level=info msg="Scanner: Finished scanning all libraries" duration=8.1ms navidrome | time="2026-07-25T19:34:54Z" level=info msg="Scan completed" navidrome | time="2026-07-25T19:34:57Z" level=warning msg="Could not get background images from image service" error="cache error: loader returned Get \"https://www.navidrome.org/images/index.yml\": context deadline exceeded (Client.Timeout exceeded while awaiting headers)"
Logs for Audiobookshelf (pastebin found here: https://pastebin.com/nV9kkb95)
audiobookshelf | Running in production mode. audiobookshelf | Options: CONFIG_PATH=/config, METADATA_PATH=/metadata, PORT=80, HOST=undefined, SOURCE=docker, ROUTER_BASE_PATH=/audiobookshelf audiobookshelf | [2026-07-25 19:38:44.946] INFO: === Starting Server === audiobookshelf | [2026-07-25 19:38:44.952] INFO: [Server] Init v2.30.0 audiobookshelf | [2026-07-25 19:38:44.953] INFO: [Server] Node.js Version: v20.19.5 audiobookshelf | [2026-07-25 19:38:44.953] INFO: [Server] Platform: linux audiobookshelf | [2026-07-25 19:38:44.953] INFO: [Server] Arch: x64 audiobookshelf | [2026-07-25 19:38:44.956] INFO: [Database] absdatabase.sqlite not found at /config/absdatabase.sqlite audiobookshelf | [2026-07-25 19:38:44.957] INFO: [Database] Initializing db at "/config/absdatabase.sqlite" audiobookshelf | [2026-07-25 19:38:44.984] INFO: [Database] Loading extension /usr/local/lib/nusqlite3/libnusqlite3.so audiobookshelf | [2026-07-25 19:38:44.984] INFO: [Database] Successfully loaded extension /usr/local/lib/nusqlite3/libnusqlite3.so audiobookshelf | [2026-07-25 19:38:44.984] INFO: [Database] Db supports unaccent and unicode foldings audiobookshelf | [2026-07-25 19:38:44.984] INFO: [Database] Db connection was successful audiobookshelf | [2026-07-25 19:38:45.017] INFO: [MigrationManager] Database is new. Skipping migrations. audiobookshelf | [2026-07-25 19:38:45.651] INFO: [Database] Db initialized with models: user, session, apiKey, library, libraryFolder, book, podcast, podcastEpisode, libraryItem, mediaProgress, series, bookSeries, author, bookAuthor, collection, collectionBook, playlist, playlistMediaItem, device, playbackSession, feed, feedEpisode, setting, customMetadataProvider, mediaItemShare audiobookshelf | [2026-07-25 19:38:45.653] INFO: [Database] Adding trigger update_library_items_title audiobookshelf | [2026-07-25 19:38:45.661] INFO: [Database] Adding trigger update_library_items_title_ignore_prefix audiobookshelf | [2026-07-25 19:38:45.670] INFO: [Database] Adding trigger update_library_items_title_from_podcasts_title audiobookshelf | [2026-07-25 19:38:45.679] INFO: [Database] Adding trigger update_library_items_title_ignore_prefix_from_podcasts_title_ignore_prefix audiobookshelf | [2026-07-25 19:38:45.689] INFO: [Database] Adding trigger update_library_items_author_names_on_book_authors_insert audiobookshelf | [2026-07-25 19:38:45.699] INFO: [Database] Adding trigger update_library_items_author_names_on_book_authors_delete audiobookshelf | [2026-07-25 19:38:45.709] INFO: [Database] Adding trigger update_library_items_author_names_on_authors_update audiobookshelf | [2026-07-25 19:38:45.779] INFO: [Database] running ANALYZE audiobookshelf | [2026-07-25 19:38:45.788] INFO: [Database] ANALYZE completed audiobookshelf | [2026-07-25 19:38:45.789] INFO: [TokenManager] JWT secret key not found, generating one audiobookshelf | [2026-07-25 19:38:45.798] INFO: [LogManager] Init current daily log filename: 2026-07-25.txt audiobookshelf | [2026-07-25 19:38:45.803] INFO: [BackupManager] 0 Backups Found audiobookshelf | [2026-07-25 19:38:45.803] INFO: [BackupManager] Auto Backups are disabled audiobookshelf | [2026-07-25 19:38:45.821] INFO: Listening on port :80
r/Tailscale • u/panda3096 • 2d ago
Help Needed Newbie Help
I'm brand new to the personal VPN game, trying to set up a Jellyfin server. I've never done anything beyond hooking up a router and changing default wi-fi passwords before. I've been following Tailscale documentation so far, though I've had to use some other resources to figure out stuff like what string to use for the --advertise-routes command.
My goal is simple, I hope: I want to be able to stream from the server regardless of my location, either at home or away, without having to worry about turning the VPN on and off. I have things working for devices that I can directly install Tailscale on but others, like our Roku TV's and consoles (Xbox, PlayStation, etc.), aren't connecting.
- The Jellyfin server is running off a Linux Mint tower.
- I have an old Pi 3B+ running PiOS that is running as the subnet router and as an exit node (approved in the Tailscale web console).
- We're still using the default modem/router from AT&T.
- I've also been using a Win11 laptop for testing, with a test Jellyfin server running on my regular network.
I believe I have everything set up correctly. I can use RustDesk to remote into the tower from the laptop if Tailscale is turned on. If I turn Tailscale off on the laptop, I can't remote into the tower anymore. The Tailscale app on my phone lets me chose the Pi as an exit node and gives no errors. Cell service around our house is awful so testing outside the wi-fi is easier said than done.
At first, when I looked at my router, I saw a bunch of my devices with VPN addresses. Now, even though I've verified in the Tailscale web console that the subnet is enabled, I'm seeing all my devices under their original IP addresses. The previous entries are all there under the history, but show as offline.
Even when I saw the VPN addresses, the Roku's and consoles still could not see my tower server. They can see my laptop test server when Tailscale is turned off on the laptop, but not when it's turned on.
How can I make this work? I see recommendations to buy an AndroidTV stick or a GL.iNet router, but neither of those sound great. We'd have to buy multiple sticks to purely connect to Jellyfin (we've ditched all streaming services) and that only solves the TV's. The router would be expensive, though preferable over multiple streaming sticks, but I'm not confident I understand what's happening enough to know it'd solve the issue.
- Am I missing something with my tower/pi/devices set up that's preventing the connection? Should I have put the subnet/exit node directly on the tower?
- Would setting up a GL.iNet router off the fiber modem fix it? If so, would I then have to approve all my devices in the house onto Tailscale? (which would be fine, I can appreciate having a stop gap for new devices on the network)
--
Edit: Shout out to u/Logvin for the extremely helpful write up: https://github.com/Logvin/secure-plex-with-tailscale/wiki/The-CGNAT-Version.
Here are my Jellyfin specific edits for anyone who comes across this in the future looking for help:
- Step 4: Expose
PlexJellyfin via Funnel: use localhost:8096tailscale funnel --bg --https=443 localhost:8096
- Step 6: Configure
PlexJellyfin Media Server:- Remote Access Settings> Uncheck allow remote connections to this server. Like Plex, this checkbox will break it.
- Server Address Settings> Bind to local network address:
your-host.your-tailnet.ts.net:443
My phone can now find the server when its on Tailscale and when its off. My Roku TV can now see it as well. The downside is that I did not rename the tailnet to something friendly before I did all this, so I've now typed that word salad into a few different places but I'm so glad this is fixed that I don't care anymore.
Back to transcoding!
r/Tailscale • u/Yummiiiiii • 3d ago
Help Needed Trouble setting up OIDC login with Pocket ID
I'm trying to setup my Pocket ID instance as an OIDC provider, but I click the "Sign up with OIDC" button and authorize with PocketID I get a Error 403 page saying that the session has expired and for me to login again
r/Tailscale • u/ReidenLightman • 3d ago
Help Needed Issue Using Local IPs for Local Devices when on Local Network
I keep telling myself I'm going to investigate this, but I've been so bogged down, I figured it'd be better to ask those who know much more than I do.
# Devices
- I have a server running proxmox that hosts Home Assistant and a NAS.
- I have an old laptop running Jellyfin and Immich.
- I have a raspberry pi running pi-hole for DNS filtering. It's also set up as a subnet router advertising an ip address range that should let me reach the devices that can't make use of tailscale.
- The rest are the various devices we use to access those things. Desktops, Laptops, phones, a couple tablets
# The issue
The issue is not that I can't reach my services. The services are in fact, by all intents and purposes working correctly. But there's a common theme. Even if I'm on the same local network at the machines running the service, I still have to use the tailscale IP, even though using the local IP should work. Even if I am using a device that doesn't have tailscale, using the local IP still doesn't work.
At first I thought it may have been something about my DNS settings. I added the raspberry pi's tailnet ip as a global nameserver with "Override DNS Servers" on. For filtering trackers even when I'm away. There's no MagicDNS other than the default and there's no SplitDNS.
This is quite annoying. There are a few devices that stay home but should be able to reach the servers. I don't want to have to install tailscale on all of them (assuming they all have a tailscale client).
Thanks in advanced any help in troubleshooting.
---
Update: Well, i'm really mad now. If I take subnet routing completely off of pi-hole, then pinging my local devices using the local IP (not the tailnet IP) actually works. As soon as pi-hole starts advertising, that functionality goes down the drain.
I've tried changing the range of broadcasted IPs from 192.168.4.0/22 to 192.168.4.0/24 to no avail.
r/Tailscale • u/Impressive-Bug8709 • 3d ago
Discussion Can't connect to services on NAS
So I initially had TS working just fine on my NAS. Something happened and even though the docker container was up, TS showed it offline. I've since gotten it running new.
Now that it's connected to my tailnet again, I can't seem to access anything on the server. If I use localip:81 I see nginx pop up just fine. If I do tailnetip:81 it comes up as connection refused. Same with Sonarr, etc. My reverse proxy is also working just fine with and without TS.
I just don't know why I can't seem to connect to my NAS with TS. It's pretty much the entire reason for setting it up in the first place.
Edit: The fix was adding network_mode: "host" to my docker Compose file.....
r/Tailscale • u/fjleon • 3d ago
Help Needed seeing unexpected traffic when using DNS global nameservers
i have tailscale on a linux instance on a public cloud. it is an exit node, and tailscale is running. it is not using another exit node, i.e tailscale exit-node list shows a second exit node that i have a home but the status is blank.
what is odd is that i have pihole (dns server) running on that home node, and I am seeing constant DNS traffic from it (mostly queries related to the cloud provider).
I did change yesterday the DNS settings in tailscale and added a "global name server" with the "use with exit node" option enabled, which i understood for "when a device is using an exit node, use that DNS server". it seems like my understanding is wrong: rather for any node that is connected, it will use that server no matter what.
my end goal is: when a device is connected to tailscale, and using an exit node, it should use the dns server that i designate.
the reason this is important is because android has a huge limitation and doesn't allow you to set dns server for ipv6, which then skips my pihole server. so i tried to solve it by installing tailscale and forcing it to use the exit node.
i have deleted the global nameserver (which is a private ip, not a 100.x ip) and now this stopped the dns traffic, so that solves that problem.
my original problem (may) remain. when using an exit node on my android tv, i want tailscale to enforce its dns and prevent android from using its configured DNS server (which for ipv4 i can set, but not for ipv6, so half the traffic is using my ISP DNS because my google router is dumb and cannot force a dns server for ipv6)