Tailscale for families: remote help, home files and safer public Wi-Fi
Tailscale links your family’s phones, computers and home devices into one private network. It works wherever each device happens to be, and you don’t touch a single router setting. Here’s how to set it up for a household, and the few settings that matter.
What Tailscale is
Tailscale is a VPN built on the WireGuard protocol, but it doesn’t work like the VPN apps advertised on podcasts. Instead of sending your traffic through someone else’s servers, it creates direct, encrypted connections between your own devices. Together they form your private network, which Tailscale calls a tailnet. Each device gets a stable private address and name, so your laptop can reach the home NAS from a hotel just as if it were on the couch.
The key benefit for families: no port forwarding. You don’t open anything on your router to the internet, which removes one of the most common ways home devices get attacked.
Cost: at the time of writing, Tailscale’s free Personal plan covers up to six users with no cap on personal devices, which is plenty for most families. Plans change, so check tailscale.com/pricing before you rely on it.
Five family uses
- Help a parent from your own home. Once both computers are in the tailnet, the screen-sharing tools built into macOS, or remote desktop tools on Windows and Linux, can connect directly. You don’t need a third-party remote-support account.
- Reach family photos on a home NAS from anywhere, without exposing the NAS to the internet.
- Safer public Wi-Fi. Route a phone’s traffic through home using an exit node when you’re on airport or café Wi-Fi.
- Ad blocking everywhere. If you run Pi-hole, Tailscale can point every device in the tailnet at it, even on mobile data.
- Check on the house. Reach a home-automation dashboard or camera recorder privately instead of through a cloud service.
Setup in 20 minutes
- Create the tailnet. Go to tailscale.com and sign up with an existing login such as Google, Microsoft, Apple or GitHub. That account owns the tailnet, so protect it with two-factor authentication.
- Install Tailscale on your own devices first (Windows, Mac, iPhone, Android, Linux) and sign in with the same account. Each device appears in the admin console at login.tailscale.com.
- Give devices clear names in the admin console, such as
mom-laptop,home-nasordad-phone. With MagicDNS (on by default for new tailnets) you can reach them by name. - Test. Turn off Wi-Fi on your phone so it’s on mobile data, open the Tailscale app, and try to reach a home device by name, for example the NAS’s web page.
Adding family members
You have two options:
- Invite them as users (admin console → Users → Invite). They sign in with their own account, and their devices join your tailnet. Best for people who live with you or whom you support often.
- Share a single device (admin console → Machines → the device’s menu → Share). The other person can reach only that device, from their own tailnet. Good for giving a sibling access to the family photo NAS and nothing else.
Exit node: your home internet, anywhere
An exit node is a device at home that other devices can send all their internet traffic through. On public Wi-Fi, your phone’s browsing is then encrypted all the way to your house and leaves from your home connection.
- Pick a device that’s always on and plugged in at home. A Raspberry Pi, a mini PC, a Mac or Windows PC that stays awake, or an Apple TV running the Tailscale app can all serve as exit nodes.
- Enable “Run as exit node” in its Tailscale app. On Linux, follow Tailscale’s exit-node guide: it covers turning on IP forwarding, then running
sudo tailscale set --advertise-exit-node. - Approve it in the admin console (the machine’s menu → Edit route settings → Use as exit node).
- On your phone, open Tailscale, choose Exit node, and pick the home device. Turn it off again when you’re back on trusted Wi-Fi.
Your speed through an exit node is limited by your home upload speed, so it’s fine for browsing but may be slow for streaming on some connections.
Reaching devices that can’t run Tailscale
Printers, cameras and many smart-home hubs can’t run Tailscale. A subnet router fixes that: one home device advertises your whole home network to the tailnet. On a Linux device, after enabling IP forwarding as Tailscale’s docs describe, you’d run something like:
sudo tailscale set --advertise-routes=192.168.1.0/24
Use your own network range, then approve the route in the admin console. Only do this if you need it. Tailscale is most secure when each device runs it directly.
Settings that matter
- Key expiry. By default, devices must re-authenticate periodically (every 180 days unless changed). That’s good for phones and laptops. For home servers, exit nodes and a parent’s computer, use Disable key expiry in the machine’s menu so they don’t silently drop off.
- Access controls. Out of the box, every device in a personal tailnet can reach every other device. That’s fine for a couple. In a bigger family, edit the tailnet policy (admin console → Access controls) so that, for example, the kids’ devices can reach only the media server. Tailscale’s docs include examples to start from.
- Remove lost or old devices from the admin console promptly.
- Protect the account that owns the tailnet with two-factor authentication. Whoever controls that login controls the network.
- DNS: under the admin console’s DNS page you can add your Pi-hole as a nameserver and choose to override local DNS, so blocking follows your devices everywhere.
What you might need
Nothing, in many homes: an always-on computer or an Apple TV you already own can be the exit node. If you’d like a dedicated, low-power device:
- A small, quiet always-on device for an exit node or subnet router. Example: Raspberry Pi kit with case and power supply
- Or a fanless mini PC if you also want to run Pi-hole and other home services. Example: fanless mini PC