Skip to content
BotServBotServ
TailscaleVPNWireGuardNetworkingOllamaSecuritySelf-Hosting

Tailscale: Secure Network for AI Services

Tailscale for AI services: secure VPN without port forwarding. Remote access to Ollama and AI services. Setup guide with examples.

S

schutzgeist

11 min read
Tailscale: Secure Network for AI Services

Tailscale: Secure Networking for AI Services

What this article covers

  • How to install Tailscale and connect your devices to a secure network
  • How to access Ollama remotely over Tailscale without opening ports to the internet
  • How to use Subnet Routers to make your entire home network accessible
  • How to control access with Access Control Lists
  • Common pitfalls with DNS, firewalls, and Exit Nodes

Introduction: Understanding Tailscale

Running AI services at home often means wanting to access them from elsewhere. Your Ollama server runs on your home machine, but you’re at a café and want to query a model. The traditional approach requires opening ports on your router, setting up DynDNS, and hoping no one exploits the gap. That’s complicated and risky.

Tailscale solves this differently. It creates an encrypted mesh network between all your devices, based on WireGuard. Each device gets a fixed IP address within this network, called your Tailnet. As long as a device is online, you can reach it regardless of location. No port forwarding, no firewall holes, no DynDNS.

This article guides you through installation, first steps, and setting up Ollama over Tailscale. For more on self-hosting, see Self-Hosting. Network security fundamentals are covered in Secure Operation.

Why do you need Tailscale?

Imagine running Ollama on your home server. At home, you access it via http://localhost:11434. Now you’re at a café with your laptop and want to query the same model. Without Tailscale, you’d forward port 11434 from your router to the server. Anyone knowing your public IP could attempt accessing Ollama. Since Ollama has no authentication by default, that would be an open door.

With Tailscale, things work differently. Your home server and laptop are both registered in your Tailnet. The server gets a Tailscale IP, say 100.64.0.1. From the café, you access http://100.64.0.1:11434. The connection travels encrypted over WireGuard, and only your laptop can reach the server. No ports are exposed, no attacker gets through.

This principle works for any service, not just Ollama. Web interfaces, databases, file servers, everything is accessible over Tailscale without opening a single port to the internet. More on network security is available in Network Security and the Firewall article.

Tailscale explained

Tailscale is a VPN service based on WireGuard that builds a mesh network between your devices. You install the Tailscale client on each device, sign in, and it becomes part of your Tailnet. Every device gets a fixed IP in the range 100.64.0.0/10. Connections between devices are end-to-end encrypted and run directly when possible, otherwise through relay servers. You don’t need to open ports or configure routers.

Who is Tailscale for?

Tailscale targets anyone wanting to securely access services remotely without exposing their home network to the internet. That includes self-hosters running Ollama, Nextcloud, or other services at home and accessing them from elsewhere. It includes developers needing to reach internal servers and databases without setting up a traditional VPN. And it includes teams connecting multiple locations or devices securely without managing network infrastructure.

If you want to use Ollama securely from a distance, Tailscale is one of the simplest solutions. For more on Ollama networking, see Ollama Network Access.

Key terms

TermDefinition
TailscaleVPN service based on WireGuard that builds a mesh network
VPNVirtual Private Network, encrypted tunnel between devices
WireGuardModern VPN protocol underlying Tailscale
Mesh NetworkNetwork topology where devices connect directly to each other
TailnetThe private network encompassing all your Tailscale devices
NodeA device in the Tailnet, such as a server, laptop, or phone
Exit NodeA Tailscale device through which you can route all internet traffic
Subnet RouterA Tailscale device making an entire local network accessible in the Tailnet
ACLAccess Control List, rules defining who can access whom in the Tailnet
MagicDNSTailscale feature using device names instead of IP addresses for connections

Installing Tailscale

Tailscale is available for Linux, macOS, Windows, and mobile platforms. Installation is similar across each platform: install the client, sign in, done.

Linux (Ubuntu)

On Ubuntu, install Tailscale from the official repository:

curl -fsSL https://tailscale.com/install.sh | sh

Then start Tailscale and sign in:

sudo tailscale up

The command opens a link in your browser. Sign in with your Tailscale account, Google, Microsoft, GitHub, or email. The device is then added to your Tailnet. For more on Ubuntu, see Ubuntu.

macOS

On macOS, install Tailscale from the Mac App Store. After launch, sign in and the device becomes part of your Tailnet. Alternatively, use Homebrew:

brew install --cask tailscale

Windows

On Windows, download the installer from the Tailscale website and install it. After launch, sign in. Tailscale runs as a system tray app and connects automatically at startup.

Mobile (iOS and Android)

Install the Tailscale app from the App Store or Google Play. Sign in, and the device joins your Tailnet. You can now access your services from anywhere.

Getting started

After installing on multiple devices, check the status:

tailscale status

This lists all devices in your Tailnet with their IPs and online status. You see which devices are reachable and how the connection is established, direct or through relay.

Tailscale assigns IP addresses automatically. If you enable MagicDNS, you can address devices by name, for example ollama-server instead of 100.64.0.1. Enable MagicDNS in the Tailscale admin console under DNS.

Test connectivity between two devices with ping:

ping 100.64.0.1

If ping succeeds, your mesh network is active and you can reach services via Tailscale IP.

Making Ollama accessible over Tailscale

For Ollama to be reachable over Tailscale, you need to adjust two things: Ollama must listen on the Tailscale IP, and the firewall must allow the port.

Step 1: Set OLLAMA_HOST

By default, Ollama listens on 127.0.0.1:11434, local only. To make it reachable via Tailscale IP, set the OLLAMA_HOST environment variable to 0.0.0.0:11434:

export OLLAMA_HOST=0.0.0.0:11434
ollama serve

For persistent operation, add the variable to the systemd service. Details are in Ollama Configuration.

Step 2: Allow port in the firewall

If you use a firewall, such as UFW on Ubuntu, allow the port on the Tailscale interface:

sudo ufw allow in on tailscale0 to any port 11434

This permits connections to port 11434 only over the Tailscale interface, not over your public network interface. For more on firewalls, see Firewall.

Step 3: Access from another device

From your laptop or phone in the Tailnet, access Ollama:

curl http://100.64.0.1:11434/

If you’ve enabled MagicDNS, you can use the device name:

curl http://ollama-server:11434/

The connection is encrypted and accessible only to devices in your Tailnet. No one outside can connect. For more on network access, see Ollama Network Access.

Subnet Router

Sometimes you want more than just a single device accessible through Tailscale. You might want your entire home network reachable. That’s where a Subnet Router comes in. A Subnet Router is a Tailscale device that acts as a gateway for an entire IP subnet.

Enable a Subnet Router on your server:

sudo tailscale up --advertise-routes=192.168.1.0/24

This tells Tailscale that your server can route the subnet 192.168.1.0/24. You then need to approve the route in the Tailscale admin console under “Edit route settings” for that device.

On other devices, accept the route:

sudo tailscale up --accept-routes

Now you can access all devices on your home network from anywhere, like your NAS at 192.168.1.50 or your printer at 192.168.1.100. This works without installing Tailscale on every device.

Access Control Lists

Tailscale lets you control exactly who can access what in your Tailnet using Access Control Lists (ACLs). By default, every device can reach every other device. In larger setups or with multiple users, you’ll want to restrict this.

Define ACLs in the Tailscale admin console under “Access Controls”. The syntax is JSON. Here’s a simple example:

{
  "acls": [
    {
      "action": "accept",
      "src": ["laptop"],
      "dst": ["ollama-server:11434"]
    },
    {
      "action": "deny",
      "src": ["*"],
      "dst": ["ollama-server:*"]
    }
  ]
}

This rule allows your laptop device to access port 11434 on ollama-server, but blocks all other access to the server. Order matters: the first matching rule wins.

Use tags to group devices, like tag:server for all servers and tag:client for all clients. This makes ACLs cleaner when you have many devices. Learn more about network security at Netzwerksicherheit.

Example: Using Ollama from Anywhere

Here’s a complete walkthrough of setting up Ollama at home and accessing it remotely.

Step 1: Install Tailscale on your server

curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up

Sign in through your browser. Your server receives a Tailscale IP, for example 100.64.0.1.

Step 2: Configure OLLAMA_HOST

sudo systemctl edit ollama

Add:

[Service]
Environment="OLLAMA_HOST=0.0.0.0:11434"

Restart Ollama:

sudo systemctl restart ollama

Step 3: Update your firewall

sudo ufw allow in on tailscale0 to any port 11434

Step 4: Install Tailscale on your laptop

Install Tailscale on your laptop and sign in with the same account.

Step 5: Access from anywhere

At a coffee shop, connect to WiFi, start Tailscale on your laptop, and access Ollama:

curl http://100.64.0.1:11434/api/generate -d '{
  "model": "llama3",
  "prompt": "Hallo aus dem Café"
}'

The connection is encrypted over WireGuard. No ports are exposed to the internet, and attackers can’t connect.

Common Pitfalls

Ollama only listens on localhost. By default, Ollama binds to 127.0.0.1. Without setting OLLAMA_HOST=0.0.0.0:11434, it won’t be reachable over Tailscale. Check which address Ollama is listening on with ss -tlnp | grep 11434.

Firewall blocks the Tailscale interface. If you use UFW and just enter ufw allow 11434, you’re opening the port on all interfaces. Instead, use ufw allow in on tailscale0 to any port 11434 to expose it only on the Tailscale interface.

Devices don’t show as online. Sometimes it takes a moment for Tailscale to establish a connection. Check if the device is recognized with tailscale status. If it stays offline, restart the Tailscale service with sudo systemctl restart tailscaled.

MagicDNS isn’t working. MagicDNS must be enabled in the admin console. If you want to use device names like ollama-server, make sure MagicDNS is on and Tailscale’s DNS server is in use. On some systems, you’ll need to clear the DNS cache.

Subnet routes aren’t accepted. You must explicitly approve routes in the admin console. Also, other devices need to accept routes with --accept-routes. Without this step, the subnet remains unreachable.

Exit Node doesn’t forward traffic. If you’ve set up an Exit Node and your internet traffic isn’t going through the server, check that IP forwarding is enabled on the Exit Node. On Linux, set net.ipv4.ip_forward=1 in /etc/sysctl.conf.

ACL accidentally blocks connections. ACLs are restrictive once you define custom rules. If you make a deny rule too broad, you’ll block legitimate traffic. Test ACLs incrementally and use tailscale ping to diagnose connection issues.

Hardware, Costs, and Security

Hardware: Tailscale runs on almost any device. Your server doesn’t need anything special, and the client is lightweight. For AI services like Ollama, hardware requirements depend on the service itself, not Tailscale.

Costs: Tailscale has a free plan for personal use with up to 100 devices. Paid plans for teams and enterprises include advanced features like custom ACLs, audit logs, and SSO. Most self-hosting setups fit comfortably in the free tier.

Security: Tailscale uses WireGuard for encryption, which is considered very secure. Connections are end-to-end encrypted, so Tailscale itself can’t read your traffic. Authentication happens through your identity provider, like Google or GitHub. Enable two-factor authentication on your Tailscale account for extra security. Learn more about security at Sicherer Betrieb.

Further Reading

FAQ: Tailscale for AI Services

Is Tailscale free?

Yes, for personal use with up to 100 devices. Paid plans are available for teams and enterprises. Most self-hosting setups work fine with the free plan.

Do I need port forwarding for Tailscale?

No. Tailscale establishes connections directly between devices or uses relay servers when a direct connection isn’t possible. You don’t need to open ports on your router.

Can Tailscale read my traffic?

No. Connections are end-to-end encrypted with WireGuard. Tailscale only orchestrates the connection setup, while the actual traffic runs encrypted between your devices.

Can I use Ollama over Tailscale without changing OLLAMA_HOST?

No. By default, Ollama listens on 127.0.0.1 and is only accessible locally. You need to set OLLAMA_HOST=0.0.0.0:11434 so it listens on the Tailscale IP.

What’s the difference between a Subnet Router and an Exit Node?

A Subnet Router makes an entire local network accessible within your Tailnet. An Exit Node routes all your internet traffic through another Tailscale device, similar to a traditional VPN.

Does Tailscale work behind a restrictive firewall?

Yes. Tailscale uses multiple methods to establish connections, including relay servers over HTTPS. As long as your device can reach the internet, Tailscale typically works.

Can I have multiple users in a Tailnet?

Yes. On the free plan, you can invite multiple users. Each user manages their own devices. Use ACLs to control which users can access which services.

What happens if my server goes offline?

It’s no longer reachable over Tailscale. Tailscale only establishes connections to devices that are online. Once your server comes back up and Tailscale starts, it’s automatically accessible again.

Do I need MagicDNS?

No, it’s optional. Without MagicDNS, you use Tailscale IP addresses. With MagicDNS, you can use device names like ollama-server, which is more convenient.

Can I use Tailscale and a traditional VPN at the same time?

Yes. Tailscale runs alongside other VPNs since it uses its own network interface. Just watch out for routing conflicts if both VPNs use the same IP ranges.

Is Tailscale open source?

The client is open source, but the server component that handles coordination is proprietary. Headscale is an open-source server alternative you can self-host.

Sources

Back to Blog
Share:

Related Posts