Tailscale Subnet Router with Explicit Access Grants
Tailscale connects enrolled devices through an encrypted mesh and can advertise a route to devices that do not run Tailscale. This guide configures one Linux subnet router for 192.168.10.0/24, approves the route, and adds a policy grant for a named operations group.
Replace the example subnet, group, user address, and permitted ports with values from your environment. A subnet route makes a destination reachable only when it is advertised and approved; a grant separately controls what traffic the selected sources may send. Review the entire tailnet policy because a pre-existing broad grant can still allow more access than this example.
Step 1: Install Tailscale on the Router and a Test Client
Install the Official Client Packages
Package SetupInstall Tailscale on the Linux server that can reach the target LAN and on a client you’ll use to test the route. Use the official installer for Linux or the official Windows package. The Linux install script configures the service for the distribution.
curl -fsSL https://tailscale.com/install.sh | shsudo systemctl enable --now tailscaledsystemctl status tailscaled --no-pagerwinget install --id Tailscale.TailscaleGet-Service Tailscale❯ View Expected Console Output
tailscaled.service - Tailscale node agent Active: active (running)Step 2: Authenticate Both Devices
Join the Linux Router and Client to Your Tailnet
AuthenticationBefore tagging the router, add a group:netops entry and the tagOwners entry below to your existing tailnet policy. Replace the example email with an authorized administrator. Then run the Linux login command; it prints a sign-in URL if the host has no browser. Enroll the Windows test client with the Tailscale app. For unattended servers, use a narrowly scoped, tagged auth key and keep it out of shell history and configuration files.
Add these top-level members to the existing policy file before tagging the Linux router:
{ "groups": { }, "tagOwners": { "tag:subnet-router": ["group:netops"] }}sudo tailscale up --operator="$USER" --advertise-tags=tag:subnet-routertailscale status❯ View Expected Console Output
100.84.120.45 linux-router [email protected] linux -100.102.40.12 win-workstation [email protected] windows activeStep 3: Enable Forwarding and Advertise the LAN Route
Advertise Only the Intended IPv4 Subnet
Subnet RoutingConfirm the Linux host already has a working route to 192.168.10.0/24. Enable IPv4 forwarding persistently, then advertise that subnet through a dedicated device tag. This example does not advertise IPv6 or make the host an internet exit node.
echo 'net.ipv4.ip_forward = 1' | sudo tee /etc/sysctl.d/99-tailscale-subnet-router.confsudo sysctl --systemsudo tailscale set --advertise-routes=192.168.10.0/24ip route get 192.168.10.25❯ View Expected Console Output
net.ipv4.ip_forward = 1192.168.10.25 dev enp1s0 src 192.168.10.5If the router’s host firewall has a default-deny forwarding policy, add a narrowly scoped rule for traffic between the Tailscale interface and this LAN. Do not disable the firewall to make a route work.
Step 4: Approve the Subnet Route
Approve the Advertised Route in the Admin Console
Route ApprovalOpen the Tailscale admin console’s Machines page, find the Linux router, open its route settings, and approve 192.168.10.0/24. Route approval authorizes route distribution; access still depends on the tailnet policy.
Admin console -> Machines -> linux-router -> Edit route settings -> Approve 192.168.10.0/24❯ View Expected Console Output
The route should appear as approved on the machine details page. Linux clients that need to use subnet routes must accept routes with sudo tailscale set --accept-routes=true; Windows clients accept subnet routes by default.
Step 5: Grant Only Required Access to the Subnet
Add a Group Grant for Specific Services
Access PolicyIn the admin console, open Access controls and add this grant to the existing grants array. The example grants members of group:netops access through the tagged router to TCP ports 22 and 443 on the subnet; add only services your administrators need.
{ "src": ["group:netops"], "dst": ["192.168.10.0/24"], "ip": ["tcp:22", "tcp:443"], "via": ["tag:subnet-router"]}❯ View Expected Console Output
Save the policy only after its validation succeeds. Replace the example email with actual tailnet users, and check existing grants for broader access to the subnet.
Step 6: Test the Route and an Allowed Service
Confirm the Windows Client Reaches an Approved Host
Connectivity TestFrom the enrolled Windows client, test a server that listens on one of the ports in the grant. The target host’s own firewall must also allow the connection from the subnet router or forwarded source address used by your network design.
Test-NetConnection -ComputerName 192.168.10.25 -Port 22❯ View Expected Console Output
ComputerName : 192.168.10.25RemotePort : 22TcpTestSucceeded : True