Skip to content

Tailscale Subnet Router with Explicit Access Grants

Tailscale connects enrolled devices through an encrypted mesh and can advertise a route to devices that do not run Tailscale. This guide configures one Linux subnet router for 192.168.10.0/24, approves the route, and adds a policy grant for a named operations group.

Replace the example subnet, group, user address, and permitted ports with values from your environment. A subnet route makes a destination reachable only when it is advertised and approved; a grant separately controls what traffic the selected sources may send. Review the entire tailnet policy because a pre-existing broad grant can still allow more access than this example.


Step 1: Install Tailscale on the Router and a Test Client

01

Install the Official Client Packages

Package Setup

Install Tailscale on the Linux server that can reach the target LAN and on a client you’ll use to test the route. Use the official installer for Linux or the official Windows package. The Linux install script configures the service for the distribution.

Terminal window
curl -fsSL https://tailscale.com/install.sh | sh
sudo systemctl enable --now tailscaled
systemctl status tailscaled --no-pager
❯ View Expected Console Output
tailscaled.service - Tailscale node agent
Active: active (running)

Step 2: Authenticate Both Devices

02

Join the Linux Router and Client to Your Tailnet

Authentication

Before tagging the router, add a group:netops entry and the tagOwners entry below to your existing tailnet policy. Replace the example email with an authorized administrator. Then run the Linux login command; it prints a sign-in URL if the host has no browser. Enroll the Windows test client with the Tailscale app. For unattended servers, use a narrowly scoped, tagged auth key and keep it out of shell history and configuration files.

Add these top-level members to the existing policy file before tagging the Linux router:

{
"groups": {
"group:netops": ["[email protected]"]
},
"tagOwners": {
"tag:subnet-router": ["group:netops"]
}
}
Terminal window
sudo tailscale up --operator="$USER" --advertise-tags=tag:subnet-router
tailscale status
❯ View Expected Console Output
100.84.120.45 linux-router [email protected] linux -
100.102.40.12 win-workstation [email protected] windows active

Step 3: Enable Forwarding and Advertise the LAN Route

03

Advertise Only the Intended IPv4 Subnet

Subnet Routing

Confirm the Linux host already has a working route to 192.168.10.0/24. Enable IPv4 forwarding persistently, then advertise that subnet through a dedicated device tag. This example does not advertise IPv6 or make the host an internet exit node.

Terminal window
echo 'net.ipv4.ip_forward = 1' | sudo tee /etc/sysctl.d/99-tailscale-subnet-router.conf
sudo sysctl --system
sudo tailscale set --advertise-routes=192.168.10.0/24
ip route get 192.168.10.25
❯ View Expected Console Output
net.ipv4.ip_forward = 1
192.168.10.25 dev enp1s0 src 192.168.10.5

If the router’s host firewall has a default-deny forwarding policy, add a narrowly scoped rule for traffic between the Tailscale interface and this LAN. Do not disable the firewall to make a route work.


Step 4: Approve the Subnet Route

04

Approve the Advertised Route in the Admin Console

Route Approval

Open the Tailscale admin console’s Machines page, find the Linux router, open its route settings, and approve 192.168.10.0/24. Route approval authorizes route distribution; access still depends on the tailnet policy.

Admin console
-> Machines
-> linux-router
-> Edit route settings
-> Approve 192.168.10.0/24
❯ View Expected Console Output

The route should appear as approved on the machine details page. Linux clients that need to use subnet routes must accept routes with sudo tailscale set --accept-routes=true; Windows clients accept subnet routes by default.


Step 5: Grant Only Required Access to the Subnet

05

Add a Group Grant for Specific Services

Access Policy

In the admin console, open Access controls and add this grant to the existing grants array. The example grants members of group:netops access through the tagged router to TCP ports 22 and 443 on the subnet; add only services your administrators need.

{
"src": ["group:netops"],
"dst": ["192.168.10.0/24"],
"ip": ["tcp:22", "tcp:443"],
"via": ["tag:subnet-router"]
}
❯ View Expected Console Output

Save the policy only after its validation succeeds. Replace the example email with actual tailnet users, and check existing grants for broader access to the subnet.


Step 6: Test the Route and an Allowed Service

06

Confirm the Windows Client Reaches an Approved Host

Connectivity Test

From the enrolled Windows client, test a server that listens on one of the ports in the grant. The target host’s own firewall must also allow the connection from the subnet router or forwarded source address used by your network design.

Terminal window
Test-NetConnection -ComputerName 192.168.10.25 -Port 22
❯ View Expected Console Output
ComputerName : 192.168.10.25
RemotePort : 22
TcpTestSucceeded : True

References

Comments