
How to Use Tailscale With Starlink for Safe Remote Access
Tips & Tricks
Starlink can be a good connection for a home server, NAS, desktop or camera system, but traditional port forwarding is often the wrong place to start. Starlink customers may be behind carrier-grade NAT (CGNAT), and exposing services directly to the public internet creates extra security work.
Tailscale gives you a private, encrypted path between approved devices. The simplest setup installs Tailscale on both the device you are using remotely and the device you want to reach at home. You do not need to open an inbound port on the Starlink router for that basic setup.
What this setup is good for
Use Tailscale when you want to:
- Reach a home PC, NAS, server or self-hosted dashboard while away.
- Connect to a device using a private Tailscale IP address or MagicDNS name.
- Avoid forwarding RDP, SSH, camera or admin ports from the Starlink router.
- Keep remote access available even when your Starlink WAN address changes.
Tailscale is a network path, not an application login. You still need a strong password, passkey or other authentication on the service you are accessing.
Before you start
You need:
- A Tailscale account and a tailnet that you control.
- Tailscale installed on the remote device, such as a phone or laptop.
- Tailscale installed on the home device you want to reach.
- The home device powered on and connected to Starlink.
- A remote-access service already working on the home device, such as file sharing, SSH, remote desktop or a NAS web interface.
For a first test, choose a computer or server that can run the Tailscale client directly. This is simpler and easier to secure than starting with a whole-LAN subnet route.
Set up direct device-to-device access
1. Install and sign in
Install Tailscale from the official download page on the home device and the remote device. Sign in to both with accounts that belong to the same tailnet.
Open the Tailscale admin console and confirm that both devices appear. Give the home device a clear name, such as home-nas or office-pc, so you can recognise it later.
2. Confirm the service works locally
From a device on your home Wi-Fi, connect to the service using its normal local address. For example, test the NAS, SSH server or remote-desktop service before troubleshooting Tailscale.
If the service does not work locally, Tailscale will not fix it. Check that the service is running, the local firewall allows it, and you are using the correct port.
3. Connect through the Tailscale address
On the remote device, open the Tailscale client and find the home device. Use its Tailscale IP address or MagicDNS name in the client you are using.
Examples:
- Remote desktop: connect to the home computer's Tailscale name.
- SSH: connect to the home server's Tailscale address.
- NAS or dashboard: open the service port on the home device's Tailscale address.
Do not substitute your Starlink WAN address for the Tailscale address. The point of this setup is to reach the approved device over the private tailnet path.
4. Test from a genuinely remote network
Turn off Wi-Fi on your phone or laptop and use mobile data, or test from another trusted network. Confirm that:
- The home device is still awake.
- Tailscale shows both devices as connected.
- The service opens using the Tailscale name or address.
- The service's own login is still required.
A successful test from the same home Wi-Fi only proves that the local network works. It does not prove remote access works.
Reaching devices that cannot run Tailscale
Some printers, cameras, smart-home devices and older NAS systems cannot run the Tailscale client. In that case, use an always-on computer or server on the Starlink LAN as a subnet router.
The pattern is:
- Install Tailscale on the always-on device.
- Find the LAN subnet used by your home router, such as
192.168.1.0/24. Use the actual subnet shown by your router, not this example. - Enable IP forwarding on the subnet-router device.
- Advertise only the LAN subnet in Tailscale.
- Approve the advertised route in the Tailscale admin console.
- Enable subnet routes on the remote Tailscale client.
- Test the specific local device by its LAN address.
Start with one narrow subnet route. Do not advertise 0.0.0.0/0 unless you intentionally want to build an exit-node setup that sends general internet traffic through home. A subnet router is for reaching selected home devices; an exit node is for routing a client's wider internet traffic through the home connection.
If the home LAN and the network you are visiting use the same address range, routing can fail or reach the wrong device. Changing the home LAN range is a router-level change, so test the direct client setup first and only change it when you understand the impact.
Keep the setup secure
- Do not forward RDP, SSH, NAS or camera ports to the public internet just to make Tailscale work.
- Keep the service's own login and software updates enabled.
- Add only devices and people you trust to the tailnet.
- Use Tailscale access controls when more than one person or device needs access.
- Install Tailscale directly on a device when possible; use a subnet router only for devices that need it.
- Treat an exit node as an advanced option. It changes where a client's general internet traffic exits and is broader than ordinary remote access.
- Remove old or lost devices from the tailnet promptly.
Tailscale can provide the private path, but it does not remove the need to secure the NAS, server, camera recorder or admin panel itself.
Troubleshooting when it connects slowly or not at all
The home device is missing: Check that it is powered on, signed in to the expected tailnet and not paused or expired in the admin console.
The Tailscale device is online but the service is unreachable: Test the service locally, then check its local firewall and listening address. Some services listen only on one interface and may need to be configured to accept connections on the Tailscale interface.
It works at home but not on mobile data: Repeat the test from mobile data and check the Tailscale connection details. Tailscale may use a relay when a direct peer-to-peer path is not possible. Relayed connections are still encrypted, but can be slower.
A subnet-routed device is unreachable: Confirm that the advertised route is approved, the remote client accepts subnet routes, IP forwarding is enabled, and the subnet-router device remains online. Check for overlapping LAN ranges on the two networks.
Remote desktop or a NAS is slow: First compare a direct Tailscale connection with the same service over local Wi-Fi. If Tailscale is using a relay, improve the home device's wired connection and check the remote network's firewall or NAT conditions. Do not open random inbound ports as a first response.
The practical recommendation
For most Starlink homes, start with Tailscale installed directly on the home computer, NAS or server and on the phone or laptop you will use remotely. Verify the service locally, test over mobile data, and keep the device's normal authentication in place.
Add a subnet router only when a device cannot run Tailscale. Keep the advertised route narrow, approve it deliberately, and document which home devices it exposes.
Official references
- Tailscale device connectivity
- Tailscale subnet routers
- Using Tailscale with your firewall
- Tailscale downloads
Image credit: Vitaly Gariev on Pexels.