Normal view

Smarter Tailscale Subnet Routing

💾

One of the biggest advantages of Tailscale is that your devices stay connected no matter where you are. But sometimes your location should change how your network behaves.
In this video, Jay demonstrates how to use IP source device posture to control access to a subnet router based on the public network your device is connected to. Instead of always routing through your subnet router, you'll learn how to automatically use your local network when you're home and Tailscale only when you're away.

Whether you're running printers, cameras, IoT devices, or other systems that can't run Tailscale themselves, this approach keeps your routing simple while avoiding unnecessary hops.
Documentation

Device posture: https://tailscale.com/docs/features/device-posture
Subnet routers:https://tailscale.com/docs/features/subnet-routers
Tailnet policy file: https://tailscale.com/docs/features/tailnet-policy-file

Want to learn more about self hosting, AI, Kubernetes, and modern infrastructure? Come to Tailscale Up and join us in person. Get 20% off IRL tickets with the code ALEXSENTME at https://tailscaleup.com

00:00 Why location sometimes matters
00:29 The problem with always-on subnet routing
00:56 What device posture can do
01:30 Demo: Accessing a printer through a subnet router
02:05 Why routing locally is often better
02:41 Why broader routes aren't a great workaround
03:17 Using your public IP as the condition
03:56 Building the posture policy
05:08 Testing the policy at home and away
05:48 Security considerations
06:15 Final thoughts
❌