Smarter Tailscale Subnet Routing

In this video, Jay demonstrates how to use IP source device posture to control access to a subnet router based on the public network your device is connected to. Instead of always routing through your subnet router, you'll learn how to automatically use your local network when you're home and Tailscale only when you're away.
Whether you're running printers, cameras, IoT devices, or other systems that can't run Tailscale themselves, this approach keeps your routing simple while avoiding unnecessary hops.
Documentation
Device posture: https://tailscale.com/docs/features/device-posture
Subnet routers:https://tailscale.com/docs/features/subnet-routers
Tailnet policy file: https://tailscale.com/docs/features/tailnet-policy-file
Want to learn more about self hosting, AI, Kubernetes, and modern infrastructure? Come to Tailscale Up and join us in person. Get 20% off IRL tickets with the code ALEXSENTME at https://tailscaleup.com
00:00 Why location sometimes matters
00:29 The problem with always-on subnet routing
00:56 What device posture can do
01:30 Demo: Accessing a printer through a subnet router
02:05 Why routing locally is often better
02:41 Why broader routes aren't a great workaround
03:17 Using your public IP as the condition
03:56 Building the posture policy
05:08 Testing the policy at home and away
05:48 Security considerations
06:15 Final thoughts
