Mesh VPN: connecting your devices with Headscale and Tailscale
Quick answer
The mesh VPN lets your laptops, devices and internal VPS instances reach each other directly, without exposing anything to the public internet. It runs on Headscale as the control server and Tailscale as the client, and you set it up from VPN in Portal.
What it's for
Normally, reaching a VPS instance means giving it a public IP or building a separate VPN gateway yourself. The mesh VPN skips that: once a device or your cloud firewall joins the mesh, it can reach other mesh members and, through Link Firewall, your internal subnets too, all without a public IP on the instance itself.
How it's built
Headscale is the control server. It coordinates the mesh: which devices belong to it, what they're allowed to reach, and how they find each other. You can use a control server that Portal manages for you, or connect to your own.
Tailscale is the client. You install it on laptops and other devices, and it also runs on your cloud firewall, where it joins the mesh as a subnet router rather than a single device.
Every client connects to the control server at its HTTPS Server URL. That's true whether the control server is portal-managed or self-hosted.
Setting up a mesh VPN
Create or connect a control server
In VPN, choose Create managed VPN server to have Portal run Headscale for you, or Connect to existing server if you already run your own.
Find your way around
A managed server gives you tabs for Overview, Nodes, Auth Keys, Networks, Setup, and Settings.
Create an auth key
Open Auth Keys and create a new key. You'll use it to authorise the next device that joins the mesh.
Install Tailscale on your device
Follow the OS-specific instructions under Setup, using the auth key from the previous step.
Link your firewall (optional)
Link Firewall installs Tailscale on your cloud firewall's gateway and advertises the internal subnets you select through it, so mesh clients can reach your internal VPS instances without those instances needing a public IP.
VPN
Choose how you want to set up your mesh.
We provision a Headscale server for you. Manage nodes, keys, and setup from this panel.
Already have Headscale or Tailscale? Connect your firewall to your existing VPN and add your cloud subnets to the mesh.
Managed VPN server
Overview Nodes Auth Keys Networks Setup Settings