ACL Configuration
Configure access control lists (ACLs) to manage device permissions.
Access Control Policies
Enforce access for users, devices, and applications in the tailnet.
Admin console session timeout
Set idle session timeout for the Tailscale admin console.
AI infrastructure access
Secure access to AI infrastructure, GPU clusters, and private LLM deployments.
API Automation
Automate and manage various aspects of the tailnet via the Tailscale API.
Application testing
Share local development servers, test webhooks, and simulate geo-specific traffic.
Tailscale CLI
Manage and troubleshoot devices within the tailnet.
Contact preferences
Set contacts for account changes, configuration issues, security issues, and billing.
Coordination Server
Central server that coordinates device connections.
Delete and suspend users
Delete or suspend users from your tailnet.
DERP relay
Designated Encrypted Relay for Packets for secure, low-latency connections.
Device Approval
Review and approve devices before they are allowed access.
Device Posture
Domain ownership
Explore how your tailnet is tied to your domain.
Ephemeral Authenticated Connections
Secure, temporary connections for CI/CD workflows.
Fast user switching
Switch between two or more logged-in accounts on the same device without re-authentication.
Grants
Grant access control permissions across network connections and application permissions.
Infrastructure access
Manage secure, audited access to production servers, Kubernetes clusters, and cloud environments.
Invite users
Invite users to join your tailnet through various methods.
IP address assignment
Stable IP addresses based on device and authorization credentials.
Manage billing
Change billing information related to your Tailscale account.
Manage plan
Change your Tailscale plan by upgrading or downgrading to a different plan.
Node keys
Mechanism for machine authentication to join a tailnet.
Personal or at-home use
Connect and manage home network devices and services from anywhere.
Accessing a regulated environment
Meet compliance requirements with static egress IPs, device posture checks, and auditable access controls.
Site-to-site VPN
Replace traditional site-to-site VPNs with Tailscale and WireGuard.
STUN
Protocol for NAT traversal.
Tailnet
A private network of devices that can communicate securely.
Tailnet names and types
Understand tailnet name types: Tailnet DNS, machine, Tailnet ID, and Legacy ID.
Tailnet Policy File
Reference syntax for the tailnet policy file.
User approval
Review and approve new users before they can join your Tailscale network.
User Invitation
Invite users to your tailnet and assign roles.
User roles
Use roles to restrict access to the admin console.
VPN replacement
Replace legacy corporate VPNs with faster, more secure remote access.