Tailscale Subnet Router vs WireGuard Setup Guide

Updated 2026-10-09 • By Marcus Vance, CCNA (Senior Network Engineer)

To access your entire home or office LAN (including NAS units, NVR cameras, printers, and router GUIs) remotely without installing VPN clients on every device or opening WAN firewall ports, enable IP forwarding on one always-on LAN device, run tailscale up --advertise-routes=192.168.1.0/24, and approve the subnet in the Tailscale Admin Console. Unlike raw WireGuard, Tailscale traverses Starlink and 5G CGNAT automatically.

Key Technical Takeaways
  • One Subnet Router covers the whole LAN: A single Apple TV, Synology NAS, GL.iNet router, Raspberry Pi, or Proxmox LXC running Tailscale bridges your entire 192.168.1.0/24 network.
  • Works behind CGNAT with zero open ports: Tailscale uses STUN, UDP hole-punching, and encrypted DERP relays to punch through Starlink, T-Mobile 5G, and hotel firewalls.
  • Mandatory Linux sysctl step: Always enable net.ipv4.ip_forward = 1 and net.ipv6.conf.all.forwarding = 1 in /etc/sysctl.d/99-tailscale.conf.
  • Native WireGuard vs. Tailscale: Use native router WireGuard when you have a public WAN IP and want maximum multi-gig throughput with zero third-party coordination servers.

1. How a Tailscale Subnet Router Works (And Why It Beats CGNAT)

Standard mesh VPNs require installing a client app on every endpoint, which is impossible on network printers, PoE IP cameras, IoT bridges, and router web interfaces (like http://192.168.1.1). Conversely, running a traditional inbound WireGuard or OpenVPN server on your router requires a public WAN IPv4 address and an open UDP port—which fails completely on ISPs that use Carrier-Grade NAT (CGNAT, 100.64.0.0/10) such as Starlink, T-Mobile 5G Home Internet, and many regional fiber providers.

A Tailscale Subnet Router solves both problems at once. Built on the Linux WireGuard cryptographic protocol (ChaCha20-Poly1305), Tailscale separates the encrypted data plane (peer-to-peer between your devices) from the coordination plane. By running one always-on Tailscale node inside your LAN and advertising your local CIDR (e.g., 192.168.1.0/24), your laptop or phone on cellular/hotel WiFi can connect directly to 192.168.1.50 (your NAS) or 192.168.1.1 (your router) via NAT traversal (STUN/ICE) without opening a single inbound WAN port.

2. Step-by-Step: Configuring a Linux / Raspberry Pi / Proxmox Subnet Router

Before advertising routes on any Linux host (Ubuntu, Debian, Raspberry Pi OS, or an unprivileged Proxmox LXC with /dev/net/tun passed through), verify that your home LAN uses a less common subnet (such as 192.168.45.0/24 or 10.20.30.0/24) so it never collides when you connect from a coffee shop that also uses 192.168.1.0/24.

  1. Enable Kernel IPv4 and IPv6 Packet Forwarding: Run the following commands in your Linux terminal to persist IP forwarding across reboots:
    echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.d/99-tailscale.conf
    echo 'net.ipv6.conf.all.forwarding = 1' | sudo tee -a /etc/sysctl.d/99-tailscale.conf
    sudo sysctl -p /etc/sysctl.d/99-tailscale.conf
  2. Optimize UDP GRO Forwarding (Linux 6.2+): For 2.5x higher throughput, enable UDP Generic Receive Offload on your physical LAN NIC (replace eth0 with your interface name from ip route show 0/0):
    sudo ethtool -K eth0 rx-udp-gro-forwarding on rx-gro-list off
  3. Advertise Your Local Subnet (and Optional Exit Node): Replace 192.168.1.0/24 with your actual LAN CIDR and run:
    sudo tailscale up --advertise-routes=192.168.1.0/24 --advertise-exit-node

3. Approving Routes in Admin Console & Using Apple TV / Synology / GL.iNet

After running tailscale up --advertise-routes=..., the subnet remains inactive until an administrator explicitly approves it in the cloud control plane:

  • Open https://login.tailscale.com/admin/machines, click the ... menu next to your Subnet Router machine, and select Edit route settings.
  • Check the box next to your advertised CIDR (e.g., 192.168.1.0/24) and click Save.
  • Disable Key Expiry on the Subnet Router machine via the same ... menu so your unattended home node never drops offline after 180 days.

Prefer not to maintain a Linux server? You can run a zero-maintenance Tailscale Subnet Router on an Apple TV 4K (install the Tailscale tvOS app → Subnet Router → enter your CIDR), on a GL.iNet Router (Applications → Tailscale → Allow Remote Access LAN), on a pfSense / OPNsense firewall via the official Tailscale package, or on a Synology NAS.

4. Tailscale Subnet Router vs. Native WireGuard Server: Which Should You Choose?

While Tailscale uses the WireGuard cryptographic protocol under the hood, choosing between a Tailscale Subnet Router and a Native Kernel WireGuard Server (running directly on UniFi, ASUS, MikroTik, GL.iNet, or OPNsense) comes down to your ISP WAN architecture, NAT type, and raw throughput goals:

  • Choose a Tailscale Subnet Router when: Your ISP uses CGNAT (Starlink, T-Mobile 5G, or apartment fiber), you want SSO identity authentication and granular JSON ACL firewall rules, or you want automatic High Availability (HA) failover by running two Subnet Routers on the same LAN advertising the same /24 prefix.
  • Choose a Native WireGuard Server when: You have a public WAN IPv4 (or static IPv6) address, want zero reliance on any third-party coordination server, and need maximum multi-gigabit speed—because kernel-space WireGuard on routers runs 30–60% faster than userspace tailscaled on embedded ARM CPUs without any external DERP relay dependencies.

Tailscale Subnet Router vs. Native WireGuard vs. Cloudflare Tunnel

Feature / MetricTailscale Subnet RouterNative WireGuard ServerCloudflare Tunnel (cloudflared)
Works Behind ISP CGNAT?Yes (Automatic STUN UDP hole-punch + DERP)No (Requires Public WAN IPv4 or IPv6 + Port Forward)Yes (Outbound HTTPS/QUIC tunnel to Cloudflare)
Full LAN Subnet Access (IP/UDP/TCP)Yes (Access any 192.168.x.x IP, SMB, SSH, RTSP)Yes (Full Layer-3 routing to all LAN VLANs)Requires WARP client for private CIDR routing
Throughput on Embedded Router CPU250 to 650 Mbps (Userspace wireguard-go)500 to 1,800+ Mbps (Kernel-space WireGuard)200 to 500 Mbps (Proxied through edge PoP)
Third-Party Coordination DependencyTailscale Control Plane (or self-hosted Headscale)Zero (100% self-contained static public keys)Cloudflare Zero Trust Edge & Account
High Availability (HA Failover)Built-in (Advertise same CIDR from 2 LAN nodes)Manual (Requires VRRP/CARP + Dynamic DNS)Built-in (Run multiple cloudflared replicas)

Tailscale Subnet Router Deployment Checklist

  1. Changed home LAN subnet away from 192.168.0.0/24 or 192.168.1.0/24 (e.g., to 192.168.45.0/24) to prevent remote WiFi IP collisions.
  2. Enabled net.ipv4.ip_forward=1 and net.ipv6.conf.all.forwarding=1 in /etc/sysctl.d/99-tailscale.conf.
  3. Enabled rx-udp-gro-forwarding on the Linux host's physical Ethernet interface via ethtool -K.
  4. Ran sudo tailscale up --advertise-routes=/24 on the always-on wired host.
  5. Approved the advertised subnet route and disabled Key Expiry in the Tailscale Admin Console.
  6. Verified 'Accept Routes' is enabled on remote client devices (automatic on iOS/macOS/Windows; --accept-routes on Linux).

Frequently Asked Questions

Why can I ping the Tailscale Subnet Router's 100.x.y.z IP, but cannot reach other 192.168.x.x devices on my LAN?

This happens for one of three reasons: you have not yet approved the subnet under 'Edit route settings' in the Tailscale Admin Console, Linux IP forwarding (net.ipv4.ip_forward=1) is disabled on the subnet router host, or your remote client has not enabled 'Accept Routes' (run tailscale up --accept-routes on Linux clients).

What happens if my primary Tailscale Subnet Router reboots or loses power?

Tailscale includes automatic Subnet Router High Availability (HA) failover out of the box. Simply configure a second device on the same LAN (for example, both a Synology NAS and an Apple TV 4K) to advertise the exact same 192.168.x.0/24 route; if the primary node goes offline, Tailscale seamlessly switches traffic to the backup node within seconds.

What is the difference between a Tailscale Subnet Router and a Tailscale Exit Node?

A Subnet Router (using --advertise-routes=192.168.1.0/24) uses split-tunnel routing so only traffic destined for your private home LAN goes through the VPN, while regular internet traffic goes out your local connection. An Exit Node (--advertise-exit-node) routes 100% of your internet traffic (0.0.0.0/0) through your home ISP connection.

Why do LAN devices see the Subnet Router's IP instead of my remote laptop's Tailscale IP?

By default, a Tailscale Subnet Router performs Source NAT (SNAT / Masquerading) on packets entering your LAN so your printers, cameras, and NAS know how to send reply packets back without needing custom static routes on your main router. If you add a static route for 100.64.0.0/10 pointing to your Subnet Router on your main gateway, you can disable SNAT with --snat-subnet-routes=false.

Reviewed by Marcus Vance, CCNA (Senior Network Engineer)

Part of the Packetsaver Network Engineering Team. All configurations and firmware safety instructions follow vendor-verified RFC and IEEE standards. Read our testing methodology →