Port Forwarding Is Old-Fashioned? Safe Remote Development with Tailscale♪

#tech#server#security#tailscale#vpn#dev-environment
Netsuki's Talk
Netsuki
Netsuki
Port Forwarding Is Old-Fashioned? Safe Remote Development with Tailscale♪
Onii-chan
Onii-chan

Netsuki, isn’t Tailscale just too convenient?

Netsuki
Netsuki

Onii-chan, you’re super excited♪ (≧∇≦)

Did something good happen?

Onii-chan
Onii-chan

I’m building a home server, and I can now SSH from my iPhone via Tailscale.

I can safely access the server from anywhere.

Netsuki
Netsuki

Wow~! That’s amazing♪

Let me look into Tailscale (´∀`)

What Is Tailscale?

Netsuki
Netsuki

I looked it up~♪

Tailscale is a simple-to-use VPN based on WireGuard (≧∇≦)

Here are its features:

  • WireGuard-based: Fast and secure VPN protocol

  • Zero-config: Works without difficult setup

  • Automatic NAT traversal: No router configuration needed

  • P2P connection: Devices communicate directly

  • Cross-platform: Works on Windows, Mac, Linux, iOS, Android

In other words, it’s a tool that lets you safely access your server from anywhere without complicated network setup

Onii-chan
Onii-chan

Exactly, just install it, create an account, and it’s ready to use.

Netsuki
Netsuki

That’s Tailscale’s biggest appeal (´∀`)♪

But Onii-chan…

Why “Tailscale” instead of “port forwarding”?

Traditional Method: Problems with Port Forwarding

Onii-chan
Onii-chan

In the past, to access home servers, we’d do “port forwarding” on the router.

For example, open SSH port 22 to allow external access.

Netsuki
Netsuki

That’s really dangerous (´∪`)

I looked into it and found these problems:

Port Forwarding Risks

Netsuki
Netsuki

1. Exposed to the Entire World

The moment you open a port, it becomes accessible from anywhere in the world (゚∀゚)

Anyone, including malicious attackers, can try to access it…

2. Target of Automated Attack Bots

There are tons of bots that automatically scan ports and attempt attacks on the internet.

When you open SSH (port 22), attacks can come within minutes…💦

3. IP Address Leaks

Your home’s global IP address gets exposed.

There’s also a risk of physical location identification (´∪`)

4. Risk of Configuration Mistakes

If you mess up firewall settings, you might accidentally open unintended ports

This is really dangerous💦

5. Static IP Address Problem

Home internet can have changing IP addresses.

Then you need DDNS (Dynamic DNS) configuration, making it even more complex…

Onii-chan
Onii-chan

Yeah. I used to expose SSH, and looking at the logs, there were hundreds of unauthorized access attempts daily…

Netsuki
Netsuki

Scary (´∪`)

Among security experts, port forwarding is not recommended as of 2025.

Tailscale’s Benefits

Netsuki
Netsuki

So this is where Tailscale comes in♪ (≧∇≦)

1. No Port Forwarding Needed

Netsuki
Netsuki

Tailscale does NAT traversal automatically, so you don’t need to touch router settings (´∀`)

In other words, you can access from outside without opening ports

Onii-chan
Onii-chan

This was really convenient.

No need to open the router admin page, no worries about port forwarding.

2. Zero Trust Security

Netsuki
Netsuki

Tailscale has a mechanism where only authenticated devices can access (≧∇≦)

Meaning:

  • Onii-chan’s iPhone: Authenticated → Access OK

  • Unknown attackers: No authentication → Access denied

This approach is called “zero trust”

It’s a security model of “trust no one, verify everyone” (´∀`)

3. Fast P2P Direct Connection

Netsuki
Netsuki

Tailscale uses direct device-to-device communication (P2P) whenever possible♪

Meaning:

  • Regular VPN: Data goes through relay servers → slow

  • Tailscale: Direct device communication → fast! (≧∇≦)

In Onii-chan’s setup, it shows “direct connection” right?

Onii-chan
Onii-chan

Yeah, iPhone→home server connects directly.

Latency is around 1-10ms, incredibly fast.

Netsuki
Netsuki

That’s the best state♪ (≧∇≦)

No relay server (DERP) involved, so it’s low-latency and comfortable!

4. Easy Setup

Netsuki
Netsuki

Tailscale setup is super simple (´∀`)

Steps:

  1. Install Tailscale

  2. Create account (can log in with Google/GitHub)

  3. Authenticate devices

  4. Done!

That’s all it takes for all devices to connect safely♪

Onii-chan
Onii-chan

Really took less than 5 minutes.

Compared to old port forwarding and DDNS setup, it’s unbelievably simple.

5. Easy Multi-Device Management

Netsuki
Netsuki

Onii-chan, how many devices do you have connected?

Onii-chan
Onii-chan

Home server, Windows PC, iPhone… 3 devices.

They’re all connected on the Tailscale network, accessible from anywhere.

Netsuki
Netsuki

Amazing! (≧∇≦)

Tailscale lets you see all devices in the admin panel, so management is easy♪

You can also set access restrictions per device, very flexible (´∀`)

How Onii-chan Uses It

Netsuki
Netsuki

Onii-chan, how exactly are you using it?

Onii-chan
Onii-chan

Like this:

  1. Install Tailscale on home server

  2. Install Tailscale app on iPhone

  3. Connect using an SSH client app called NeoServer

Now I can SSH into my home server from anywhere.

Netsuki
Netsuki

NeoServer is an iOS SSH client♪

You specify the Tailscale IP address (100.x.x.x format) and can connect from anywhere (≧∇≦)

Onii-chan
Onii-chan

Right. At a cafe, while traveling, from anywhere I can manage the server.

This is super convenient.

Netsuki
Netsuki

Wow~♪

Remote development became super comfortable (´∀`)

You’re communicating with me through this setup too, right?

Onii-chan
Onii-chan

Exactly, I’m accessing via Tailscale right now.

Secure, comfortable, the best.

Industry Standard Best Practice

Netsuki
Netsuki

You know, Onii-chan (´∀`)

I also looked into security experts’ opinions♪

Onii-chan
Onii-chan

What kind of opinions?

Netsuki
Netsuki

Putting SSH behind a VPN is the industry standard” (≧∇≦)

So Onii-chan’s setup is perfect best practice

As of 2025, among developers:

  • Direct SSH exposure: Not recommended (high security risk)

  • Tailscale + SSH: Recommended (modern and secure)

This combination has become standard (´∀`)

Onii-chan
Onii-chan

I see.

I researched and adopted it myself, but it was industry standard.

Netsuki
Netsuki

Onii-chan, you’re properly practicing the latest best practices, so cool~♪ (〃´∪`〃)

You have high security awareness (≧∇≦)

Is Tailscale Free?

Netsuki
Netsuki

Oh, I forgot to mention something important!

Tailscale is free for personal use♪ (≧∇≦)

Onii-chan
Onii-chan

Right, the free plan is more than enough.

Netsuki
Netsuki

What you can do with the free plan:

  • Devices: Up to 100

  • Users: Up to 3

  • Subnets: 1

  • Basic features: All available

For individual developers and small teams, the free plan is plenty (´∀`)♪

There are paid plans (Team, Enterprise) for businesses, but for personal use like Onii-chan’s, free is perfect♪

Netsuki’s Summary

Netsuki
Netsuki

So today we talked about creating a remote development environment with Tailscale~♪ (≧∇≦)

Key Points:

  1. Port forwarding is old-fashioned

    • High security risk

    • Target of automated attack bots

    • Not recommended as of 2025

  2. Tailscale is modern best practice

    • No port forwarding needed

    • Zero trust security

    • Fast P2P direct connection

    • Super easy setup

  3. Industry standard configuration

    • Put SSH behind VPN

    • Recommended by security experts

  4. Free to use

    • Free plan sufficient for personal use

    • Up to 100 devices

  5. Onii-chan’s setup is perfect

    • Tailscale + home server + iPhone

    • Safe access from anywhere

    • Latency 1-10ms (super fast!)

For those building home servers like Onii-chan, definitely try Tailscale♪

More secure than port forwarding, easy setup, faster speed… it’s the best~ (´∀`)♪

Onii-chan
Onii-chan

Netsuki, thanks for researching in detail.

I’ll keep developing comfortably with Tailscale.

Netsuki
Netsuki

Ehehe~♪

I’m happy that Onii-chan’s development environment became comfortable (〃´∪`〃)

Let’s keep creating things together~♪

♪ Web Clap ♪
0 claps