🚀 合作咨询: fahim@fahimai.com | 深受17种语言、每月超过25万读者的信赖 🔥

🚀 合作咨询: fahim@fahimai.com

如何使用 Tailscale VPN:2026 年设置和使用教程

| Last updated Aug 14, 2026

快速入门

本指南涵盖了Tailscale的所有功能:

所需时间: 每部影片 5 分钟

本指南还包含以下内容: 专业提示 | 常见错误 | 故障排除 | 定价 | 替代方案

为什么信任本指南

I have run Tailscale for two years across a Linux machine, a Raspberry Pi, my phone and two cloud servers.

Every step here comes from my own tailnet, not from vendor screenshots.

How to use Tailscale

Tailscale is a mesh VPN built on the WireGuard protocol.

It creates a decentralised network called a tailnet, where 设备 connect directly to each other.

Most people install it, log in once, then never touch the settings again.

That is a shame, because the good features sit one layer down.

尾尺度教程

This How to Use Tailscale VPN tutorial on how to use Tailscale walks through every feature, from the first install to zero trust access rules.

尾鳞

Connect every device you own into one private network in about five minutes. No ports to open, no server to rent, no config files to edit. Free forever for personal use.

Tailscale入门指南

Do this once and every feature below becomes available.

It takes about three minutes on any platform.

Watch the full walkthrough first:

如何在 10 分钟内开始使用 Tailscale

现在让我们逐一分析每个步骤。

第一步:创建您的帐户

Go to the Tailscale website and click Get Started.

Sign in with Google, Microsoft, GitHub or Apple instead of making a new password.

检查点: The admin console loads with an empty Machines list.

Step 2: Install the Client

Download the app for Windows, macOS, iOS or Android from the site or your app store.

On a Linux machine, run the one-line install script, then 尾部向上.

Apple devices ask for a VPN profile permission on first launch.

Here’s what you get once the client is running:

尾端顶级福利

检查点: Your computer appears in the Machines list with a 100.x.x.x address.

Step 3: Add More Devices

Repeat the install on your phone, your server and any other devices you own.

Once installed, each client finds the others on its own, with nothing to configure.

Every device signed into the same account joins the same tailnet automatically.

Here is how that looked on my own setup:

无题设计 5 19

✅ 完成: Your tailnet devices can now reach each other by name from anywhere.

如何使用 Tailscale Business VPN

商业 VPN lets you swap your old corporate VPN for a mesh network that every employee joins in minutes.

以下是使用步骤。

Step 1: Invite Your Users

Open the admin console and send invites by email.

Everyone who signs in with the same domain lands on the same tailnet.

Step 2: Approve Tailnet Devices

Each laptop, phone and server appears in the Machines list after the client installs.

这就是它的样子:

使用 Tailscale 设置您自己的 VPN,保护您的互联网安全!

检查点: Every invited computer shows a 100.x.x.x IP address in the admin console.

Step 3: Set Your Access Policy

Edit the ACL file so each team only reaches the servers it owns.

✅ 结果: Your team has a private network with no gateway hardware to configure.

💡 专业提示: Tailscale uses single-sign-on to authenticate users, so revoking someone in Google Workspace cuts their access 即刻.

How to Use Tailscale Remote Access

安全的 远程访问 lets you reach a work machine from any computer in the world without exposing it to the internet.

以下是使用步骤。

Step 1: Install the Client on Both Ends

Install Tailscale on the office machine and on your laptop.

On Linux the one-line install script does everything.

Step 2: Check Tailscale Status

跑步 尾规模地位 to confirm both devices are connected.

这就是它的样子:

无题设计 53

检查点: The remote host appears as online with a direct peer connection.

Step 3: Connect by Hostname

SSH or 浏览 to the device using its MagicDNS name instead of an IP.

✅ 结果: You can access work files from home without a port forward or public IP.

💡 专业提示: 使用 tailscale ssh and Tailscale handles the keys for you, so there is no key file to copy around.

如何使用 Tailscale 站点到站点网络

站点间联网 lets you join two whole networks together instead of installing the app on every machine.

以下是使用步骤。

Step 1: Pick a Gateway Device

Choose one always-on Linux machine at each site.

Step 2: Advertise the Subnet

Run the advertise-routes command with your local range, such as 192.168.1.0/24.

这就是它的样子:

无题设计 1 45

检查点: Printers and NAS boxes at the far site answer pings from your laptop.

Step 3: Approve the Route

Approve both subnet routers in the admin console under Machines.

✅ 结果: Two home or office networks now talk as if they sat in one building.

💡 专业提示: Enable IP forwarding on the router first, or packets reach the gateway and stop there.

如何使用 Tailscale 多云网络

多云网络 lets you put AWS, GCP and bare-metal servers on the same private network with no peering setup.

以下是使用步骤。

Step 1: Install on Each Server

Add the client to every cloud instance with the one-line script.

Step 2: Use an Auth Key

Generate a reusable auth key so new servers join without a browser login.

这就是它的样子:

无题设计 2 44

检查点: All cloud hosts appear in one list with 100.x.x.x IP addresses.

Step 3: Tag Your Machines

Apply tags like tag:prod so access rules follow the role, not the person.

✅ 结果: Your servers communicate across providers without VPC peering or public endpoints.

💡 专业提示: Bake the install command into your image so every new node joins the tailnet at boot.

如何使用 Tailscale Kubernetes

Kubernetes lets you reach internal cluster services from your laptop without a public load balancer.

以下是使用步骤。

Step 1: Install the Operator

Deploy the Tailscale operator into your cluster with Helm.

Step 2: Annotate a Service

Add the Tailscale annotation to any service you want on the tailnet.

这就是它的样子:

无题设计 3 40

检查点: The service shows up as its own device in the Machines list.

Step 3: Open It by Name

Hit the service DNS name from your phone or laptop.

✅ 结果: Internal dashboards stay off the public internet but remain accessible to your team.

💡 专业提示: Use the operator’s API server proxy so kubectl works without a public control plane.

如何使用 Tailscale Edge 和物联网部署

边缘计算和物联网部署 lets you manage a Raspberry Pi fleet or a shelf of sensors from one dashboard.

以下是使用步骤。

Step 1: Flash and Install

Install the client on each Raspberry Pi with the standard Linux command.

Step 2: Use Ephemeral Keys

Ephemeral auth keys clean up stale entries when a device goes offline for good.

这就是它的样子:

无题设计 4 40

检查点: Each board reports online and answers SSH over its tailnet name.

Step 3: Name Every Node

Rename each machine so the hostname tells you where it sits.

✅ 结果: Field hardware is reachable without static IPs, dynamic DNS or open ports.

💡 专业提示: Set a device to never expire, or a remote sensor will drop off after 180 days and need a physical visit.

How to Use Tailscale Cloud connectivity

Cloud connectivity lets you let a cloud app read an on-premise database without a public route.

以下是使用步骤。

Step 1: Route the On-Prem Side

Run a subnet router next to the database and advertise its range.

Step 2: Join the Cloud Workload

Install the client inside the cloud VM or container.

这就是它的样子:

尾规模云连接

检查点: The application connects to the private host by its internal IP.

Step 3: Lock It Down

Write an ACL that allows only that workload to reach the database port.

✅ 结果: Cloud and on-prem traffic stays encrypted end to end with no bastion host.

💡 专业提示: Turn on MagicDNS so the connection string uses a stable name instead of a changing address.

How to Use Tailscale Secure AI

保障人工智能安全 lets you keep a GPU box or local model server private while your laptop still reaches it.

以下是使用步骤。

Step 1: Bind Locally

Run the model server on localhost or on the tailnet interface only.

Step 2: Add the GPU Host

Install the client on the GPU machine and confirm it is connected.

这就是它的样子:

tailscale 保障人工智能

检查点: The model answers requests from your laptop and nowhere else.

Step 3: Point Your Tools at It

Use the tailnet hostname as the API endpoint in your app.

✅ 结果: Your private model is usable from anywhere and invisible to the public internet.

💡 专业提示: Share the node with one teammate instead of the whole tailnet when you need a second pair of eyes.

How to Use Tailscale Zero Trust networking

Zero Trust networking lets you grant access per user and per device instead of trusting everyone on the network.

以下是使用步骤。

Step 1: Open the Access Controls

Edit the policy file in the admin console.

Step 2: Write Narrow Rules

Allow each group to reach only the ports it needs.

这就是它的样子:

尾规模零信任网络

检查点: A test account is blocked from a server it should not touch.

Step 3: Require Device Posture

Turn on device approval so new hardware waits for a human check.

✅ 结果: Access follows identity, so a stolen laptop does not hand over the whole network.

💡 专业提示: Use the ACL preview tab before saving, since a bad rule can lock you out of your own machines.

Tailscale 专业技巧和快捷方式

If you are interested in getting more from your tailnet, start with these.

Handy Commands

行动命令
Check connections尾规模地位
Connect this machine尾部向上
Send a filetailscale file cp
Test a pathtailscale ping

大多数人错过的隐藏功能

  • Exit node: Route all internet traffic through one device. For example, a laptop in San Francisco can browse through your home connection. Exit nodes are chosen per client.
  • Taildrop: Send files between your own devices without the cloud, straight from the share sheet on a phone.
  • MagicDNS: Human-readable hostnames replace raw IP addresses, so ssh pi works from any client.
  • Tailscale Serve: Publish a local web server to your tailnet over HTTPS with one command.

尾部规模分析中需要避免的常见错误

Mistake #1: Expecting it to hide your browsing by default

❌ 错误: Installing the app and assuming websites now see a different IP address.

✅ 右图: Only tailnet traffic is routed by default. Pick an exit node if you want your public IP hidden too.

Mistake #2: Forgetting to approve subnet routes

❌ 错误: Running the advertise command, then wondering why the home network is unreachable.

✅ 右图: Approve the route in the admin console and enable IP forwarding on the host.

Mistake #3: Ignoring key expiry

❌ 错误: Leaving a headless server to expire after 180 days and losing remote access.

✅ 右图: Disable key expiry on servers you cannot physically reach.

尾尺度故障排除

Problem: Devices connect but the link feels slow

原因: A direct peer connection failed, so traffic is going through a DERP relay server.

使固定: 跑步 尾规模网络检查, then open UDP 41641 outbound or turn off strict NAT on the router.

Problem: A machine shows as offline

原因: The client stopped, or its node key expired.

使固定: Restart the service, run 尾部向上 again and re-authenticate in the browser.

A machine configured months ago sometimes just needs connecting once more.

Problem: Hostnames do not resolve

原因: MagicDNS is off, or another VPN client is holding the DNS settings.

使固定: Enable MagicDNS in the admin console and disconnect the other VPN.

📌 笔记: If none of these help, the Tailscale documentation and support team are both quick to answer.

Tailscale是什么?

尾鳞 is a VPN service that builds a private mesh network between your own machines.

Think of it as a network cable that follows your devices around the world.

It is based on the WireGuard protocol, and its architecture avoids the single point of failure a central VPN server creates.

Traffic takes the shortest path possible, usually a direct peer-to-peer hop, with encrypted packets end to end.

Here is the short version:

尾量级主页

它包含以下主要特点:

  • 企业VPN: One tailnet for the whole company, with single-sign-on and admin roles.
  • 安全远程访问: Reach a home server or office host without exposing services to the internet.
  • 站点间联网: Subnet routers link entire networks through one gateway device.
  • 多云网络: Servers across providers share one flat set of IP addresses.
  • Kubernetes: Cluster services become tailnet devices instead of public endpoints.
  • 边缘计算和物联网部署: A Raspberry Pi in the field stays accessible with no open ports.
  • 云连接: Cloud workloads reach on-prem hosts over an encrypted path.
  • 保障人工智能安全: Local model servers stay private while your tools still connect.
  • Zero Trust networking: Access rules follow the user and the device, not the network.

For the full breakdown, see our Tailscale 评测.

尾量定价

Here is what Tailscale costs in 2026:

计划价格最适合
个人的永久免费One user, home network and side projects
个人加强版每月 5 美元Enthusiasts who want more devices and a few users

免费试用: The Personal plan is free forever, so there is nothing to trial.

退款保证: Paid plans are monthly, so you cancel rather than claim a refund.

The Personal plan is free for personal use and covers 20 devices on a single tailnet.

Team plans add advanced SSO, unlimited access control, admin roles and enterprise support.

Here is the pricing page as it stands:

Tailscale VPN 定价

💰 性价比最高: Personal — free forever, and enough for a home lab with a Raspberry Pi, a NAS and a laptop.

Tailscale 与其他方案的比较

Most tools on this list are privacy VPNs. Tailscale is a networking tool, so compare on the job you need done.

工具最适合价格等级
尾鳞Private device networks每月 0 美元⭐ 4.6
NordVPN流媒体和隐私每月 12.99 美元⭐ 4.7
ExpressVPNSpeed and ease每月 12.95 美元⭐ 4.6
ProtonVPNPrivacy and free tier每月 9.99 美元⭐ 4.5
Surfshark VPN设备数量不限每月 12.95 美元⭐ 4.5
网络幽灵流媒体服务器每月 12.99 美元⭐ 4.3
私人互联网接入Configurable client$11.95/mo⭐ 4.4
PureVPNBudget plans$10.95/mo⭐ 4.2

快速精选:

  • 综合最佳: Tailscale — nothing else connects your own machines this quickly.
  • 最佳预算: Tailscale — the free plan covers most home setups.
  • 最适合初学者: ExpressVPN — one button, no networking knowledge needed.
  • Best for hiding traffic: ProtonVPN — audited clients and a genuine free tier.

🎯 尾规模替代方案

Looking for Tailscale alternatives? Here are the options worth a look:

  • 🚀 NordVPN: Huge server network for streaming and privacy, though it hides your traffic rather than linking your own devices.
  • ExpressVPN: Fast consumer VPN with apps on nearly every platform, built for location switching instead of private device networking.
  • 💰 PureVPN: Budget subscription VPN with a dedicated IP add-on, useful if you only need a hidden public address.
  • 💼 Surfshark VPN: Unlimited device connections on one account, a good pick for families who want traffic encryption everywhere.
  • 🔒 ProtonVPN: Privacy-first provider with a solid free tier and open-source clients audited by outside firms.
  • 👶 PrivadoVPN: Simple free tier with a small monthly 数据 allowance, aimed at people new to VPN apps.
  • 🎯 AdGuard VPN: Pairs traffic encryption with ad blocking, handy on a phone where trackers are the main annoyance.
  • 🏢 虚拟盾牌: Consumer privacy bundle with identity monitoring, sold mainly to households rather than technical users.
  • 🔧 StrongVPN: Long-running provider with router support, a fit if you want one device covering the whole home network.
  • 📊 AuraVPN: Part of a wider identity protection suite, bundling a VPN with credit and dark web monitoring.
  • 🔥 网络幽灵: Streaming-tuned servers and a very long refund window, built for media rather than infrastructure.
  • 🧠 迈克菲VPN: Bundled with McAfee antivirus, convenient if you already pay for the 安全 套房。
  • 私人互联网接入: Configurable client with per-app rules and a no-logs record tested in court.
  • 🌟 神秘: Decentralised node marketplace where users pay for bandwidth from other people’s hardware.
  • 🎨 SafeShell VPN: Focused on streaming access with region-specific modes for major platforms.
  • 🚀 Oyster VPN: Small provider with cheap long-term plans and a straightforward app on phone and desktop.

完整列表请参见我们的 尾规模替代方案 指导。

⚔️ Tailscale 对比

Here is the head-to-head against each one:

  • Tailscale 对比 NordVPN: NordVPN wins for anonymous browsing. Tailscale wins when you want to reach your own machines.
  • Tailscale 与 ExpressVPN 对比: ExpressVPN is simpler for casual users. Tailscale gives you a real private network.
  • Tailscale 对比 PureVPN: PureVPN is cheaper for streaming. Tailscale is free for personal use and far better for remote access.
  • Tailscale 对比 Surfshark VPN: Surfshark covers more devices per plan. Tailscale connects those devices to each other.
  • Tailscale 对比 ProtonVPN: ProtonVPN is stronger on anonymity. Tailscale is stronger on connectivity between your own servers.
  • Tailscale 对比 PrivadoVPN: PrivadoVPN suits light browsing. Tailscale suits anyone running a home server.
  • Tailscale VPN 对比 AdGuard VPN: AdGuard blocks ads better. Tailscale handles private networks that AdGuard never touches.
  • Tailscale vs VirtualShield: VirtualShield targets families. Tailscale targets developers and IT teams.
  • Tailscale 对比 StrongVPN: StrongVPN is easier on an old router. Tailscale gives per-device access rules.
  • Tailscale 对比 AuraVPN: Aura bundles more privacy tools. Tailscale does one job properly.
  • Tailscale 对阵 Cyber​​Ghost: CyberGhost unblocks more catalogues. Tailscale reaches your NAS and Raspberry Pi.
  • Tailscale 对比 McAfee VPN: McAfee is convenient if bundled. Tailscale is the better standalone network tool.
  • 尾规模网络与私有互联网接入: PIA offers deeper tuning for privacy. Tailscale offers direct peer-to-peer links.
  • 尾鳞对战神秘: Mysterium is more experimental. Tailscale is production-ready for daily work.
  • Tailscale VPN 与 SafeShell VPN 对比: SafeShell is aimed at viewers. Tailscale is aimed at 建筑商.
  • Tailscale 对比 Oyster VPN: Oyster costs less monthly. Tailscale costs nothing for a personal tailnet.

立即开始使用 Tailscale

You now know how to use Tailscale across every major feature:

  • ✅ 企业版 VPN
  • ✅ 安全远程访问
  • ✅ 站点间联网
  • ✅ 多云网络
  • ✅ Kubernetes
  • ✅ 边缘计算和物联网部署
  • ✅ Cloud connectivity
  • ✅ 保障人工智能安全
  • ✅ Zero Trust networking

下一步: Install the client on two devices and run 尾规模地位.

大多数人都是从安全远程访问开始的。

只需不到五分钟。

常见问题解答

如何实际使用Tailscale?

Create a free account, install the client on two or more devices, and log in with the same account. Each machine gets a 100.x.x.x IP address and connects by name.

Tailscale 可以免费供个人使用吗?

Yes. The Personal plan is free forever and covers 20 devices on one tailnet. Personal Plus costs $5/per month if you want more devices and a few extra users.

我应该一直开着Tailscale吗?

Yes, for most people. It only routes tailnet traffic by default, so it barely touches battery or speed unless you turn on an exit node.

Tailscale会隐藏我的IP地址吗?

Not by default, because normal browsing skips the tailnet. Enable an exit node and your public traffic leaves through that device instead of your own connection.

Tailscale能看到我的流量吗?

No. Packets are encrypted between devices with WireGuard keys. The coordination server handles public key exchange and device lists, never the contents of your connections.

相关文章