1. Map a dedicated miner network

Tailscale provides private connectivity; it is not a mining dashboard. A local subnet router lets authorized remote devices reach ASICs that cannot run its client. Plan the path: remote laptop → Tailscale → Linux server → miner LAN. Keep miners on an isolated network that does not overlap the remote LAN. For example, after checking existing ranges, use 10.77.40.0/24: LAN gateway 10.77.40.1, with DHCP reservations for the server at 10.77.40.2 and miners from 10.77.40.101.

2. Prepare the local server

Use a mini PC or Raspberry Pi running supported Linux, connected by Ethernet, with reliable SSD storage and clean ventilation. Size memory, storage and a recommended UPS for the monitoring workload and desired backup time. Keep the server away from hot miner exhaust. Update Linux and record how an on-site contact can reach it.

3. Install and authorize Tailscale

Follow the official installation instructions on the server and authorized remote client. Sign both into your private Tailscale network, or tailnet. Enable multifactor authentication at the identity provider. Do not install packages into closed miner firmware. Protect miner credentials separately; private connectivity does not replace device authentication.

4. Enable only the required route

On Linux, enable persistent IP forwarding, advertise only the miner subnet, then approve that route in the Tailscale admin console. Forwarding, route advertisement, approval and access policy are separate settings. Remote Linux clients must also accept subnet routes. Check the current official setup guide for the distribution-specific steps.

5. Restrict access at both layers

Use grants or ACLs to limit named operators to required miner IP addresses and ports; remove broad allow-all rules. Configure the server’s forwarding firewall for the same intended traffic and test its effective rules. Keep miner interfaces private: no public port forwarding, UPnP mappings or Funnel. Tailscale encryption ends at this gateway for non-client miners; isolate the remaining LAN segment and use miner HTTPS where supported.

6. Choose what to observe

Open each manufacturer’s miner interface over the private route, or separately install trusted monitoring software with read-only access where available. Track hashrate, temperature, rejected shares and last-seen time; configure actionable alerts. Compare pool-reported hashrate over its averaging window, because it will not match every instantaneous device reading.

7. Run a practical acceptance check

Test from a laptop using a phone hotspot outside the miner LAN.

  • Confirm the permitted device can open the intended miner page.
  • Confirm an unauthorized identity/device cannot reach it.
  • Reboot the server and verify forwarding, route access and monitoring recover.
  • Check alerts for a missing miner and an unreachable gateway.

8. Plan for lost access

Set reminders before key expiry, document reauthentication arrangements, review device access, and revoke lost devices promptly. Keep alerting independent enough to detect a failed gateway. Maintain an on-site contact and a recovery checklist. Investigate alerts before intervention; do not automate power cycling or unsafe unattended repairs.

Sources and further reading

Tailscale: Subnet routers

Tailscale: Configure a subnet router

Tailscale: Install Tailscale on Linux

Tailscale: ACL policy examples

Tailscale: What is Tailscale?

Tailscale: Use ufw to lock down an Ubuntu server

Tailscale: Key expiry

Tailscale: Tailscale encryption