1. Map a dedicated miner network
Tailscale provides private connectivity; it is not a mining dashboard. A local subnet router lets authorized remote devices reach ASICs that cannot run its client. Plan the path: remote laptop → Tailscale → Linux server → miner LAN. Keep miners on an isolated network that does not overlap the remote LAN. For example, after checking existing ranges, use 10.77.40.0/24: LAN gateway 10.77.40.1, with DHCP reservations for the server at 10.77.40.2 and miners from 10.77.40.101.
2. Prepare the local server
Use a mini PC or Raspberry Pi running supported Linux, connected by Ethernet, with reliable SSD storage and clean ventilation. Size memory, storage and a recommended UPS for the monitoring workload and desired backup time. Keep the server away from hot miner exhaust. Update Linux and record how an on-site contact can reach it.
3. Install and authorize Tailscale
Follow the official installation instructions on the server and authorized remote client. Sign both into your private Tailscale network, or tailnet. Enable multifactor authentication at the identity provider. Do not install packages into closed miner firmware. Protect miner credentials separately; private connectivity does not replace device authentication.
4. Enable only the required route
On Linux, enable persistent IP forwarding, advertise only the miner subnet, then approve that route in the Tailscale admin console. Forwarding, route advertisement, approval and access policy are separate settings. Remote Linux clients must also accept subnet routes. Check the current official setup guide for the distribution-specific steps.
5. Restrict access at both layers
Use grants or ACLs to limit named operators to required miner IP addresses and ports; remove broad allow-all rules. Configure the server’s forwarding firewall for the same intended traffic and test its effective rules. Keep miner interfaces private: no public port forwarding, UPnP mappings or Funnel. Tailscale encryption ends at this gateway for non-client miners; isolate the remaining LAN segment and use miner HTTPS where supported.
6. Choose what to observe
Open each manufacturer’s miner interface over the private route, or separately install trusted monitoring software with read-only access where available. Track hashrate, temperature, rejected shares and last-seen time; configure actionable alerts. Compare pool-reported hashrate over its averaging window, because it will not match every instantaneous device reading.
7. Run a practical acceptance check
Test from a laptop using a phone hotspot outside the miner LAN.
- Confirm the permitted device can open the intended miner page.
- Confirm an unauthorized identity/device cannot reach it.
- Reboot the server and verify forwarding, route access and monitoring recover.
- Check alerts for a missing miner and an unreachable gateway.
8. Plan for lost access
Set reminders before key expiry, document reauthentication arrangements, review device access, and revoke lost devices promptly. Keep alerting independent enough to detect a failed gateway. Maintain an on-site contact and a recovery checklist. Investigate alerts before intervention; do not automate power cycling or unsafe unattended repairs.
Sources and further reading
Tailscale: Configure a subnet router
Tailscale: Install Tailscale on Linux
Tailscale: ACL policy examples

