When I was recently setting up my GL.iNet Spitz AX router in my RV, I saw a new ‘beta’ tailscale menu item in the GL.iNet GUI. tailscale is a secure, easy-to-use VPN service that connects your devices directly over the Internet, creating a private network without a complicated setup. Basically, tailscale lets you easily connect remote devices together into their own private SD-WAN, and they’ve made the setup dead simple. Heck, you can even use an AppleTV to provide remote access to your whole network via tailscale.
In this article, I’m going to set up a very simple tailscale network using the GL.iNet Beryl AX travel router as well as a computer at home. The idea here is that I’ll be able to access services and devices behind the Beryl AX, and when connected to the Beryl AX with any of my devices, I’ll be able to remote desktop to my home PC.

This way, when I’m travelling, I’ll be able to connect up my travel router to any Internet connection, and once it’s connected, I’ll have a secure tunnel right to my home PC. In this particular example, I’m only using tailscale with a Windows 10 PC I have at home, but you could also set up another tailscale node that provides access to the entire home subnet as well.
But what does it cost??? Well – that’s the cool thing. It’s free. tailscale is free up to 100 devices and 3 users – way more than most home users will ever need. tailscale monetizes their business customers so that you get this awesome tech free of charge!
tailscale initial setup
OK – so let’s get started…the first thing you’ll want to do is head over to tailscale.com and sign up for a free account. Click ‘Get started’ in the upper left-hand corner. You can then select your Identity provider of choice – I’m going to pick Google, and it’ll walk you through the rest of that setup.

When you first log in, a wizard pops up and first asks if you’re using tailscale for personal or business use – we’ll select ‘Personal use’ for our purposes.

Next, we’ll be prompted to add our first device. Windows is already selected for me since it was able to detect my OS. Click ‘Download Tailscale for Windows’ to start the installation.

This brings you to the tailscale client download page where you can click ‘Download Tailscale for Windows’ again to get the client.

Follow the installation wizard prompts and log back in with the same identity provider. Once logged in, you can go back to the first tailscale browser window, and you should now see your first device added.

tailscale will now wait for you to add another device, but at this point, click ‘Skip this introduction’ at the bottom since our 2nd device is the Beryl AX, and that process is a bit different.
Before we get to that though, take a look through the admin console for tailscale. We can see the 1st machine we added, you can add additional systems with the links below your machines, and then there’s a full list of various menu items across the top.

GL.iNet tailscale setup
Now it’s time to dig into the setup of the Beryl AX travel router – keep in mind that while I’m doing this setup with the Beryl AX, it should be exactly the same for any GL.iNet device since they’ve all got the same GUI. For a full overview of GL.iNet travel router setup – check this video:
Connect to the Beryl AX by connecting to its wireless SSID or by plugging into the LAN port. Open up 192.168.8.1 in the browser (or the admin GUI IP if you changed it to something different) and then select Applications –> Tailscale from the left-hand menu.

Toggle the switch to enable tailscale and click ‘Apply.’

tailscale is now enabled, but we haven’t yet connected it to our tailnet (our group of devices that we’re securely connecting together). To do this, click the Device Bind link:

This will give you a pop-up window with a unique link that, when clicked, will bind this device to your tailnet. Click the link and go through the identity verification again.

Once you’re authenticated, you’ll be prompted to connect your device to your tailnet. Click ‘Connect’ and you should receive a verification.

Now head back into the GL.iNet GUI and close the Device Bind Link window – you should see your bind account email and a virtual IP for your device. While we’re in here, go ahead and enable ‘Allow Remote Access LAN’ since we’ll want other devices in our tailnet to be able to connect to devices behind the router. In our example, we’ll be connecting to an OpenSpeedTest server that I have running on a Minisforum MS-01.

Final steps
If you go back to the tailscale admin GUI, you should now see both of your devices connected – awesome! But we have a few more steps to take before we are fully operational.
First, we need to tell tailscale that it’s OK to route traffic to the LAN subnet behind the Beryl AX. Click on the 3 dots to the right of the Beryl AX in the tailscale GUI and choose ‘Edit Route Settings.’

Then check the box for your LAN subnet (by default, this will be 192.168.8.0/24) and click ‘Save.’

Let’s test it out! From your Windows PC (or the first device you added to the tailnet), make sure that you’re NOT connected to the wireless SSID of the Beryl AX and browse to the admin GUI of the Beryl AX at 192.168.8.1. It should pop up for you!
Now let’s try to browse to the tailscale IP address of the Beryl AX which you can find on the tailscale machine table. In my case, the IP is 100.112.124.126.

This also brings us to the admin GUI for the Beryl AX! However, if anyone else in the world who isn’t a part of our tailnet tries this IP, they’ll get nothing back.

Let’s now try to get to our OpenSpeedTest server that’s running on a server behind the Beryl AX. From the clients table in the Beryl AX GUI, I can see that my Minisforum server is at 192.168.8.150.

OpenSpeedTest runs on port 3000, so from my Windows PC that’s NOT connected to this Beryl AX LAN, I should be able to open up http://192.168.8.150:3000 and get to my OpenSpeedTest server.

Success!
Now let’s try to connect the other direction. I want to be able to RDP to my Windows PC whenever I’m on the road, so from that Minisforum PC (which is also running Windows), open up the Remote Desktop application and try to connect to the tailscale IP address of your connected Windows PC. In my case, it’s 100.118.44.88.
IF the RDP connection doesn’t work immediately, it’s possible that you haven’t configured your Windows PC to allow for incoming RDP connections (also assuming you’re on Windows 10/11 Pro here – incoming RDP doesn’t work with the Home version of Windows).
First enable Remote Desktop by pressing WIN+I to open Settings. Make sure that ‘Enable Remote Desktop’ is enabled.

You should also enable RDP through the Windows Firewall by pressing WIN+R, type ‘Control Panel’ and press ENTER. Go to System and Security –> Windows Defender Firewall –> Allow and app or feature through Windows Defender Firewall. Find Remote Desktop and make sure that it’s enabled through Private and/or Public networks.
Now if you try to RDP from the remote server behind your Beryl AX through the tailnet, it should work!
One more pro tip here – apparently there’s potentially some issues with Microsoft SSO authentication with RDP – mine kept telling me that the password was wrong even though I triple-checked it. After some Google-fu, I found THIS ARTICLE that sorted it for me. I didn’t dig deep into why this happens, or how this command fixed it…but it fixed it.
So now our setup is complete!

From behind the Beryl AX travel router, we can RDP to our Windows PC, and from the Windows PC, we can hit services behind the Beryl AX – no matter what kind of Internet you plug in to that travel router, it should still work.
Here’s one bonus! Even if you enable the Beryl AX travel router to connect through a VPN proxy service such as Private Internet Access, this whole setup still works! Amazing…
If you enjoyed this tutorial – please consider the following!
Subscribe to Crosstalk Solutions on YouTube!
Check out Rogue Support for all of your Internet/wireless/networking support needs!
Buy me a beer HERE – cheers!

Comments 3
Hello
As I pasted in as a comment on your YouTube video about tailscale, use this link to update to the latest version. I’ve done this again today and have been doing this update several times.
https://forum.gl-inet.com/t/script-update-tailscale-on-nearly-all-devices/37582
So I do find this helpful, but I still have some issues.
I have the Opal, which (currently) isn’t offering Tailscale.
I have set up an Openwrt router at home and can successfully connect home with individual devices.
I am now trying to setup an Openwrt router as a travel router and have it Tailscale back to my home exit node router. How do I tell that travel router through Terminal/ssh to use that exit node? Since in Openwrt the GUI is not as nice and user friendly as GL.iNet.
I am also very new with Linux and Terminal. I was wondering if it might tbe The process of setting up a Linux device to do it.
would all devices connected to the beryl AX be able to connect to other devices in my tailnet if I set it up like you described?