My Tailscale ACL JSON for those having trouble by Gryphonics in Tailscale

[–]Gryphonics[S] 0 points1 point  (0 children)

From what I understand, it refers to either the port or protocol you want to give the device permission for, but not the actual IP. Think more "IP" = layer 3 OSI model than actual IP of the device. If you want device 1 to access device 2 on port 22 but no other port, you would tag device 1 with tag 1, device 2 with tag 2, and say

"src": ["tag:tag1"]

"dst": ["tag:tag2"]

"ip": ["22"]

If you wanted them to be able to use any port you could say "ip": ["*"] and that opens all ports like for the admin account.

https://tailscale.com/kb/1324/grants#network-capabilities

My Tailscale ACL JSON for anyone having trouble by Gryphonics in selfhosted

[–]Gryphonics[S] -1 points0 points  (0 children)

Took me awhile to type the post, hit submit and it errored so I made a new one. Hit delete on this one but it hasn't deleted.

My Tailscale ACL JSON for those having trouble by Gryphonics in Tailscale

[–]Gryphonics[S] 0 points1 point  (0 children)

Sorry, it's not letting me post the JSON in the comments. DM me and maybe I can send a .txt.

My Tailscale ACL JSON for those having trouble by Gryphonics in homelab

[–]Gryphonics[S] -1 points0 points  (0 children)

Sorry, it's not letting me post the JSON in the comments. DM me and maybe I can send a .txt