Tailscale + Reticulum · advanced

A Practical Reticulum TCP Bridge over Tailscale on Port 4242

The configuration is small, but binding address and access policy decide whether the bridge is private or accidentally broader than intended.

Current. Hands-on Tailscale/Reticulum/home-infrastructure field note. Private addresses and credentials intentionally omitted.

A Practical Reticulum TCP Bridge over Tailscale on Port 4242

The configuration is small, but binding address and access policy decide whether the bridge is private or accidentally broader than intended.

My Reticulum lab already uses a TCP server interface on port 4242. Moving that transport onto the tailnet is mostly about choosing the right bind address and then proving both layers independently.

The setup I use

If the TCP server binds to 0.0.0.0, it can listen on LAN and Tailscale interfaces. If I want the bridge to be tailnet-specific, I bind to the host's Tailscale address instead. I then allow only the intended tailnet sources to reach TCP 4242.

Commands and configuration

# Verify the IP path first
tailscale ping hserver

# Verify the Reticulum listener
ss -lntp | grep 4242

# Then inspect Reticulum state
rnstatus

Where this usually fails

Opening 4242 in a host firewall is not the same thing as authorizing a Reticulum peer, and a listening socket is not proof that Reticulum has a healthy path. I test IP reachability, TCP reachability and Reticulum behavior separately.

The rule I keep

Bind narrowly when possible, authorize narrowly, and validate Tailscale, TCP and Reticulum as three separate layers.

That rule is more useful to me than memorising one command because it identifies which layer owns the decision. Tailscale is excellent at creating a private, authenticated IP network between machines, but I still keep application state, Reticulum state, SSH authorization and public ingress as explicit layers.

References

  • https://reticulum.network/manual/interfaces.html
  • https://tailscale.com/docs/features/access-control
Quick navigationEsc