By default, every device in your tailnet can reach every other device on every port. For solo work that is usually fine. But once you have a few devices and a server with sensitive ports, ACLs (Access Control Lists) let you tighten the mesh.
The default — wide open inside
No ACL set: every device → every device, all ports. If your phone gets stolen, the attacker has SSH access to your home Mac, your Pi, your VPS — all of it.
The minimum useful ACL
Now if your phone walks off, the attacker can hit your web apps (still PIN-protected; that's why) but cannot SSH to any host. The blast radius shrinks dramatically.
The two ACL habits worth forming
- Phones can never SSH. Use a tag for phones; deny port 22 to that tag. Phones don't need SSH; their absence makes lost-phone attacks much less interesting.
- Admin services on a separate tag. Database admin UIs, server config endpoints, anything destructive — restrict to
tag:admin-laptop. A compromised laptop is rarer than a compromised phone.