The Toronto server connected.
My home NAS remained unreachable.
I was in a Kuala Lumpur hotel room with twenty-seven minutes before a client presentation. The final deck was ready, but the signed pricing appendix was sitting on the NAS in my apartment several thousand kilometres away.
I opened my established commercial VPN and chose a Canadian location.
The public IP address changed to Toronto.
I entered the NAS address in the browser.
Nothing loaded.
I blamed the machine at home. Perhaps it had restarted after an update or lost its network connection.
I tried the local address again.
192.168.1.42 refused to connect.
The VPN app still showed a green shield and a Canadian flag.
That was when I realised I had asked it to do something it had never promised to do.
The commercial VPN could make my internet traffic exit in Canada.
It could not place my laptop inside the private network in my apartment.
The presentation began in twenty-four minutes.
I did not need a Canadian IP address.
I needed one specific file from one specific machine.
The short answer
I could not inspect the hotel’s internal filtering rules or determine the precise cause of every earlier failure. The visible division of labour was decisive: Tailscale reached the private NAS, while the smaller commercial service completed the public upload that followed.
A nearby VPN server was not my home network
A commercial VPN normally carries public internet traffic through a server operated by the provider. That can protect a connection on hotel Wi-Fi and change the public address seen by websites.
It does not automatically create a route to a private NAS, desktop or development server behind a home router.
Tailscale solves that narrower problem. Devices added to the same tailnet receive private addresses and can connect without exposing the destination service directly to the public internet. (Tailscale)
I already had it installed on both the NAS and laptop.
I opened it.
The NAS appeared online under its device name.
The file-sharing page loaded.
My commercial VPN had failed because I was choosing the wrong kind of destination. A Canadian exit server was still a public internet route. Tailscale reached the NAS because the NAS itself belonged to its private network.
That distinction mattered more than the country beside the connect button.
For remote access, the question was not where my traffic appeared to exit.
It was whether the destination device was part of the network I had joined.
The private file arrived through a slow relay
I found the signed appendix and began downloading the project folder.
The estimate settled at fourteen minutes.
The hotel speed test had shown more than 200 Mbps.
The folder was only 430 MB.
I checked the connection status. The laptop had not formed a direct link to the NAS. The hotel network had forced the transfer through a relay.
Tailscale first tries to connect devices directly. When the surrounding networks prevent that, it can relay the traffic so the devices remain reachable. The trade-off is lower throughput than a clean direct path. (Tailscale)
That explained the mismatch.
The hotel Wi-Fi was fast for ordinary websites.
The private connection home was taking a longer route.
Other travellers have seen the same practical result: strong hotel bandwidth, followed by a surprisingly slow Tailscale transfer when the network prevents a direct connection. (Reddit)
I let it continue.
Eight minutes later, the signed appendix was on my laptop.
Tailscale had completed exactly the task it was built for. The private file had reached me without my opening the NAS to the public internet.
The next step was different.
I had to send that file to a public client portal.
The exit node sent the upload on a trip home
I selected my home NAS as an exit node.
The decision felt logical. If I was already connected to my apartment, why not send all my hotel traffic through it?
The client portal opened.
I selected the presentation package and started the upload.
The estimate changed to fifty-three minutes.
An exit node routes ordinary internet traffic through a selected device in the tailnet. (Tailscale) My client upload was therefore making an unnecessary round trip:
Kuala Lumpur to my apartment.
My apartment back out to the client platform.
The return traffic followed the same detour.
The transfer now depended on the distance home, the home connection’s upload capacity and the quality of every route between them.
Tailscale still worked.
It was simply solving the wrong part of the job.
The private appendix was already on my laptop. Sending a public upload through the distant home connection added delay without improving access to the file.
I turned off the exit node.
The client portal immediately became more responsive.
That was the moment the workflow separated into two clean tasks:
Tailscale brought the private file to me.
A commercial VPN needed to protect the public upload from the hotel.
One route did not need to do everything
I briefly considered keeping Tailscale active for the NAS while running a commercial VPN for public traffic.
That can work with careful routing, but overlapping VPN configurations can also compete over which service controls the default route. Tailscale documents specific compatibility considerations, especially when exit nodes or another VPN’s broad routing rules are involved. (Tailscale)
I no longer needed the complexity.
The appendix was local.
The NAS had completed its role.
I disconnected Tailscale and returned to the established commercial provider.
This time, I was asking it to perform the job it was designed for: protect ordinary internet traffic while I sent the presentation to a public service.
The separation made the comparison fairer.
It still did not make the upload work.
The established provider failed at the public half
The provider had years of public history, mature applications and many Asian locations.
Its automatic server opened the client portal quickly.
The upload reached 19 percent and stopped.
I selected Singapore.
The portal requested another login, accepted it and returned a network error at 31 percent.
A second nearby route triggered a CAPTCHA before the attachment page opened.
The provider’s fastest option loaded normal websites without difficulty, but the upload repeatedly dropped back to zero.
The problem was no longer remote access. Tailscale had already retrieved the private file.
The problem was carrying that file through hotel Wi-Fi to the client.
I had eleven minutes left.
A larger server list was not helping. It was creating more opportunities to restart the same upload.
By then, I had stopped asking for the nearest country.
I needed one route that could keep the portal signed in until the progress bar reached 100 percent.
The smaller app completed the public job
I closed the established provider and opened OnlydogVPN.
The smaller app did not begin with a country list. I selected the situation for working on a restrictive hotel network and connected.
Then I closed the client portal and started a fresh session.
The login page appeared.
The authentication request reached my phone.
The project dashboard loaded.
I selected the presentation package.
The upload began.
Ten percent.
Twenty-five.
The progress bar continued moving.
At 47 percent, the client sent a message asking whether the signed appendix had been included. The messaging app remained online, so I confirmed it without interrupting the transfer.
Sixty-eight percent.
Ninety.
The client portal processed the archive and displayed each file, including the appendix I had retrieved from the NAS.
I pressed Submit.
The status changed to:
Presentation package received.
There were three minutes left.
The result came before the technical explanation.
The service uses an HTTP/3-based transport with additional traffic obfuscation, giving the hotel network a steadier web-style route for the client portal and messaging application.
I could not inspect the hotel’s internal filtering rules or determine the precise cause of every earlier failure. The visible division of labour was decisive: Tailscale reached the private NAS, while the smaller commercial service completed the public upload that followed.
The connection followed the work into the lift
I packed the laptop and left for the meeting room.
The hotel Wi-Fi weakened inside the lift.
My phone switched to mobile data.
The client messenger paused briefly, then refreshed.
The VPN remained connected.
A final message appeared:
Files checked. Ready when you are.
I replied before the lift reached the lobby.
The message delivered.
The HTTP/3-based connection had recovered as the phone changed networks. (IETF)
That smaller result gave the app a reason to remain active after the presentation package was safe.
Tailscale had brought the private file out of my home network.
The smaller service carried the public client workflow through the hotel and continued onto mobile data when I walked away.
The two tools were not competing for the same part of the journey.
They were most useful when each stopped trying to perform the other’s job.
Tailscale remained the right tool for the NAS
The failed exit-node upload did not make Tailscale a poor choice.
For reaching a private NAS, development server or remote desktop, it was the correct tool in this story.
It gave the laptop a private route to a named device.
It avoided exposing the NAS directly to the internet.
It kept the device reachable even when the hotel network forced the connection through a slower relay.
A commercial VPN could not replace that function. Choosing a Canadian server did not grant access to the private network in my apartment.
The commercial service became useful after the file was local and the work returned to the public internet.
That was the boundary I had missed at the beginning.
Tailscale connected devices I controlled.
The smaller VPN protected the ordinary applications I used after retrieving their files.
An exit node is useful when home is the destination
The home exit node was not inherently a bad setup either.
It would make sense if I needed websites to see my home internet address.
It could help when a service allowed access only from that familiar connection.
It could also give me a consistent route through infrastructure I controlled.
But none of those benefits applied to the urgent presentation upload.
The client portal did not require my home address.
The file no longer lived only on the NAS.
Routing the upload through my apartment simply added thousands of kilometres to a task that should have travelled from the hotel to the client.
That distinction is easy to lose because both tools display a connected status.
One connection answers, “Can I reach my private machine?”
The other answers, “Can my public applications use this unfamiliar network safely and reliably?”
Those are not the same test.
Remote access was not one tunnel for everything
The smaller service has fewer locations and a shorter public history than the largest commercial VPN providers.
Neither limitation affected the presentation delivery.
The established provider changed my public location but could not reach the private NAS. Its tested routes later failed to complete the public upload.
Tailscale reached the NAS securely, but routing everything through my distant home exit node turned the upload into a fifty-three-minute detour.
The smaller app handled the public half of the workflow: the client portal, the messaging application and the transition from hotel Wi-Fi to mobile data.
I had started the morning asking whether Tailscale or a commercial VPN was better for remote access.
The presentation succeeded when I stopped treating them as interchangeable: Tailscale brought me into the private network, and the smaller VPN carried the work after I came back out.
Questions this experience may leave you with
What was actually causing the problem?
I could not inspect the hotel’s internal filtering rules or determine the precise cause of every earlier failure. The visible division of labour was decisive: Tailscale reached the private NAS, while the smaller commercial service completed the public upload that followed.
Why did the obvious fixes fail?
Tailscale had completed exactly the task it was built for. The private file had reached me without my opening the NAS to the public internet.
What should you check first?
Tailscale reached the NAS securely, but routing everything through my distant home exit node turned the upload into a fifty-three-minute detour.
What finally changed the result?
The client portal processed the archive and displayed each file, including the appendix I had retrieved from the NAS.
What is worth remembering?
The presentation succeeded when I stopped treating them as interchangeable: Tailscale brought me into the private network, and the smaller VPN carried the work after I came back out.