Access your Portable RTX Compute Node from anywhere — hotel WiFi, coffee shop, or another city — using either Tailscale (easiest) or WireGuard (self-hosted).
Tailscale is a zero-config VPN built on WireGuard. It handles NAT traversal automatically and requires no port forwarding.
On both the host (Acer Predator) and client (Dell Precision):
- Download from tailscale.com/download and install.
- Sign in with the same Tailscale account on both machines.
- Both machines appear in your Tailscale admin console.
In the Tailscale admin console, note the Tailscale IP of the host (e.g., 100.x.y.z). Alternatively:
# On the host
tailscale ip -4Replace Desktop.home with the Tailscale IP (or use MagicDNS hostname):
# In PowerShell on the client — test connectivity
Test-NetConnection -ComputerName 100.x.y.z -Port 22
# Set Ollama to use Tailscale IP
[System.Environment]::SetEnvironmentVariable("OLLAMA_HOST", "http://100.x.y.z:11434", "User")Or use MagicDNS (enabled by default): the host becomes desktop-home.<tailnet>.ts.net — no IP needed.
All services work identically over Tailscale:
| Service | Remote URL |
|---|---|
| Ollama | http://100.x.y.z:11434 |
| JupyterLab | http://100.x.y.z:8888 |
| SSH | ssh <user>@100.x.y.z |
| Sunshine | https://100.x.y.z:47990 |
⚠️ Security reminder: JupyterLab has no token by default. Add one before accessing remotely — see SETUP.md.
If you only want to route traffic to the host through Tailscale, ensure split tunneling is on (the default). This keeps your regular internet traffic on the local ISP.
Use WireGuard if you want full control with no third-party service. This requires a static public IP or DDNS on the host side, and port forwarding on your router.
- Static IP or a DDNS service (e.g., DuckDNS, No-IP) pointing to your home router's WAN IP
- Port forwarding: UDP 51820 → host LAN IP
Download from wireguard.com and install on Windows.
# Generate server key pair (run in PowerShell as Admin)
wg genkey | Tee-Object server_private.key | wg pubkey > server_public.keyCreate C:\ProgramData\WireGuard\wg0.conf:
[Interface]
PrivateKey = <server_private_key>
Address = 10.8.0.1/24
ListenPort = 51820
DNS = 8.8.8.8
[Peer]
# Dell Precision (client)
PublicKey = <client_public_key>
AllowedIPs = 10.8.0.2/32[Interface]
PrivateKey = <client_private_key>
Address = 10.8.0.2/24
[Peer]
# Acer Predator (GPU host)
PublicKey = <server_public_key>
Endpoint = <your-ddns-hostname-or-ip>:51820
AllowedIPs = 10.8.0.0/24
PersistentKeepalive = 25On both machines, import the .conf file into the WireGuard GUI and click Activate.
Test:
# From client — ping the host over WireGuard tunnel
ping 10.8.0.1Replace Desktop.home with 10.8.0.1 in your environment variables and SSH config.
Before enabling remote access, review these items:
- JupyterLab token set —
jupyter lab --NotebookApp.token=<your_token> - SSH key-only auth — password auth disabled in
sshd_config - Firewall rules — only Tailscale/WireGuard port open on host Windows Firewall
- SMB not exposed — SMB (445) should never be internet-facing
- Sunshine web UI — use a strong password; accessible on Tailscale IP only
- No secrets in repo — confirm
.gitignorecovers.env,*.key,sunshine_state.json
| Connection | Typical Latency | Usable For |
|---|---|---|
| LAN (same subnet) | <1 ms | Everything |
| Tailscale (same city) | 5–20 ms | SSH, Ollama, Jupyter |
| Tailscale (cross-country) | 50–100 ms | SSH, Ollama; streaming marginal |
| WireGuard (same ISP) | 10–30 ms | SSH, Ollama, Jupyter |
Moonlight game streaming requires <30 ms for comfortable use. Over Tailscale at distance, latency may be too high for real-time streaming but SSH and LLM inference work fine.