How to send iPhone photos to your NAS over Tailscale, without opening ports

By Isaac Griffiths, developer of SMBDrop ·

SMB is built for your home network. Away from home, the tempting fix is to forward port 445 on your router, and that's a bad idea: SMB exposed to the internet is a favourite target for automated attacks. A VPN is the safe way to reach your NAS from outside, and Tailscale is the easiest VPN to set up for this, because it needs no port forwarding at all.

Once it's running, your iPhone can reach the NAS from a hotel, a friend's Wi-Fi or mobile data as if it were at home, and any SMB app, including the Files app, works as normal.

Disclosure: I make SMBDrop, which works over Tailscale like any SMB app. Tailscale isn't connected to me. It has a free Personal plan as of October 2026; check its site for current terms.

How it works, briefly

Tailscale puts your devices on a private network (a "tailnet"). Each device gets an address starting 100. and, if you turn on MagicDNS, a name. Devices connect to each other directly where they can, with everything encrypted, and nothing on your network is opened to the internet. Only devices signed in to your tailnet can reach the NAS.

Step 1: Install Tailscale on the NAS

Tailscale's documentation lists these routes:

Sign in with the same account you'll use on the iPhone.

Step 2: Install Tailscale on the iPhone

  1. Install Tailscale from the App Store and sign in to the same tailnet.
  2. Allow it to add a VPN configuration when iOS asks.
  3. Turn it on. The NAS should appear in the app's list of devices with its 100.x.y.z address.

Step 3: Stop the NAS's key from expiring

By default, Tailscale asks devices to re-authenticate every so often. For a NAS that sits in a cupboard, open the Tailscale admin console, find the NAS under Machines, and choose Disable key expiry. Otherwise remote access stops working one day while you're away.

Step 4: Test with the Files app

  1. Turn off Wi-Fi on the iPhone so you're on mobile data, which proves you're not on the home network.
  2. With Tailscale on, open Files → Browse → ⋯ → Connect to Server and enter smb://100.x.y.z using the NAS's Tailscale address, or smb:// and its MagicDNS name.
  3. Sign in with the same NAS user as at home.

Step 5: Add the share in SMBDrop

  1. In SMBDrop's Settings, add a share using the NAS's Tailscale address (or MagicDNS name) and the same username and password.
  2. Tap Find Shares, pick the folder, run Test Connection and save. Naming it something like "NAS (remote)" keeps it apart from your home connection.
  3. Send as normal. Transfers carry on in the background, and if the connection drops mid-way, interrupted items wait in the retry queue.

Tip: the Tailscale address also works at home while Tailscale is on, so some people use a single share entry everywhere. Keeping a separate home entry using the local address is slightly faster on your own Wi-Fi.

Option: a subnet router instead of installing on the NAS

If you can't install Tailscale on the NAS itself, install it on another always-on device on the same network (a Raspberry Pi, a Mac mini, a Linux box) and set it up as a subnet router that advertises your home network, for example 192.168.1.0/24. Approve the route in the admin console. Your iPhone can then reach the NAS on its normal local address, like smb://192.168.1.40, from anywhere. Tailscale's documentation covers the exact commands.

What to expect

Alternatives to Tailscale

Any VPN back to your home network works the same way for SMB: WireGuard or OpenVPN on your router (many routers, including FRITZ!Box and UniFi models, have one built in), or your NAS maker's VPN server package. Vendor remote access services such as Synology QuickConnect, myQNAPcloud or UGREENlink are designed for their own apps, not for SMB.

FAQ

Is it safe to open SMB port 445 to the internet?

No. SMB exposed to the internet is widely scanned and attacked. Use a VPN such as Tailscale or WireGuard to reach your NAS from outside instead.

Does Tailscale need port forwarding?

No. Tailscale connects devices without opening ports on your router, and only devices signed in to your tailnet can reach the NAS.

Can I use the iPhone Files app over Tailscale?

Yes. With Tailscale on, use Connect to Server with smb:// and the NAS's Tailscale address or MagicDNS name, then sign in as usual.

Does SMBDrop work over Tailscale?

Yes. Add a share using the NAS's Tailscale address or MagicDNS name and your usual NAS username and password. It works the same as on your home network, at the speed your connection allows.

More guides

Try SMBDrop

Send original photos, videos and files from your iPhone straight to your own SMB share. One purchase, no account, no subscription.

Download SMBDrop on the App Store £2.99 once · no subscription · iOS 17+