My ISP uses CG NAT which is stopping me from reaching my internal network, so I’m thinking about using Tailscale to allow me to connect to my server and hence to my internal network.
But I’m not very comfortable giving 100% access to Tailscale to my internal network, so I was thinking if I could limit it only to what it requires to connect to the internet and to a wireguard service running in the same container. This would in turn connect to a wireguard server in the container’s host and provide me with full network access.
I know, as long as they have a service running in the server, even if inside a container, they can always be able to access the host. But even do I would feel safer if at least tried to contain it.
Does anyone know if this is possible? And can it be done through Docker Compose?


Just setup wireguard on your server, add masquerading and ip forwarding. That single wireguard in, will give you full access to your lan
He can’t open ports because of the ISPs setup.
Edit NVM, read up on it. Seems like you have to run PCP protocal on IP4 to bypass thr CGNAT issues.
You can use any open port and port forward at the router, or is CG NAT only 80