In the last post we stood up SearXNG on your NAS and pointed your agent at it, so the query stops leaking to Google and Bing. There's one catch I flagged at the end: that box lives on your LAN. The moment you close the laptop and open it again at a café, a client's office, or a hotel, http://192.168.1.50:8080 resolves to nothing. Your agent's private search only works at home.
This post fixes that. By the end, the same private search follows you onto any network on earth — and you won't have opened a single port to do it.
Like the last one, it comes in two halves: the do-it-yourself steps, and a copy-paste prompt at the bottom you can hand to your agent to reconfigure itself.
The wrong way to fix it (don't)
The obvious move is to forward port 8080 on your router so http://your-home-ip:8080 works from anywhere. Don't. An open SearXNG on the public internet gets found by bots within hours, hammered, and either abused as an open proxy or rate-limited into uselessness by the very engines you're trying to reach. You'd also be exposing an admin surface that was only ever meant for you. The whole point of the last post was to stop handing your search to strangers — punching a hole in your firewall gives it to a worse class of stranger.
What you actually want is a private network that spans your devices no matter where they physically are. That's Tailscale.
What Tailscale is
Tailscale is a mesh VPN built on WireGuard. You install it on each device and log in with the same account; every device then joins one private network — your tailnet — and gets a stable address in the 100.x range plus a friendly MagicDNS name like nas.tailXXXX.ts.net.
The key part: connections go device-to-device, encrypted end-to-end with WireGuard. Tailscale's servers only broker the introduction — they hand your two devices each other's keys and help them punch through NAT, then get out of the way. Your NAS never listens on the public internet. From your laptop's point of view, your home NAS is just there, on the same private network, whether you're one room away or one continent away.
Why this is the right tool
- No open ports. Nothing on your NAS is reachable from the public internet. There's no attack surface to scan, because there's no listening service exposed.
- Works from any network. Café, hotel, tethered off your phone, a client's guest Wi-Fi — the tailnet stitches your devices together regardless of the network underneath.
- Stable addressing. MagicDNS gives your NAS a name that never changes, even when its LAN IP or your public IP does. You configure the agent once.
- Encrypted end-to-end. On an untrusted network, the query and the results ride the WireGuard tunnel. Whoever runs the Wi-Fi sees encrypted noise — not what you're researching, not what you're building.
- Free for personal use, and about the least painful VPN you'll ever set up. No certificates to manage, no static IP, no router config.
What it gives your agent
The immediate win is that your agent's SEARXNG_URL stops being a LAN address and becomes a tailnet name that resolves from anywhere:
http://192.168.1.50:8080 → http://nas.tailXXXX.ts.net:8080
Configure that once and private search just works — at home, at the café, on the train. The agent doesn't know or care which network you're on.
But search is only the first thing you'll run over it. Once the tailnet exists, it's the natural fabric for everything your agent talks to that you'd rather keep off the public internet:
- A local model — Ollama or an OpenAI-compatible gateway on your GPU box — reachable at
http://gpu.tailXXXX.ts.net:11434from your travelling laptop, so private inference follows you too. - Self-hosted MCP servers — a filesystem bridge, a database tool, an internal API — exposed to the agent over the tailnet instead of the internet.
- A build box or database the agent needs to reach during a task.
One encrypted network, every home service your agent uses, nothing exposed publicly. Search is just the first tenant.
1. Install Tailscale on the NAS
Install it on the same host that runs your SearXNG container. On a Linux box or most NAS shells:
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up
tailscale up prints a URL — open it, log in, and the machine joins your tailnet. On a Synology or UGREEN NAS you can instead install the Tailscale package from the app center (or run the official container); either way the result is the same: the NAS shows up in your tailnet.
You do not need to change your SearXNG docker-compose.yml. It keeps listening on 8080 as before — the difference is that the only network that can now reach it from outside your LAN is your tailnet. limiter: false stays fine, because the only clients are your own devices. Just don't also forward 8080 on your router — that would undo the whole point.
2. Install Tailscale on your laptop
This is the machine your agent runs on. Install the app (macOS, Windows, or the same curl … | sh on Linux) and log in with the same account. That shared login is what puts both machines on one tailnet — there's nothing to pair by hand.
Confirm they can see each other:
tailscale status
You'll get a list of your devices with their 100.x addresses. Ping the NAS by name to prove the tunnel works:
tailscale ping nas.tailXXXX.ts.net
3. Turn on MagicDNS and grab the name
In the Tailscale admin console, enable MagicDNS. Now every device is reachable by name — nas.tailXXXX.ts.net — instead of a bare 100.x IP. Your exact tailnet suffix (tailXXXX) is shown right there in the console. Prefer the name over the IP: the IP is stable, but the name is the thing you'll actually remember and it survives a rebuild.
4. Point the agent at the tailnet address
Same two agents as last time, one value changing: swap the LAN IP for the MagicDNS name.
Claude Code — re-add the MCP server with the new URL:
claude mcp remove searxng
claude mcp add searxng -e SEARXNG_URL=http://nas.tailXXXX.ts.net:8080 -- npx -y mcp-searxng
Codex — edit the env line in ~/.codex/config.toml:
[mcp_servers.searxng]
command = "npx"
args = ["-y", "mcp-searxng"]
env = { SEARXNG_URL = "http://nas.tailXXXX.ts.net:8080" }
Restart the agent so it reloads the config, exactly as before.
5. Verify from a foreign network
This is the step that proves it. Get off your home Wi-Fi — tether the laptop to your phone's hotspot — and hit the JSON API over the tailnet:
curl "http://nas.tailXXXX.ts.net:8080/search?q=test&format=json"
A wall of JSON from a network that isn't yours means the tunnel is live and your agent's search now works anywhere. Ask the agent to "search the web for X" while tethered and watch it route through your NAS from a coffee shop.
Two optional hardening steps for later: ACLs in the admin console let you say which devices may reach the NAS (so a future phone or a shared device can't), and tailscale serve puts a real HTTPS certificate in front of the box if you'd rather talk to it over https. Neither is required to get search working — reach for them once this is load-bearing, not before.
The copy-paste version
Already have Tailscale installed on both machines and MagicDNS on? Hand this to the agent on the machine you want to reconfigure and let it repoint itself.
Repoint my SearXNG MCP server from its LAN address to my Tailscale MagicDNS name so search works from any network. My NAS is nas.tailXXXX.ts.net (change to your real tailnet name).
1. First verify reachability: run `tailscale status` to confirm this machine is on the tailnet, then `curl "http://nas.tailXXXX.ts.net:8080/search?q=test&format=json"` and confirm it returns JSON. Stop and tell me if it doesn't.
2. If this is Claude Code: run `claude mcp remove searxng`, then `claude mcp add searxng -e SEARXNG_URL=http://nas.tailXXXX.ts.net:8080 -- npx -y mcp-searxng`.
3. If this is Codex: in ~/.codex/config.toml, update the [mcp_servers.searxng] env so SEARXNG_URL=http://nas.tailXXXX.ts.net:8080. Leave the rest of the block unchanged.
4. Tell me exactly what changed and remind me to restart the agent so it reloads.
Show me each command before running it. Do not open any router ports or expose SearXNG publicly.
That's the whole thing. Your private search box stopped being a thing that only works at your desk. It's on your tailnet now — so the next time your agent looks something up from a hotel room, the query still goes through a box with your name on it, over a tunnel nobody else can read.