On my Mac MIni the Roon core runs with MacOS 10.15.7, so I cannot install Tailscale.
I tried to set up a VPN with the Fritz!Box, which also worked. Unfortunately, I can’t open the port shared by Roon only via this VPN.
Under no circumstances do I want the port to be open to everyone on the Internet.
I don’t want to buy a Roon Nucleus or a new Mini for this purpose.
Are there any other options?
The goal would be that I can only connect to the Roon Server with a connected VPN on the iPhone with Roon ARC.
If you are using a VPN to your router then you do not need to open an external port to the Internet.
ARC should see it without port forwarding enabled as long as TailScale is running on your phone.
Just make sure UPNP is turned off as a method on the ARC settings on Roon
You can setup subnet routing, which works fine for ARC.
I have TailScale running only on my Synology server and that alllows me to access my whole network using subnet routing.
You will find a couple of threads here about it and plenty of information on the TailScale site
Oh dear, I’m afraid that’s too high for me
Then I’ll download the music for the road and the Arc Port will remain closed. I don’t want anyone getting up to mischief and hacking in here.
I also have a Synology NAS…
As I think you know the vpn need to be implemented at both ends.
So Tailscale on either your Mac or another device on your network with subnet routing turned on - and installed on your phone. Tailscale doesn’t require any ports to be opened.
Or the VPN on your fritzbox, with a vpn client on your phone connected to the fritzbox.
You shouldn’t need to open any ports explicitly for ARC used this way (although the Fritzbox is probably using a port to allow the incoming vpn connection).
Ok, so I have installed Tailscale on the NAS (cool) and am connected to it with the iPhone.
Now I have to tell Tailscale that it has to route to the Mini? Roon ARC says “not ready”