@badnetmask Not everything has to have access to everything else within a tailnet, you can write an ACL to permit host A to only access port X on host B for example