# cnMaestro On-Prem/ NSE / Tailscale migration

**URL:** https://community.cambiumnetworks.com/t/cnmaestro-on-prem-nse-tailscale-migration/109074
**Category:** cnMaestro
**Created:** [October 8, 2026, 7:14pm UTC](https://community.cambiumnetworks.com/t/cnmaestro-on-prem-nse-tailscale-migration/109074 "2026-10-08T19:14:31Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![Martin\_Keding](https://d10gw3vjmzyp8.cloudfront.net/user_avatar/community.cambiumnetworks.com/martin_keding/32/12198_2.png) [@Martin\_Keding](https://community.cambiumnetworks.com/u/Martin_Keding)
#### Post date: [October 8, 2026, 7:14pm UTC](https://community.cambiumnetworks.com/t/cnmaestro-on-prem-nse-tailscale-migration/109074/1 "2026-10-08T19:14:31Z")

</div>

I’m been doing some interesting testing with on-prem cnMaestro with multi remote site cambium migration.

Problem: On-Prem cnMaestro running either locally or on AWS, Azure etc and securely connect to multiple customer sites without dealing with firewall or ACL rules.

Test Solution: Tailscale VPN

1. Local cnMaestro On-Prem
  1. Running on Proxmox VM
  2. Install Tailscale Client from the cnMaestro CLI
    1. ex: curl -fsSL [https://tailscale.com/install.sh](https://tailscale.com/install.sh) | sh && sudo tailscale up --auth-key=“yourkey”  
\*\*\* In Tailscale, add a Linux server and generate an install script to paste into the CLI

  3. Install Tailscale Client on remote customer Router
    1. In this case, I used NSE 3000 with **2.5-b2** version
    2. Turned on full GUI features
    3. Turned on Tailscale Remote access with appropriate tailscale key \*\*\* In Tailscale, add a Linux server and generate the script. You, however, only need the Key part for the NSE 3000
    4. Use the tailscale cnMaestro IP or URL address for the server address.

  4. Point your Cambium device cnMaestro URL to the new Tailscale cnMaestro IP or URL
    1. Push template, AP Group Override etc, or manual

  5. Onboard and then delete device from the Cloud.

* * *

I tested this for Tailscale which is a very easy deployment of Wireguard. It should work with any customer router that supports Tailscale. **pfSense** , **OPNsense** and a bunch more. Total time test setup was \< 2 hrs.

It should also work with any Wireguard or for that matter, any other VPN deployment.

Comments?
