as a windoz guy, i fumbled thru that the first time.
need to be careful not to lose control to the remote machine.
might test using a vm or as i do, rent the cheapest virtual machine from hetzner or any such provider.
this could be a very easy way to get ssh only over tailscale
note: the software is beta
An solution could be just to set the sshd to listen on the tailscale interface only.
BUT its risky business since then you cannot even connect using the LAN IP, so I would not really recommend this approach, unless you have other ways of controlling the server.