Hello again.
I've gone through your steps outlined in this post now for LAN. I've made my own network name .crypt and added *.crypt to Adguard and pointed it at the IP address of Nginx.
I've then gone and mapped my local services in Nginx. So radarr.crypt sonarr.crypt plex.crypt etc and mapped them to ports.
Now what I enjoyed was that I had to map Adguard to forward to Nginx, but in Nginx I can use the IP address of anything on my network, not just on the host.
So it's map Adguard in DNS rewrites to Nginx IP, then map the IP:ports in Proxy Hosts in Nginx.
Now when I use my Tailscale exit node (that I have from Home Assistant) I can use those addresses outside the house.
I have noticed it only works for the .crypt domains, and not .local despite being set up as well. I guess because .local is a special address it is harder to map to Tailscale.
Anyway, it's working for me after following what you've done, I just did less in Tailscale because of the exit node