3 ms·
I think this is what https://tailscale.com/ https://tailscale.com/ is trying to solve :) (I'm in no way affiliated, but stumbled upon it on twitter a few weeks
by katnegermis 7y ago
I think this is what https://tailscale.com/ https://tailscale.com/ is trying to solve :)
(I'm in no way affiliated, but stumbled upon it on twitter a few weeks ago)
- tw04 7y agoTailscale looks like it's creating a mesh network - he's not asking for end-users to have VPN connections between each other (what Tailscale is doing). He's asking for a central server where he can retrieve/update/manage end-user keys, likely: because helpdesk. You could in theory do this with any number of the existing team password managers, but I think he'd like integration directly to wireguard. Edit: care to reply rather than just downvote? All of their documentation and examples state exactly what I'm saying. They're turning all the devices into endpoints and creating a mesh - he doesn't want users bypassing his SINGLE VPN endpoint into the company or talking directly to each other based on his description. He wants Cisco Anyconnect - only wireguard.
- api 7y agoWe get this question about ZeroTier from time to time and the answer is the same: set rules (or ACLs in Tailscale) so as to allow only traffic to/from what you want users to communicate with.
- tw04 7y agoSure - you can block access but the fundamental problem you're appearing to target isn't what he's after. Heck to even get the user-auth he's asking for you have to use tailscale + some third party app whether that's okta or azure or google. I'm not saying he can't sort-of accomplish what he's trying to do but it very much feels like you've got a hammer and think his screw looks like a nail.
- basch 7y agoYou can use ACLs to control what clients can connect to. https://news.ycombinator.com/item?id=22665589 https://news.ycombinator.com/item?id=22665589 It doesnt look like a nail/hammer/screw at all. Tailscale isnt configured how he wants out of the box, but using SSO to control access isnt a massively complex hurdle. Anyone with Office 365 will be able to use their Office account to authenticate, which is basically Cloud Active Directory, and way better (if its something you have) than maintaining a separate username/password database for the VPN. ACLs and a relay node are a good fit for the request. https://tailscale.com/kb/1019/install-subnets https://tailscale.com/kb/1019/install-subnets Cloud SSO might be a deal breaker, but it doesnt make the solution the wrong class of solution.