4 ms·
While I appreciate the hard work that went in to this, it seems like it's solving the wrong problem. My home and work computers already have DNS addresses and
by X-Cubed 5y ago
While I appreciate the hard work that went in to this, it seems like it's solving the wrong problem.
My home and work computers already have DNS addresses and valid TLS certificates for those addresses. It would be nice if Tailscale DNS supported resolving those domain names, so that when I'm at home I can enter in the normal DNS address of my work machine and route the request over Tailscale. Instead, peers on Tailscale get a <host-name>.<email-address>.beta.tailscale.net address (or with this new feature <host-name>.<random-animal>-<random-animal>.ts.net), which doesn't match any existing domain names already configured on the peer.
They do support Split DNS configuration, which almost works for this, but it resolves all domain names with a particular suffix, not just the names used by peers on the network. As it resolves domain names to the native IP address of the host, not the Tailscale IP address, it only makes sense to be used with subnet nodes that expose an entire subnet to the VPN.
I just want host.corp.com to access a work machine (or host.home.org to access a home machine), no matter where I am, rather than having to use different names depending on whether the VPN is connected or not.
- hiciu 5y agohow about using always-on vpn, even in home / work? It works fine most of the time.