4 ms·
We just adopted it to consolidate multiple different OpenVPN installations. Why? * The Tailscale clients are dead simple and good quality (but not perfect). O
by mdeeks 4y ago
We just adopted it to consolidate multiple different OpenVPN installations.
Why?
* The Tailscale clients are dead simple and good quality (but not perfect). OpenVPN clients for mac and iOS are pretty bad. Onboarding OpenVPN users was a large document that generated a lot of questions and support issues. Tailscale onboarding is about two minutes for most users and we had nearly no support requests rolling it out widely to our company.
* Tying OpenVPN to Okta is a truly terrible experience. Users would login with their Okta creds and a push would silently go to their devices. If they didn't know to check their phone it would just fail to login. Alternatively you can paste your TOTP code after your password. Yes, really.
* We don't have to manage or debug anything related to LDAP.
* Maintenance on our side is extremely minimal. Just install subnet routers (<10 lines of bash) and put our ACLs in source control.
* We no longer have to tell users to logout and login to another VPN to get to certain resources. We just grant them access and suddenly they can reach what they need. ACLs are amazing and super easy to script, audit, and test.
* Split DNS that actually works on all operating systems. For private domain A, query this resolver (over the wireguard link), for private domain B, query this other resolver.
* I rolled it out as a PoC to all of our major VPCs in a day.
The bad? It's still a young product and is missing features and has some warts.
* Notifications on macOS that you need to relogin are just plain broken (they know and are working on it).
* We're currently battling issues with network resets due to what looks like a client bug when you have lots of users.
* No access to audit logs yet
* You can't restrict people from using exit nodes
* No good way to canary changes to your user population. Any mistake in the UI instantly breaks everyone.
- jaywalk 4y ago> Users would login with their Okta creds and a push would silently go to their devices. If they didn't know to check their phone it would just fail to login. How would users not know to check their phone? They had to specifically set up this MFA method.
- mdeeks 4y agoBecause they didn't specifically set it up. That is just how Okta MFA over LDAP works: https://help.okta.com/en-us/Content/Topics/Directory/LDAP-interface-MFA.htm https://help.okta.com/en-us/Content/Topics/Directory/LDAP-in... Also people just forget. Some people may only need the VPN once per month and in that time they forget about this weird login flow. They just assume they typed their password wrong or that they lost permissions to the VPN or something.
- sconi 4y agocurious what 'dead simple' means re: clients. Do your users still need to login like openvpn, or is it always on?
- mdeeks 4y agoIt's a small icon in the top bar on macOS. You click login, it opens your browser, you Google/Okta auth in your browser using any factor you want (push, totp, yubikey), and you're done. Login literally takes seconds and there is little chance for confusion.
- dx034 4y agoThe last point is a good one, I'm not sure how that makes tailscale usable for big orgs. Imagine a company with 10k+ people using it, I guess you'd need to build a lot of own tooling to avoid breaking the whole corporate network because of a mistake in setting an ACL.
- mdeeks 4y agoI'm somewhat more comfortable with making ACL changes because they have tests I can write in the ACLs themselves, plus I can specifically target users with new ACLs. I'm more concerned about making any DNS changes at all. Or adding/modifying subnet routers.
- yebyen 4y ago> Users would login with their Okta creds and a push would silently go to their devices. If they didn't know to check their phone it would just fail to login. Alternatively you can paste your TOTP code after your password. Yes, really. This sounds exactly like my Cisco (anyconnect) VPN experience from a previous job/life, both before and after Okta was introduced... we think it don't be like it is, but it do.