3 ms·
There is a lot of truth to this. To provide some further context on differences with a comparison of Tailscale and OpenZiti. - Tailscale is a great VPN, super
by PLG88 4y ago
There is a lot of truth to this. To provide some further context on differences with a comparison of Tailscale and OpenZiti.
- Tailscale is a great VPN, super easy to use. Being based on wireguard means, it differs from OpenZiti (note, I work on the project too).
- Tailscale has proprietary features to make it easier to use (e.g., DERP). OpenZiti includes those as part of open source.
- Wireguard/TS will allow peers to join the same network segment, so if I want to restrict access, I have to start using firewalls to block ports or implement segmentation. This can be surmised as WG being 'default-open' whereas OpenZiti is 'default-closed' with outbound tunnels, least privilege, micro-segmentation, and attribute-based access.
- Wireguard/TS really cares about "connecting machines" and not so much about connecting "services". This includes operating at the host level. While OpenZiti can do this too, it also has SDKs which can be embedded in an application. That's useful for developers or creating 'clientless' solutions, which we are actively working on.
OpenZiti uses the Windows TUN (WinTun) that the Wireguard project made as (at least) part of our Windows tunneler. Thanks, Wireguard!