4 ms·
Dynamic DNS with wireguard works great, especially for a small footprint (sounds like you only have one LAN you want to access remotely, not multiple sites). I
by 0x0000000 4y ago
Dynamic DNS with wireguard works great, especially for a small footprint (sounds like you only have one LAN you want to access remotely, not multiple sites). It'll be free, and you won't have any cloud centralized service you're dependant on.
Personally I host both of these services (dynamic DNS client, wireguard server) right on my WAN edge router, but you could also run it on a host (e.g., VM or raspberry pi) inside the LAN.
- unshavedyak 4y agoHow was wireguard setup? My fear with manually setting up wireguard is making some mistake that compromises security. While i like free (selfhosting), my gut says $5/m would be worth having Tailscale manage security for me to ensure it's done right.
- 0x0000000 4y agoI'd say it depends on how many remote clients you plan to have, since you have to manually configure the associated key per client. Unlike a traditional VPN which was just username/password based (from the user perspective, anyway) wireguard is based on keys, which means if you want to get in remotely, you need to have a key which has been configured. If you only have a few clients, this is easy enough to get going. If you have lots of clients, or want to be able to easily add new clients, I can see it becoming cumbersome. As far as setting it up securely, I don't think you're any worse off doing it yourself compared to using tailscale. You can define what networks each client may access. Personally I run wireguard on top of OpnSense, so I also have firewall rules in place to limit what any client can do from my remote-access network towards other parts of my network.