5 ms·
It's a usability thing, IMO. Historically you had enterprise-grade VPNs that cost a lot of money, or OpenVPN. Both ran over IPSec or SSL, and neither were supe
by 0x0000000 4y ago
It's a usability thing, IMO.
Historically you had enterprise-grade VPNs that cost a lot of money, or OpenVPN. Both ran over IPSec or SSL, and neither were super straightforward to config/maintain, nor were they particularly performant.
Then came wireguard, which is awesome, but wireguard is just a transport. It doesn't have all the UX niceties built on top of it, like registering clients or generating / distributing keys. Tailscale does a lot of that lifting for you, so you can easily and quickly get a working VPN, at a low cost, with good performance.
Personally I manage wireguard myself, but I also self-host my own VMs, storage server, applications, etc.
Tailscale is like taking your car in for an oil change instead of doing it yourself, plenty of people find that worth it.
- teaearlgraycold 4y agoWhat does everyone use it for?
- TheFlyingFish 4y agoNot GP, and I can only answer for myself, but: Personally, I use it to connect my home devices as if they were always together on the same LAN, even when they're not. E.g. Raspberry Pi, home NAS, "home" server that's actually in a different physical location, etc. All accessible anywhere at any time, even (say) from my laptop in a moving vehicle, without connections dropping even when my IP changes. It really is like magic. At work, we use it so that remote employees can access locally-hosted applications, office NAS, etc. ACLs make it easy to employ the principle of least privilege, so that having a route into the office LAN doesn't immediately mean any and every device is compromised.
- TkTech 4y agoI have it on all my personal and family servers and devices. I use it so that for both myself and my family all our internal stuff (unraid network shares, jellyfin, homepages, photo backups, etc, etc) "just works" for the less technical members of the family even when they're not at home. It seamlessly detects when the peer is local so it doesn't route out to the internet and back, has an easy ACL to segment things (wife's phone doesn't need access to dd-wrt), and a bunch of other features. We've been able to do this with existing VPNs for a long, long time, but tailscale is by far the most painless offering I've ever used and I migrated away from OpenVPN completely.
- pyinstallwoes 4y agoCan you use it like a VLAN for segmenting devices? I have eero’s and a firewalla but since my eero’s don’t support tagged vlan traffic I can’t segment my devices as much as I’d like to.
- mbesto 4y ago(not an expert here) but my understanding is: sort of. I believe the biggest difference is that VLAN operates at Layer 2 and Wireguard works at Layer 3.
- pyinstallwoes 4y agoSo anything already on the same LAN wouldn’t be able to be segmented; if my theory is aligned?
- yakkers 4y ago>It seamlessly detects when the peer is local so it doesn't route out to the internet and back One of my use cases for Tailscale was connectivity between my primary NAS and an off-site NAS I use for backups. Being able to bring my NAS to the same site/network I had set-up the off-site NAS and just have things work over the LAN without reconfiguring anything was a wonderful surprise. (Yes, I’m aware I could save some overhead by reconfiguring but looking at the network traffic monitor I was happy enough with the throughput I got though Tailscale’s LAN routing)
- gog 4y agoI have a Tailscale client running on my NAS at home, this allows me to access stuff at home when I am not there, mostly my Home Assistant instance but sometimes the files on the NAS as well. Without Tailscale I would need a way to publish my routers current WAN address somehow (probably with DDNS), create a port forward rule on my ISPs router/modem and then setup a VPN server to listen to those connections. Not to mention that the current ISP doesn't even allow me to login to their modem and setup port forwarding.
- influx 4y agoI use it on my EC2 dev box and my home network, allowing me to block ssh on all the firewalls, yet ssh freely between all of them.
- mbesto 4y agoA few use case: - I have a SOHO setup at home: several PCs/ my work laptop, raspberry pi, synology and ubiquiti. It means I can access ubiquiti console and synology via network as opposed to be some janky proxy that those company's provide. - taildrop is great for sending screenshots and files from my phone to (can't wait until they let me send URLs/links/txt like KDEConnect) - I also have a raspberry pi setup in an ABNB in another country. When I'm traveling I can use my house as a proxy for US based services and the reverse is true - if I want my browsing to look like my IP address in another country I can.
- dgacmu 4y agoThe thing that sold me on it was managing remote (and I mean remote - like in a field in west Virginia with solar + cell) nodes. We started with using manually provisioned wireguard tunnels, but wg isn't great at things like failing over. Plus, our core infrastructure is on a slightly dynamic IP and we didn't want to route image upload through GCP. Tailscale made this problem go away . And then we got hooked on it for all developer access, having GitHub actions be able to push into our deployment, etc. It's pretty magical.
- youainti 4y agoI use it to link together my research computer, laptop, and home-servers to give me access while traveling or working from home.
- raihansaputra 4y agoThrowing in my usecases: - Running a Jupyterlab instance on my desktop PC (WSL) and use it through my laptop from anywhere. Can also be accessible through phone/tablet if needed - Simple routing of other services my PC exposes (Jellyfin for now) - Access dev services running on my laptop through my phone without checking IP all the time - Good replacement for AirDrop using Taildrop file sharing. AirDrop errors out if I try to use it on a "public" network (ex: University Wi-Fi)
- KleinPoes 4y agoSeedbox access without exposing it to the wider web. Managing personal devices. One day I had to go to the office and only then did I notice my keepass hadn't synced in months. My home PC was sleeping so I SSH'd to my Openwrt box, got the MAC for my PC and used etherwake to start it. From there I used RDP to login and get an updated password. All from my phone.