4 ms·
I feel like you are answering your own question though... while a VPN hub and spoke can be faster than standard internet (by having peering relationships which
by PLG88 3y ago
I feel like you are answering your own question though... while a VPN hub and spoke can be faster than standard internet (by having peering relationships which are better than the users local telco - i.e., effectively circumvent and improve their standard BGP), you can do this on steroids with a mesh VPN by being able to deploy the relays into many diverse locations so that any user anywhere gets these benefits, even if they change location and access different resources.
Its basically the same but more dynamic and distributed.
- linsomniac 3y agoI'm not sure how I'm answering my own question, or how the question I was replying to is about mesh VPNs at all, I'm replying to "hub and spoke VPNs are slow". I'm just saying: It's not that simple. But, to clarify, when you say "relay node", are you talking VPN traffic relays (DERP nodes in tailscale parlance) or relays to the public Internet (exit nodes in tailscale parlance)? If the former, tailscale goes out of it's way to avoid the DERP servers and instead route traffic directly between the nodes (hence the "mesh"), so it doesn't gain the benefits of hub and spoke that I was speaking about, unless the src/dst nodes can't directly communicate. If the latter, I don't know of any mesh that has smarts about optimizing the reachability to the public Internet and shifting traffic between exit nodes to get better reachability. Can you mention a VPN that has the abilities you are speaking about, because I'm not aware of one, unless you somehow did something like integrating BGP into the exit node selection combined with something like a InterNAP traffic optimization appliance.
- PLG88 3y agoHuh, I did not know that about TS, I thought they were always using the nodes. I was leaning on the former point (i.e., private applications rather than public internet), I know OpenZiti fabric does optimisation across available nodes by doing 'smart routing'. Interesting idea with the exit node and integrated BGP, not a use case ziti is trying to solve today but its a neat idea that is theoretically possible.
- linsomniac 3y agoYep, tailscale definitely will do direct routing between nodes if available and only uses the DERP relays if it can't establish a direct connection. It also uses the DERP nodes to help with NAT-busting, and from what I've heard the tailscale NAT busting is "best in class". I can say that in my situation TS is able to establish direct connections between all my nodes, with maybe a couple exceptions.