4 ms·
I have several WG peers(phones, laptop, tablet) hosted up on a US residential symmetric fiber, and a couple of travel routers that can connect to it as well (th
by kennethrc 2y ago
I have several WG peers(phones, laptop, tablet) hosted up on a US residential symmetric fiber, and a couple of travel routers that can connect to it as well (this was helpful when going overseas so I could get to US TV providers, among other things).
Since I've done that work already, would TailScale buy me anything?
- Yeri 2y agoThey offer some extra's like MagicDNS, go/, ssh auth, etc But no, if you don't need that and if you've done the setup part, and you're just looking at the VPN part, you wouldn't gain anything. Tailscale magically works, recovers well from crashes/network changes (I've had a few issues here with WG native client), manages your keys (and rotation of), creates point to point tunnels (which is just confusing via a plain text config with several devices).
- deleted 2y ago[deleted]
- mynegation 2y agoDo you ever find yourself in a situation where all NAT traversal strategies fail and your only way is through DERP server. Unless your in your own DERP, this is one of the situations where Tailscale might be useful.
- kennethrc 2y agoI've got my WG's server endpoint open to the world; unless I'm misunderstanding something this won't be an issue for me. That being said, none of my WG peers really ever need to talk to each other (but the way I have it set up the remote IP subnet does route within it, so I guess they could).
- aborsy 2y agoIf outgoing udp is blocked, Wireguard can not connect.
- aborsy 2y agoEase of installation, SSO, peer to peer tunnels (whereas in VPN access server, the server sees inside of the tunnel), no open ports, DNS, private dns server, switching easily between different exit nodes (or no exit node), subnet router, ACL (like cloud firewall), sending files from one device to another, TLS certificate for each device, fall back to TCP/relays when udp is not available. Tailscale is very good if you have to manage many users, and if you want to share nodes with others. Cool tech! If you install Tailscale, then you don’t need to think of connectivity for other applications: media servers, file sync, RDP, etc. Otherwise, for each of them, you have to think of networking all over (port forwarding, relays, UPnP, …). Cons: You have to install an agent running as root on all devices, trust the coordination server to some extent, much bigger attack surface!