3 ms·
I was once in South Africa and needed to look up my prescriptions in the CVS app. I had lost my pills and needed to show a local pharmacist what I needed. CVS g
by Trumpi 2y ago
I was once in South Africa and needed to look up my prescriptions in the CVS app. I had lost my pills and needed to show a local pharmacist what I needed. CVS geoblocked me. Luckily I had a TailScale exit node running at home, which solved the problem.
- deuschelandian 2y agoWhen I was in Germany - Capital One blocked access to my account unless I confirmed via SMS or tapping my card. Both of which I didn’t have with me. Tunnelling into my home machine I was able to access the account and transfer money I needed. Sure a VPN might be able to do this too but it’s nice being able to exit via a connection you control. I can also watch Plex movies without exposing ports.
- codethief 2y agoAnother data point: I was at Doha airport recently and logged into their public WiFi. Unfortunately, they seemed to be MitM'ing certain connections, mostly to well-known domains. To work around this, I tried setting up Mullvad (which I had used occasionally in the past) but they downgraded Mullvad.net to HTTP, too. Thankfully, I had Tailscale already set up and I could easily book their Mullvad package and add Mullvad as an exit node to my Tailnet. Problem solved.
- HPsquared 2y agoAlternative: OpenVPN server on your router.
- gabeio 2y ago> OpenVPN server on your router. Honestly I would suggest wireguard on your router before openvpn.
- deuschelandian 2y agoThat’s all Tailscale is really.
- metadat 2y agoTailscale even supports OPNSense routers (BSD-based): https://tailscale.com/kb/1097/install-opnsense https://tailscale.com/kb/1097/install-opnsense I'm not sure about the performance yet, however.
- import 2y ago10 times slower than Wireguard
- gabrielhidasy 2y agoCounterpoint: CGNAT
- danudey 2y agoI was on a cruise ship a few weeks ago and realized that, instead of being throttled, a lot of sites were completely blocked. Very irritating. They also do DPI on the cruise ship network so that VPN clients like OpenVPN are blocked regardless of port. Without a laptop handy, I had to use my iPhone to set up a droplet running Ubuntu, then install vray onto it and configure it to run on port 443. vray uses "standard" SSL to tunnel connections, so to DPI it just looks like normal HTTPS traffic and I was able to pass traffic through the firewall when I needed to access something that was blocked. It makes me wonder if TailScale would also bypass their analysis, or if it would be blocked as well. (I didn't abuse this to the detriment of the network, and I did pay for the "streaming package" on sea days when I had a lot of traffic to run)
- abdullahkhalids 2y agoTor Browser should have worked with the right bridge or proxy.
- kdmtctl 2y agoWireguard is easy to block. Some VPN providers do implement an obfuscation layer for it, but Tailscale uses plain WG, so if WG is blocked, you will get no connection. Control plane would still work, though.
- devilbunny 2y agoIntriguingly, my work network (both guest and employee networks) blocks OpenVPN, commercial VPN (Proton I use, plus a couple of others I tried just as an experiment), and Tailscale authentication, but if the device is already authenticated to the tailnet, it will continue to work. Turns out that work uses the same ISP my home does, so perhaps that's part of it, but I have another TS exit node running at my in-laws' house (so I can remotely maintain their network, and so I can get out to the Internet via TS even if my home is down), and they're in another state with a different ISP. I haven't actually tried this when my home service is down, because it's basically never down, but I can easily switch exit nodes when they are both running without hitting the authentication servers again.