4 ms·
> Is that a gigantic PITA to implement? Oh heck, you betcha it is I use my own self-hosted Wireguard VPN server. I agree with a lot of what you were saying abo
by codetrotter 2y ago
> Is that a gigantic PITA to implement? Oh heck, you betcha it is
I use my own self-hosted Wireguard VPN server. I agree with a lot of what you were saying about client certificates etc. And I plan to eventually do that sort of thing on some of my services in my own Wireguard VPN too.
But in terms of Tailscale, if you are going to set up all kinds of client certificate things that will take a lot of time and effort, why not self-host Wireguard also?
Setting up a Wireguard server is super simple. The only couple of things that complicate it a tiny bit is opening up a port for it for inbound connections if you host it from your home connection rather than a rented server, and managing the Wireguard public keys that are allowed to connect.
But if you are going to do a whole client certificate setup on top anyway, the work of setting up your own Wireguard VPN is small in comparison.
Unless like OP your ISP has put CGNAT on you.
- stego-tech 2y ago> But in terms of Tailscale, if you are going to set up all kinds of client certificate things that will take a lot of time and effort, why not self-host Wireguard also? Already do! I tried Tailscale initially, but ultimately decided to put in the effort of a proper Wireguard setup. It's how my personal devices always get back to my home LAN, and then exit to the internet; it's also how I make sure every DNS lookup hits the Pi-Hole, for domain blocking wherever I am. I emphatically recommend learning WireGuard (and to a lesser degree, VPN Concentration) when practical and possible. Until then, Tailscale is an excellent product.
- selfhoster 2y ago> Unless like OP your ISP has put CGNAT on you. I run Wireguard on a VPS and route public traffic with it over Wireguard to my home machine. Are you saying my ISP must not be CGNAT or else it wouldn't work?
- aborsy 2y agoHow is this a good solution, when traffic is decrypted in the cloud, all traffic goes through one node, there is no ACL, key distribution, static IP, …? Tailscale addressed those issues.
- selfhoster 2y agoI guess I'm not clear what "when traffic is decrypted in the cloud" means but, here's how it works...public traffic comes in on port 80 to the VPS, Wireguard is configured to route it over the VPN to a VM on my home machine. I control the VPS and the peer receiving the traffic.
- aborsy 2y agoIf the Wireguard server is run on VPS, the encryption is not end to end from the client in public internet to your home. It’s encrypted from client to VPS, then from VPS to home. The VPS sees the traffic inside of tunnel. That’s the first problem.
- codetrotter 2y agoNo. I was talking specifically about the case where you want to host the Wireguard VPN server at home. See earlier in the comment where I said: > opening up a port for it for inbound connections if you host it from your home connection rather than a rented server Although I can see how it might not be clear that in the end where I’m mentioning CGNAT I am still specifically talking about hosting the VPN server from your home connection.
- selfhoster 2y agoThat makes sense, I forgot people also expose a server at home the way I do on the VPS then route to a peer at home. Appreciate the insight.