4 ms·
Genuinely curious: is Tailscale actually providing any values to this use case beyond what you get from a raw Wiregaurd exit node with port forwarding instead o
by mightyham 6mo ago
Genuinely curious: is Tailscale actually providing any values to this use case beyond what you get from a raw Wiregaurd exit node with port forwarding instead of Tailscale's NAT traversal? I've never used Tailscale, but I have a Wiregaurd setup on my home server for the same purpose as described in the article, and I've never had any issues with it.
Edit:
Noticed some sibling comments asking effectively the same thing as me. I've been meaning to write a blog post covering the basic networking knowledge needed to DIY with just Wiregaurd. My impression is that many people don't realize just how easy it is or don't have the requisite background information.
- nighthawk454 6mo agoIt has plenty of useful control plane features out of the box. Nothing much you _couldn’t_ do yourself but you don’t have to. Or with Headscale as the self-hosted open-source version
- f33d5173 6mo agoDynamic IP addresses.
- ectospheno 6mo agoUpdate your DNS when it changes. Pretty trivial.
- f33d5173 6mo agoYeah I tried writing a script for that, but at a certain point using an off the shelf tool that does everything is easier.
- pkulak 6mo agoIf you're just doing hub-and-spoke anyway, yeah, you can do it yourself. I did for years. But holy smokes, is it a PITA to manually copy keys around to devices; especially when they might not even be yours. I have my Tailscale account hooked up to my self-hosted identity server and now it's just a matter of logging in on whatever device I want to be on the network. Plus, I have the option of spinning up a random EC2 box whenever I want and instantly joining it to the network with basically no fuss.
- mightyham 6mo agoI have a phone and laptop; those are my only two "mobile" devices that I might ever use to access my home network remotely. I set them up once, it took a few minutes, and I won't have to do it again unless I replace one of them. I can completely understand using Tailscale for enterprise networks, but it seems very overengineered for my personal VPN needs.
- ddxv 6mo agoHow do you handle home network IP changes?
- andreasha 6mo agoDynamic DNS
- lostlogin 6mo agoNot OP, but a static IP was about US$10 as a one off payment. It’s really nice.
- barelysapient 6mo agoCloudflare tunnels
- genewitch 6mo agoi had this issue, with an even more wild set of restrictions, so i used Caddy to "output its own access log" and i had a cron job on any server at home that would hit that caddy server with a pre-defined key, so like `http://caddyserver.example.com/q?iamwebserver2j http://caddyserver.example.com/q?iamwebserver2j` for one server and "q?iamVOIP" for another. https://github.com/genewitch/opensource/blob/master/caddy_get-log.py https://github.com/genewitch/opensource/blob/master/caddy_ge... https://github.com/genewitch/opensource/blob/master/show_own_logs-Caddyfile https://github.com/genewitch/opensource/blob/master/show_own... And now i have bi-directional IP exposure. it's cute because you can't tell if you just drive by, it doesn't look like it does anything. you have to refresh to see your IP, which is a little obfuscation. if you care about security, not sure what to tell you. use port knocking. Please note: this doesn't require installing anything on any remote, just a cron job to curl a specific URL (arbitrary URL). I used it to find the IP to ssh on remote radio servers (like allstar, d-star) for maintenance, for example.
- twelvedogs 6mo agowith wireguard i found that pretty almost every public wifi blocked it and even a lot of private internet connections at my friends houses did as well if my mobile provider blocked it as well it would have been completely useless probably depends on your location a lot though
- tristor 6mo ago> Genuinely curious: is Tailscale actually providing any values to this use case beyond what you get from a raw Wiregaurd exit node with port forwarding instead of Tailscale's NAT traversal? Yes, but I guess it depends on how much of an adoption barrier/pain you want to deal with. Tailscale's control plane is dead simple and they ship apps on basically every platform so its easy to onboard mobile devices in addition to anything else. I'm a literal former network engineer with over two decades of experience, and I tried Tailscale randomly one of the first few times it popped on HN and stuck with it precisely because of how easy it was and how trivial it was to verify the security of my tunnels. Doing this manually is definitely possible on devices you control, but it's not a fun time, and Tailscale is dead simple.