- cross-posted to:
- [email protected]
- [email protected]
- cross-posted to:
- [email protected]
- [email protected]
Very solid article. Tailscale is a godsend for my workflow and I’m glad they’re so direct and transparent.
I don’t understand what they do
they provide a mesh vpn.
You can set it up so your home network is an exit node. Meaning any other device you use with Tailscale will look as if it’s coming from your house. This is irrespective of their Internet source.
This let’s people watch Jelly Fin on their phone from anywhere while it’s safely hosted on their home network. Or setup a locally run LLM that can accept calls from anywhere. A synthetic LAN if you will.
Best way to think about it is as an abstraction layer where you can make any computer anywhere talk to another one like they are on the same network without being. You can build networks however you want and it mosly just works. It became popular to do things like tie together multiple machines or networks in datacenrers or home or wherever and let them network together irrespective of the underlying isolation. At home people like to use it to let them access their home network and self hosted services on the go without having to expose anything to the Internet.
Under the hood it’s mostly “just” a VPN with some extra convenience and controls, but it made VPN networking a lot more convenient.
This is a great explanation
So what does this do different from wire guard?
(For simpler use cases) it is basically a control plane above wireguard. The simple connections made use the wireguard protocol, all the other functionalities (and boy there’s a lot) are tailscale.
i’m curious about the other functionalities because in almost every homelab discussion about tailscale there’s somebody bringing up wireguard as a viable alternative
You can do most everything Tailscale does with native Wireguard, it’s just a lot of work to manage any of what Tailscale does beyond the most basic. It’s a lot of convenience on top of Wireguard. If you just need a basic “I want my phone to easily get back to my home network” then I would probably stick to Wireguard (and maybe a GUI on top like wg-easy). If you want to do more complicated stuff, like link multiple sites, mesh routing between multiple networks, sophisticated user access controls, etc, Tailscale starts to be maybe be worthwhile. Or another solution, I personally actually prefer to use Netbird, which is basically similar.
One thing it does do that native Wireguard does not is it includes a relay server, so that if two hosts can’t actually reach each other directly they can still negotiate a direct connection or even fall back to using the relay server to communicate. This is useful if you’re stuck behind something like CGNAT or other networking schemes where hosts may not be able to have a publicly routable IP address.
Tailscale (and Netbird) also offer one extra convenience which is they both have built in reverse proxies that integrate with the VPN network they generate. Strictly speaking that part is separate from Wireguard; you can also do that yourself but it’s rather convenient. This lets you have publicly trusted TLS certificates and stuff for your internal sites and depending on how you use it can replace stuff like Cloudflare tunnels. So you can host sites without port forwarding.
FWIW I primarily use a native wireguard server with wg-easy for most of my VPN needs and I only really use Tailscale (actually, Netbird) for some specialized uses. Mostly replacing Cloudflare tunnels with something I fully control.
Very non exhaustive list (just things I personally use), all of these are configurable (globally or per device/group/tag)
- NAT traversal (no open ports)
- mesh-routing, any device can connect to any device as soon as its added to the tailnet (configurable of course)
- 'magic’DNS, route to any node based on name in your tailnet. E.g.
ping homepcin my terminal connects just like that - ssh auth via tailnet, can just `ssh accountname@homelab to get a shell on my homelab
- taildrop, think localsend over your tailnet
- subnet routing, expose a subnet to any node, e.g. i can ping 192.168.0.123 from any device via my tailscale node running on 192.168.0.50
- exit nodes, route all traffic from a device through another device that advertises itself as an exit node. (Basically classic VPN)
- funnel, expose a service to the internet (haven’t used that one in a while since I got my own domain and reverse proxy etc set up
They offer so much more though
I see. Some of these are possible through wireguard btw. Subnet routing and exit nodes are pretty easy. Funnel would require some firewall rules, so not wireguard but still easy. For SSH using names, and “magic dns”, you could just modify the hosts file. Taildrop is localsend.
But NAT traversal and automatic re-configuration of clients sound like the main benefits here.





