Live data from Hacker News

Tailscale is pretty useful

blog.6nok.org

241–250 of 419 posts

Re: Tailscale is pretty useful

#242

I previously used WireGuard and for a bit tried just having an SSH tunnel with autossh, but in the end just settled on using Tailscale, because it doesn’t ask me to manually manage the keys and also doesn’t drop around every 30 minutes for a bit and doesn’t need weird hacks to expose ports for my Docked network traffic. That said, what messed with me greatly was the fact that Tailscale seems to have an MTU of 1280 wh…

tldr - wireguard doesn't do per-peer MTU: https://www.wireguard.com/todo/#per-peer-pmtu

Its due to some strangeness in general with tcpip layers that don't forward PMTU discovery ICMP messages. You'll see the same thing in some cell networks, and wireguard is particularly fragile here, because wireguard itself doesn't have a PMTU discovery mechanism.

Or, to be more exact, wireguard currently doesn't have a method to 'bubble up' a PMTU process to the inner wireguard interface from mtu-impacting events in its outer layer.

There's hacks like https://github.com/luizluca/wireguard-ipv6-pmtu/blob/main/wi... that try to handle this by monitoring outer route discovered MTUs and then applying them to wireguard routes.

In applications where I've had to deal with this (wireguard over cellmodem networks), I tool my network setup to poll whatever the cell network mtu happens to be and then set the wireguard MTU appropriately.

This gets really painful though if you think you wanna do something like run a network that really wants a >1280 MTU over tailscale. It's pretty much not doable, and it is, in fact, my biggest gripe with tailscale. Yes, its suboptimal for the 'whole-internet' usecase, but I really do want my wireguard links to be 9000 MTU.

Maybe wireguard will get that in the future, since it is an acknowledged problem. I bet someone in the conjunction of secure networking and HPC spaces could even justify paying the wireguard team to implement it.

Re: Tailscale is pretty useful

#243
post #217

I don’t understand why one would use Tailscale over WireGuard. Is it because it’s easier to setup sort of like how Dropbox was? I’m primarily wary of the rug being pulled out and Tailscale suddenly costing me a lot of money whereas my WireGuard setup seems more stable in the long term. Or is there more to it that I’m missing?

I'm in the same boat. I set up wireguard network on my unraid server at my main house. Then set up a network to network bridge to another unraid server at my other house. My devices (really just my phone) can use either a phone to LAN connection or a complete tunneled connection to my server, from anywhere. My devices at either of my houses behave as if they're on the same network.

It wasn't very intuitive to set up but it took less than an hour and it has worked flawlessly for years. Unraid definitely made it a bit easier. Seems Tailscale almost completely solves that complexity for the initial setup and each additional device.

Re: Tailscale is pretty useful

#244

I'm curious to hear well-informed reasons from this crowd for why we can trust Tailscale given the non-self-hosted part of the architecture? Does it come down to Tailnet locks [1], not worrying that Tailscale will be compromised, not worrying that your home network is worth compromising, or something else? [1]: https://tailscale.com/kb/1226/tailnet-lock

For me, Tailscale is worth the trouble of not maintaining my own Wireguard setup. Everything on my home network is set up as if it were public-facing.

> Everything on my home network is set up as if it were public-facing.

That's Wireguard, I have the same, just Wireguard + VPS, everything I want available that is. I don't put every PC on my home network on the VPN, I could though, pretty easily.

Re: Tailscale is pretty useful

#245
post #132

And it's Canadian. Cool. We have a policy now that doesn't allow us to bring in new services from US companies.

Kind of:

  Schedule A
  Tailscale Entity
  Existing customer accounts as of September 2, 2024 Tailscale Inc., a Canadian business corporation
  New customer accounts on or after September 3, 2024 Tailscale US Inc., a Delaware corporation
My account is associated with Tailscale US Inc., unfortunately.

https://tailscale.com/terms

Re: Tailscale is pretty useful

#246
post #96

Earlier quoted context omitted.

Wireguard?

Wireguard doesn't do NAT traversal on its own, which is, IMHO, the killer feature of Tailscale.

I wasn't sure and still am not what your statement means, I checked Google, their AI tool offered this:

"Yes, WireGuard does support NAT traversal, though it doesn't handle it natively; it relies on techniques like UDP hole punching to establish connections between peers behind NATs."

That makes no sense to me, I have my peers talking to each other on the Wireguard VPN behind my ISP NAT. I do have one UDP port open on the VPS that they all talk to. Is that what you mean by, "Wireguard doesn't do NAT traversal on its own, which is, IMHO, the killer feature of Tailscale."?

If so, how does not having to open one UDP port which can't really be detected anyway, justify having all your traffic controlled by a third party through servers (I forget what Tailscale called them) you don't own?

Re: Tailscale is pretty useful

#247

I'm curious to hear well-informed reasons from this crowd for why we can trust Tailscale given the non-self-hosted part of the architecture? Does it come down to Tailnet locks [1], not worrying that Tailscale will be compromised, not worrying that your home network is worth compromising, or something else? [1]: https://tailscale.com/kb/1226/tailnet-lock

For me, Tailscale is worth the trouble of not maintaining my own Wireguard setup. Everything on my home network is set up as if it were public-facing.

This baffles me. What's to maintain? I've been running wireguard for years and never had to do anything except scan a QR code when I get a new phone.

By "as if it were public facing" I assume you mean locked down as much as possible using either router or host-based firewall rules?

Re: Tailscale is pretty useful

#248

Tailscale is one of my favorite companies. They're clearly on to something. Here's a great post by their CTO explaining a lot of the motivation and vision behind it: https://crawshaw.io/blog/remembering-the-lan IMO the main outstanding questions/concerns are: * Is the VPN model really the way to go? If someone gets their hands on one of your Tailscale nodes, they can access every service on your tailnet, which are li…

  > set up a private network between all your ~~Google-signed-in~~ devices.
I've been doing something like this as a fun side project. Idea is to get everything to pass through piholes and have both clear and VPN exit nodes. So then I can send some pis to people and we can create an internal network to share things like files, movies, streaming services, whatever. It also can increase security, especially making it easier for people like my parents when I need to fix their computers and I can just block malware for them, to some degree at least. It's also been very useful debugging stuff in my home network while I'm out somewhere else. And I can access any of my anywhere. I'm out traveling? Still got all my movies and stuff.

One big issue is Apple, who doesn't seem to respect DNS and VPNs, especially local network access... the other aspect is that it makes some ssh automation annoying because they will change things, such as getting the name of the current ssid (wtf?!). So I can't just make a conditional in my config to go through TS instead of local network based on that

Re: Tailscale is pretty useful

#249
I'm thinking about exposing some services outside of my LAN, and wondering whether it would be better to go with Tailscale or Cloudflare Tunnel. [1]. At a high-level both solutions seems pretty similar, with a client service running on the machine you want to share.

My sense is that tailscale makes sense for a more locked-down service that is not accessible to the general public (although they do have a way to open up access to the world [4], it felt like more of a temporary thing than a permanent solution when I was looking into it).

And Cloudflare is more for exposing a service to the world, with support for a custom domain name, DDoS protection and other IP blocking feaures, etc. Cloudflare does have a "Zero Trust Network Access" product that I think might offer similar functionality to Tailscale, but honestly pretty hard to tell what it does from their website or how hard it would be to set up.

They both have free tiers that are pretty generous for "homelab" use cases. [2][3]

Does that sound pretty much correct? Are Tailscale and Cloudflare competitors with a lot of overlapping functionality? Or are they mostly distinct products serving different use cases/markets?

[1] https://developers.cloudflare.com/cloudflare-one/connections...

[2] https://tailscale.com/pricing

[3] https://www.cloudflare.com/plans/

[4] https://tailscale.com/kb/1223/funnel

Post reply on HN