zlacker

[parent] [thread] 8 comments
1. rane+(OP)[view] [source] 2025-01-05 14:13:57
What do you need Tailscale for? Why isn't Wireguard enough?
replies(3): >>ErneX+J >>_heimd+L >>HomeDe+82
2. ErneX+J[view] [source] 2025-01-05 14:20:23
>>rane+(OP)
I think it’s easier to manage, plus you get ACL functionality. You can use Headscale for the control server and tailscale clients.
3. _heimd+L[view] [source] 2025-01-05 14:20:26
>>rane+(OP)
There's nothing wrong with wireguard at all if you already have the hosting service available. The core value add for Tailscale is that they provide/host the service coordinating your wireguard network.

If I'm not mistaken, there's a self-hosted alternative that let's you run the core of Tailscale's service yourself if you're interested in managing wireguard.

replies(2): >>azthec+I6 >>bennyt+Bi
4. HomeDe+82[view] [source] 2025-01-05 14:32:43
>>rane+(OP)
The author mentioned closing their VPN port so people would stop trying to break in, but this also cut off the author's access.

Tailscale allows you to connect to your home network without opening a port to allow incoming connections.

◧◩
5. azthec+I6[view] [source] [discussion] 2025-01-05 15:11:38
>>_heimd+L
I believe you are referring to Headscale https://github.com/juanfont/headscale
◧◩
6. bennyt+Bi[view] [source] [discussion] 2025-01-05 16:46:19
>>_heimd+L
What kind of "hosting service" are you referring to? Just run wireguard on the home server, or your router, and that's it. No more infra required.
replies(1): >>_heimd+hB
◧◩◪
7. _heimd+hB[view] [source] [discussion] 2025-01-05 19:12:10
>>bennyt+Bi
I meant to say hosted service there, I.e. running a wireguard server to negotiate the VPN connections.

The main reason I haven't jumped into hosting wireguard rather than using Tailscale is mainly because I reach for Tailscale to avoid exposing my home server to the public internet.

replies(1): >>rane+4U
◧◩◪◨
8. rane+4U[view] [source] [discussion] 2025-01-05 21:43:54
>>_heimd+hB
What could be the issue with exposing WireGuard at a random port to the public internet?

It works over UDP so it doesn't even send any acknowledgement or error response to unauthenticated or non-handshake packets.

replies(1): >>_heimd+G21
◧◩◪◨⬒
9. _heimd+G21[view] [source] [discussion] 2025-01-05 23:07:28
>>rane+4U
There may not be an issue at all, I'm just gun shy about opening any ports publicly. I don't do networking often and have never focused on it enough to feel confident in my setup and maintenance.
[go to top]