Exit Nodes | Tailscale Explained

Поділитися
Вставка
  • Опубліковано 25 гру 2024

КОМЕНТАРІ • 27

  • @ashishjulliageneric
    @ashishjulliageneric Місяць тому +10

    Something is off here as the official cli docs says "--exit-node-allow-lan-access Allow the client node access to its own LAN while connected to an exit node. Defaults to not allowing access while connected to an exit node." this contradicts to what you stated at 5:00 and more specifically at 5:09

    • @Tailscale
      @Tailscale  Місяць тому +11

      Thank you for pointing this out! You are quite correct and this was an error in the video.
      To clarify. "Allow LAN access" permits the client system to access other clients on the current LAN when enabled.
      An easy test is to flip the exit node ON and ping a host in your current LAN at the same time. Watch the ping times change as you change the "allow LAN access" setting. In my case, due to subnet routing in my Tailscale network I did not notice the subtle difference because I can already route this LAN subnet from anywhere - thanks to Tailscale!
      I'll pin this comment to help others, and once again thanks for pointing this out.

  • @handle_your_set
    @handle_your_set 4 дні тому

    I really have to thank you, and applaud you for the way you present this content. Your ability to plainly lay out, and stack the details, without muddling them up is brilliant. Your guidance has been a masterclass in zero trust self hosting. Once again, thank you sir.

  • @wtcxdm
    @wtcxdm Місяць тому +11

    Really appreciate the quality of Tailscsale's documentation and tutorial videos. And the use of Apple TV is just too cool.

    • @Dominik-K
      @Dominik-K Місяць тому

      I have to agree, the quality is just amazing. I can't recommend Tailscale enough

  • @dwhiskerburn6729
    @dwhiskerburn6729 Місяць тому +6

    I appreciate the clear and well thought out instructions with a little humor for fun.

  • @kevyben6772
    @kevyben6772 Місяць тому +20

    Tailscale should add a feature to automatically switch exit note when the main one you're using is down so you would not be stuck with internet not working.

    • @fakebizPrez
      @fakebizPrez Місяць тому +1

      Or when it completely nukes your OPNsense config

  • @toddzilla
    @toddzilla Місяць тому +1

    Completely unrelated but so cool that you’re in NC, I’m in Charlotte.

  • @weholmes5315
    @weholmes5315 Місяць тому +1

    Superb explanation. As always! Thank you, sir.

  • @minituff
    @minituff 9 днів тому +1

    What happens if you have multiple exit nodes? If I access the internet, which node would I be router through?

  • @6LordMortus9
    @6LordMortus9 Місяць тому

    This video might bring me back to Tailscale.. I was having issues with connectivity and I believe that lan option might have been the cause.

  • @trafficant3
    @trafficant3 Місяць тому

    Thanks for these videos. Tailscale for pc should have a setting like the mobile app where you are able to tell which apps should run exit node or not. Anyways, great app! I'm using it a lot to connect to my devices in China

    • @Tailscale
      @Tailscale  Місяць тому +3

      App connectors allow tailnet wide split tunneling. A future video will cover this.

  • @defyiant
    @defyiant Місяць тому +1

    Thanks for teaching us. I have deployed tailscale on my unraid server and on my pf sense router with the ability to use both as a exit node. If wanting to access my home network away from the house what is the best exit node destination?

    • @Tailscale
      @Tailscale  Місяць тому +1

      Pick whichever you feel like! It doesn’t matter one bit. They’ll both show as you exiting from your home network.

  • @jawata58
    @jawata58 23 дні тому

    great video! thanks. I wonder if I can use tailscale with TP-LINK Mesh WIFI system like the X50 or X75? J.

  • @biro3000
    @biro3000 8 днів тому

    i have 3 windows machines in 3 diffrent countries, i activate exit nodes on 2 of them? which exit node will use the 3rd machine? considering the simplistic design of the whole concept which is amazing, what was the idea behind the implementation of the "acl"s cumbersomeness? i know i can disconnect from the "tailnet" on a pc from the tray icon, but why can't i disable the virtual adapter itself? what made you think this concept is accepable?

  • @kevyben6772
    @kevyben6772 Місяць тому +2

    It would be great if you can also add subnet routing to Android.

  • @Anu_was_here
    @Anu_was_here Місяць тому

    Hey! Many thanks for your amazing videos.
    If i may suggest a new video: "Using Tailscale in a Coolify Server (locally or VPS)"
    With Coolify Caddy support and many configurations, i believe it's one of the amazing combos - especially having mixed access services (things public, others via tailscale VPN only).

  • @GabrielFrisan
    @GabrielFrisan Місяць тому +1

    thanks!

  • @kevinoconnor6570
    @kevinoconnor6570 Місяць тому +1

    Did I understand correctly that Tailscale is unencrypted when used as an overlay network?

    • @l0gic23
      @l0gic23 Місяць тому +1

      You did understand incorrectly. The traffic between nodes/devices is encrypted... What I think he is saying g is that the http(s) traffic between a device and a website does not transverse the tailnet by default which means that traffic does not benefit and is not slowed down by transversing the tailbet before hitting the internet. That external traffic is direct (off tailnet) by default... Tailnet traffic is end to end encrypted but your web traffic is secured with https or is plain text (but a more direct connection with no overhead).
      Hope the above helped

  • @Wahinies
    @Wahinies Місяць тому

    That Pi2b that wasnt quite powerful enough for reliable streaming became an awesome Pihole/unbound/chrony server, now I will have to throw on TS ❤

  • @maikmueller
    @maikmueller Місяць тому

    And you can even use an Echo Show 15 as exit node.

    • @kevyben6772
      @kevyben6772 Місяць тому

      @@maikmueller it's Android so of course most Amazon products are.

  • @iam_muni_baa
    @iam_muni_baa Місяць тому

    Add a support for Android rooted devices because we missing the VPN.
    Because tailscale using VPN, as i seen some people build a tailscale without VPN in rooted device but it's not official so it's great if it's comes from tailscale.