Tailscale: NETWORKING MAGIC!

Поділитися
Вставка
  • Опубліковано 17 гру 2024

КОМЕНТАРІ • 364

  • @Level1Techs
    @Level1Techs  Місяць тому +51

    Download here! tailscale.com/download
    Read our article summary here: forum.level1techs.com/t/tailscale-interviewing-the-ceo-and-co-creator-avery-pennarun/220053
    Thanks for watching! ~ Amber

    • @nannnanaa
      @nannnanaa Місяць тому +1

      have you heard of nostr

  • @callumhaynes1384
    @callumhaynes1384 Місяць тому +191

    Use Tailscale for my home server, no ports to open, no complex configuration. Just fire it up and log in and it works, for free! Outstanding piece of software

  • @pendent23
    @pendent23 Місяць тому +61

    Speaking as a network engineer who’s been in the industry for over a decade the “How NAT traversal works” article is genuinely one of the best pieces of technical writing I have ever read

  • @LAWRENCESYSTEMS
    @LAWRENCESYSTEMS Місяць тому +97

    Great interview, I think I have been using Tailscale about as long as Wendell has and I have referenced that "How NAT traversal works" many times as a great way to better understand the complexity behind making Tailscale seem like "magic"

  • @joeykeilholz925
    @joeykeilholz925 Місяць тому +79

    "Every time you're going to the cloud, you're paying rent to somebody."
    Perfect expression of how I've felt about cloud services for so long.

    • @jfbeam
      @jfbeam 29 днів тому +3

      Or you and your data are the product.

  • @RifterDask
    @RifterDask Місяць тому +34

    Tailscale + Nextcloud is an actual lifechanging combination. You will feel like a wizard.

    • @gg-gn3re
      @gg-gn3re 9 днів тому

      there is probably no open source software worse than nextcloud. It is easily one of if not the most janky and worst softwares I've seen in 30 years of open source. I'm glad louis rossmanns new 13 hour video goes over how bad it is and sets up actual good software to replace all of what nextcloud does badly (everything)

  • @octtburr
    @octtburr Місяць тому +22

    I just added a Tailscale exit node to my homelab yesterday, and it has become hands down my most useful tool of all my systems. Great tool, can never go back!

    • @Mike_v_E
      @Mike_v_E Місяць тому +4

      I enabled my Unraid server as an Exit Node yesterday, changed the Tailscale DNS to my Adguard port, and now I have adblocking even when im not at home!

  • @steensadolin8749
    @steensadolin8749 Місяць тому +99

    Have been avoiding Tailscale for a while since I thought it sounded too good to be true. I finally caved in early this year and tried it… and yes it just works. Love it.

    • @manitoba-op4jx
      @manitoba-op4jx Місяць тому +6

      headscale.

    • @zeighy
      @zeighy Місяць тому

      I was avoiding it for a bit as well, since it sounded more complicated than I probably want to manage so I was using zerotier for a while. I have both where I can now, and I'm starting to slowly switch over since I find that tailscale actually functions more predictably for me and the coordination of the configuration works well. Also, Zerotier has been pushing for heavier monetization now... so I'm moving stuff off it to reduce the node count.

    • @39zack
      @39zack 29 днів тому

      @@manitoba-op4jx sure, but you are giving up a lot of what makes tailscale just work tho

    • @gg-gn3re
      @gg-gn3re 9 днів тому

      @@manitoba-op4jx yep way better, thanks. I'll still gladly avoid tailscale now

  • @martixy2
    @martixy2 Місяць тому +23

    Ok, I didn't understand tailscale before this, but now I'm sold.

    • @pohra663
      @pohra663 Місяць тому +2

      Same here. I hadn't been able to get my head around Tailscale before but this video made everything click. I'm just a personal user so they won't make much money from me right now, but at least I can be an evangelist now. 😀

    • @xxxxxx-wq2rd
      @xxxxxx-wq2rd 24 дні тому

      but what if the tailscale company decides you are a political enemy or something like that?

    • @mackado
      @mackado 13 днів тому

      ​@@xxxxxx-wq2rd None of your traffic goes through their servers, they basically just work as a sign-post so your devices know where to find each other. They can block your login but none of your data should be compromised.

    • @williamp6800
      @williamp6800 13 днів тому

      @@xxxxxx-wq2rd if you aren’t a political enemy, explain it to them. With luck your problem will be resolved.
      If you are a political enemy, you should have been using headscale, the open source version that you can self host.

  • @Maxjoker98
    @Maxjoker98 Місяць тому +31

    I've actually used Tailscale before! Tailscale is awesome if you just want to connect computers.
    But it's kind of sad that we need something like Tailscale to replace IPv4 instead of having just IPv6 and E2E encryption by default everywhere.

    • @TooLazyToFail
      @TooLazyToFail 17 днів тому +1

      Even if we had the IPv6/E2EE world, managing those connections would need something simple that would be adequate for most users, because most users don't want to create ACLs for all the devices in their lives and maintain them. Tailscale basically is that solution, but for the world we actually live in.

  • @zeppelins4ever
    @zeppelins4ever Місяць тому +28

    This is some insane timing, I've been spending all day reading the TailScale documentation! Then I open UA-cam and this is the very first thing I see! I think the universe is telling me something.

    • @chaemelion
      @chaemelion Місяць тому +1

      Or the algorithm is. 😉

    • @zeppelins4ever
      @zeppelins4ever Місяць тому

      @chaemelion I thought so at first, but I was on a work PC reading the docs completely detached from my phone with UA-cam, from a different IP, location, and account. If it was the algorithm, they're doing some damn clever data association.

    • @chaemelion
      @chaemelion Місяць тому

      @@zeppelins4ever I don't doubt they do exactly that. I've had some very similar experiences. I wouldn't put it past Google to analyze visits to a website associated with an advertisement client of theirs, and bump that content suggestion a few points for related public IPs by common current or historical clients, by location (again, by IP or otherwise), etc..

    • @MelroyvandenBerg
      @MelroyvandenBerg Місяць тому +1

      Yes to pay 10 dollars per month to them.

    • @zeppelins4ever
      @zeppelins4ever Місяць тому

      @@MelroyvandenBerg Or, now hear me out, I use the free version.

  • @TooLazyToFail
    @TooLazyToFail 17 днів тому +1

    I'm halfway into this video and I've been able to set up Tailscale on my laptop, PC, and UnRAID server. This is frickin' WILD. Enumerating services across my network and make the Tailscale plugin on UnRAID a one-stop-shop from anywhere in the world? Holy crap!
    Thank you.

  • @karaloop9544
    @karaloop9544 Місяць тому +2

    Damn, that intro statement was on point!

  • @monano
    @monano 24 дні тому +2

    Love this! Tailscale is so amazing! It’s made my life so much easier as an amateur homelabber and a person with an interest in networking.

  • @pieterrossouw8596
    @pieterrossouw8596 Місяць тому +7

    Tailscale has been great for years - set it up on my dad's machine as an exit node and my homelab also as an exit node. If I need to change something on his network (e.g. change his inverter parameters), I just activate his machine as a exit node and do what I need to. Easily run nightly backups of all his most important files e.g. .docx, .pptx, .xlsx, .pdf etc. on his machine to my homelab. I wish the ACLS were more easily editable by non-technical people through the web GUI but maybe one day that'll be added. Think if the video streaming platforms get more aggressive in enforcing family accounts must all live together, tailscale would be my go-to solution for that too.

  • @aelliixx
    @aelliixx 8 днів тому

    I recently set up Tailscale for my friend's home network. We installed it, clicked a few buttons on the admin page, and then were confused what to do next. Tried connecting to the network out of curiosity and it just worked. We both stood up in shock literally gasping at the magic.

  • @bosstowndynamics5488
    @bosstowndynamics5488 Місяць тому +63

    I use and enjoy Tailscale but I would like to see a bit of discussion of alternatives, Netbird, Nebula, ZeroTier etc. It just kind of bothers me that using Tailscale means either trusting their infrastructure for key exchange, or running Headscale, the latter of which doesn't seem to really be considered stable and has unclear security properties (whereas at least Netbird and Nebula let you host the direct enterprise code to run your own backend rather than a reverse engineered host, even if Headscale is written with Tailscale's blessing it's still reverse engineered)

    • @includenull
      @includenull Місяць тому +2

      I'm currently exploring Headscale vs Nebula myself. Oh and now Netmaker, that one looks interesting.

    • @JelleRevyn
      @JelleRevyn Місяць тому

      I tried Netbird first but I couldn't get it to work, switched to tailscale so easy. I'm using it with the unraid plugin. So even if my server reboots for whatever reason, I do not need to hope my docker container starts up correctly.

    • @seanwright4976
      @seanwright4976 Місяць тому +1

      One of the devs putting in a bunch of work on headscale, is employed by tailscale.
      They've got a nice article on why it didn't make sense to just release the headend source as-is.

    • @peegee101
      @peegee101 Місяць тому

      Add twingate to the list 😊

    • @includenull
      @includenull Місяць тому

      @@peegee101 Twingate is closed source and not self-hostable right? Only known because of paid sponsorships to a bunch of UA-camrs.

  • @RichardRuffUK
    @RichardRuffUK 13 днів тому

    Genuinely one of the most game-changing pieces of software I've come across in a long time. I travel a lot and need to access resources that have IP allowlists. Now I can just Tailscale into a connection that's already whitelisted with zero drama. Love it - just set it up to access home assistant away from home too!

  • @thorhojhus
    @thorhojhus Місяць тому +1

    Used tailscale for a couple of years and it just works. What a wonderful product!

  • @MrTubeuser12
    @MrTubeuser12 Місяць тому +1

    I literally downloaded and set up tailscale on my Linux and Android device while I was watching this video. Amazing ! will be definitely sharing this video.

  • @sarjannarwan6896
    @sarjannarwan6896 Місяць тому +2

    Been using it for a while and found out my company uses it internally on some teams too. Really nice way of providing a lot of customisability while having the kind of UX where it’s easy to use for personal use.

  • @svenstubes
    @svenstubes Місяць тому +2

    arguably the best piece of software in my network

  • @carpentb17
    @carpentb17 Місяць тому +1

    Tailscale user here. I love it. Great Work.

  • @NotFab
    @NotFab Місяць тому +20

    Tailscale is an awesome product that has already revolutionized networking everywhere I know, simply because it's so simple to use.

  • @Raintiger88
    @Raintiger88 Місяць тому +2

    I've only been using tailscale for a few months and it's awesome. No matter what I tried, I could never get wireguard to work and it was the only thing that got past the double nat and my ISPs cg-nat. Exit node for me is my pfsense router so I can see my server, cameras - everything on my home network. Yes, it just works and yes, just 5 minutes to set up.

  • @Marc.Google
    @Marc.Google Місяць тому +2

    Fellow Canadian 👋🏼 🇨🇦 thanks for the great chat and amazing software!

  • @user-hk3ej4hk7m
    @user-hk3ej4hk7m Місяць тому +8

    It'd be cool if you could interview the ZeroTier guys, they did most of this stuff before wireguard was a thing. The result is more of an integrated whole rather than a control layer on top of wireguard. Besides that their all-in-one binary hosts all functionality (controller, root servers and end nodes) besides the web portal. The "controller" or "control server" in tailscale is closed source, so if it wasn't for the headscale project we'd be stuck with tailscale as the single provider and authority over what and who enters the network.

    • @chromerims
      @chromerims Місяць тому

      👍Emphasizing, "It'd be cool if you could interview the ZeroTier guys, they did most of this stuff before wireguard was a thing. The result is more of an integrated whole rather than a control layer on top of wireguard. Besides that their all-in-one binary hosts all functionality (controller, root servers and end nodes) besides the web portal."

    • @chromerims
      @chromerims Місяць тому

      👍Emphasizing, "The "controller" or "control server" in tailscale is closed source, so if it wasn't for the headscale project we'd be stuck with tailscale as the single provider and authority over what and who enters the network."

  • @kevinstratton1677
    @kevinstratton1677 27 днів тому

    Tailscale is such a fantastic piece of software. I cannot imagine my life without it anymore. Shout out to the Tailscale team!

  • @greggmacdonald9644
    @greggmacdonald9644 Місяць тому +1

    Great video! Thank you, Wendell, I had no idea this existed, but it looks really useful!

  • @greyvlad
    @greyvlad 25 днів тому

    Great opening!

  • @phildegruy9295
    @phildegruy9295 Місяць тому

    Great interview. I installed Tailscale on a Truenas server and on our desktops, laptops and use it everyday including when traveling. We also use the exit node when needed while traveling, makes life easier.

  • @RetroTinkerer
    @RetroTinkerer 28 днів тому

    Awesome, thanks Wendell for sharing I will look into it always wanted to have access to my media library when I'm on the road but I didn't want to open a big hole in my firewall, the fact that I will be able have and give access and or backup files and pictures securely without uploading it to the cloud is a huge plus!

  • @scotthoffman8682
    @scotthoffman8682 Місяць тому +10

    Wendel, please add a video on using an exit node with Ring cameras! The statement that everyone can see my footage freaked me out more than a little bit!! 😮

    • @zaneandre6387
      @zaneandre6387 19 днів тому

      De-Ring yourself for ultimate security

    • @scotthoffman8682
      @scotthoffman8682 19 днів тому

      ​@@zaneandre6387In time I will but for now I would love to know what Wendell meant!

  • @xelu01
    @xelu01 Місяць тому +15

    It's an incredible application, love using it

  • @EidolonKaos
    @EidolonKaos Місяць тому +17

    The notion of wireless being faster than wired seems alien to me. Hooking up a 25ft patch cable to an ethernet over power adapter is leagues better than trying to use wifi through three walls.

    • @lordsamnon
      @lordsamnon Місяць тому +1

      I think it's a reference to USB and how slowly all phone manufacturers are updating to the latest standards.
      You can't easily connect a patch cable to a phone..

    • @ryan.crosby
      @ryan.crosby Місяць тому +3

      I don't think it's an accurate statement, given that the technology used to improve wireless transmission speeds can be analogously applied to wired copper connections that have significantly less signal to noise.

    • @jfbeam
      @jfbeam 29 днів тому +1

      Wired technology will ALWAYS be faster than wireless. At any given point in time, any random collection of hardware could have faster and slower bits. eg. my laptop has USB3, 1G ethernet, and 11n wireless. a current generation iPhone has 11ac/ax wifi. That fancy new $$$$ Wifi 6E/7 router/accesspoint has 10G wired ports.

    • @williamp6800
      @williamp6800 13 днів тому

      @@lordsamnon a Lightning to Ethernet adapter has been around for years. Got one in my troubleshooting bag. Equivalent USB C to Ethernet adapters are available from Amazon and other places.
      I think he was making a direct reference to the fact that even with their transition from Lightning to USB C, Apple is still introducing new models that only support USB 2. Only the “Pro” model phones support USB 3.

    • @iota-co7369
      @iota-co7369 11 днів тому

      You’re all wrong.

  • @bopal93
    @bopal93 Місяць тому

    Alright, convinced me to setup Tailscale within my network infrastructure. I have been putting it off for so long . I will be installing next week.

  • @meco
    @meco 29 днів тому +1

    I’ve replaced all our VPN infrastructure with Tailscale at work. It just works so seamless and the enduser doesn’t have to worry about manually connecting when needing a connection to local infrastructure

  • @D_Chm
    @D_Chm Місяць тому

    Looking forward to more Tailscale tutorials, thanks for the great work you do!

  • @MattHoyle95
    @MattHoyle95 Місяць тому +1

    This sounds absolutely incredible, I hate how most home labers have to rely so heavily on cloud flare. I cant wait to download and play around!

  • @jarkkoaitti287
    @jarkkoaitti287 Місяць тому +4

    So how does the user count work? What does a user mean in this licensing model? Do you have to log in somewhere for it to work?

  • @handle_your_set
    @handle_your_set Місяць тому

    Before I even heard the phrase “it just works”, it’s exactly how I described it to a friend. It really is an elegant solution to a lot of problems. If it isn’t magic, it’s surely sorcery.

    • @jfbeam
      @jfbeam 29 днів тому

      So do almost every cloud service... I take a picture on one phone (iPhone), and by the time walk across the house to pick up the other phone, it'll also have that picture.

  • @T313COmun1s7
    @T313COmun1s7 Місяць тому +1

    I have not even watched the video yet. I just have to say that I love and use WireGuard, and I LOVE!!! Tailscale.

  • @MK--Ultra
    @MK--Ultra 4 дні тому

    This randomly appeared in my feed and wow it is like magic. Minutes to access my truenas scale server at work from home

  • @grimtagnbag
    @grimtagnbag Місяць тому

    I love it. Been using it for years. OMG note you are talking about it. So awesome

  • @theminer49erz
    @theminer49erz 23 дні тому

    Wow!! That's awesome!!!! I can think of so many ways to use that! I have actually been wanting something just like this!

  • @DC13333
    @DC13333 20 днів тому

    Tailscale makes homelabbing simple for the normal person. Thanks Avery.

  • @solidreactor
    @solidreactor Місяць тому +10

    Ok this all sounds good... BUT... why do I need a google, microsoft or apple account to use tailscale? I thought the purpose was to being able to avoid these companies!
    I have recently put an effort of de-googleing my digital life and thinking Tailscale would be a nice addition, was I wrong?

    • @nickdonathan
      @nickdonathan Місяць тому +1

      I may be wrong but I think headscale is what you’re after.

    • @keyboard_toucher
      @keyboard_toucher Місяць тому

      yeah i did a U-turn as soon as i saw that lol

    • @dayvie9517
      @dayvie9517 Місяць тому

      just use wireguard frfr

  • @jenesuispasbavard
    @jenesuispasbavard 26 днів тому

    I love Tailscale! Never having to open ports and expose my home network to the internet is super handy.

  • @bencrockett1422
    @bencrockett1422 Місяць тому

    This was a very helpful explanation of Tailscale.

  • @Elkemper
    @Elkemper Місяць тому

    Hey Wendell, great guest!
    I hope this interview was conducted via p2p connection.

  • @chun-li-tq6lf
    @chun-li-tq6lf Місяць тому +5

    I wanted to setup wireguard btn my home pc n laptop. But port forwarding was an issue. Will try it today💯

  • @TheAutumnNetwork
    @TheAutumnNetwork 12 днів тому

    Tailscale really is magical stuff. This guy is brilliant for real.

  • @Lambretta_G
    @Lambretta_G Місяць тому +6

    How is this not just another VPN? Genuine question. The word "VPN" is not mentioned even once in the interview but their site's title is "Best VPN Service for Secure Networks"

    • @Level1Techs
      @Level1Techs  Місяць тому +4

      full mesh. it's like a VPN but each point tries to talk directly to each other point unlike a VPN where all points connect centrally

    • @Loanshark753
      @Loanshark753 Місяць тому

      @Level1Techs would it be possible to use IPSec to encrypt connections at the internet level instead of using TLS on the transport level like HTTPS does so that P2P encryption is not reliant on the transfer protocol.

    • @EidolonKaos
      @EidolonKaos Місяць тому

      ​@@Loanshark753 it would probably be better to check the official site instead of youtube comments

    • @SteenLarsen
      @SteenLarsen Місяць тому

      ​@Level1Techs sorry but you can also setup a VPN as a full mesh.

    • @saminieminen9966
      @saminieminen9966 Місяць тому

      @@Loanshark753thats how IPsec VPN works for 99% conpanies today. Issues not Limited to: needs static IP’s, crypto is expensive after crossing 1Gb speeds, fiddly to configure, requires always open ports on firewalls (means vulnerabilities bound to happen) and does not handle NAT nicely.

  • @AJAYRAJ-tm4jk
    @AJAYRAJ-tm4jk Місяць тому

    I am from a remote area where the ISP uses private address for connectivity and Static IP cost money
    In a situation where I can't use DDNS or static IP
    Tailscale is a saviour for me
    Now I can do literally anything that requires me to be in person or static IP or DDNS
    There are no port forwarding no firewall and stuff
    Just install it and login in
    It takes about 5 mins to set it up
    It's really magical

  • @TheScorpio32
    @TheScorpio32 24 дні тому

    Been using tailscale since the early days, its great!

  • @joshhardin666
    @joshhardin666 Місяць тому +5

    This seems like an awesome idea, but how do we run it locally? relying on tailscale's admin interface and key exchange is just yet one more cloud provider. is this FOSS? can we spin it up on our own servers?

  • @pokerindia2091
    @pokerindia2091 Місяць тому +1

    looking very promising. im in.

  • @TheoneandonlyRAH
    @TheoneandonlyRAH Місяць тому +1

    YESSSSS I HAVEN'T EVEN LISTENED TO IT YET BUT I LOVE TAILSCALE

  • @pah1of284
    @pah1of284 Місяць тому

    I use Tailscale every day - greatest thing ever!

  • @seansingh4421
    @seansingh4421 Місяць тому

    Tailscale is extremely friendly towards small businesses. Like they can’t fully replace having static IPv4 addresses but they not only come very close they do so without any of the security issues surrounding static IPv4.

  • @cuatropantalones
    @cuatropantalones 20 днів тому

    Great interview! I would be super interested in hearing about the camera setup.

  • @HeieiX
    @HeieiX 28 днів тому

    I use a different mesh network and it’s one of the best, most game changing pieces of tech in my network. It’s almost like having a static ip for all your devices but it ignores things like DHCP and dynamic WAN addresses just by being smarter about how it connects.

  • @comandercrypto1318
    @comandercrypto1318 Місяць тому

    Definitely going to have to check this out for my new network overhaul.

  • @PacketChasers-k7y
    @PacketChasers-k7y 27 днів тому

    Finally someone whos speaking my language!

  • @xdevs23
    @xdevs23 29 днів тому

    I use Tailscale to access my Home Assistant, Jellyfin and TrueNAS instance from outside my home. Additionally, I can also access other devices via subnet routing. This is useful when I need to access my router configuration or build server.

  • @owenness6146
    @owenness6146 Місяць тому +5

    Feels like Distracted Boyfriend meme. Holding Wireguard's hand while looking at Tailscale.

    • @simon7719
      @simon7719 Місяць тому +1

      Tailscale uses wireguard internally. Wireguard is the core building block, Tailscale is a full-featured service.

  • @EricInTheNet
    @EricInTheNet Місяць тому

    I love that WebVM integrated Tailscale to allow an in-browser Linux to be part of your own network as a full host 🤯

  • @AndyShrestha
    @AndyShrestha Місяць тому

    This is amazing technology making our life easy. ❤

  • @ados8064
    @ados8064 Місяць тому +4

    Tailscale is just a fancy beginner friendly VPN but still cool tech.

  • @LeonLionHeart
    @LeonLionHeart Місяць тому +1

    Currently using it on my Synology!

  • @Peterowsky
    @Peterowsky Місяць тому +8

    So this guy is basically doing a "do not cite the deep magic to me, witch. I was there when it was written" to the big tech companies when it comes to basic networking and FTP.

    • @Peterowsky
      @Peterowsky Місяць тому +2

      Reminds me of Hamachi about 15 years ago

    • @jfbeam
      @jfbeam 29 днів тому

      He might've been there when it was created, but he's certainly painting with a giant FUD brush to justify his narrative. FTP works just as well today as it did decades ago. ('tho you'll have to install client and server software yourself; no OS installs that stuff out-of-the-box anymore, and most browsers no longer support ftp urls.) "File Server" is also just as cumbersome as it has always been. Tailscale is just one more bit of application "Magic" to install, and figure out how to configure.

  • @HaartieeTRUE
    @HaartieeTRUE Місяць тому +1

    I have a laptop 'server' running a large number of services using proxmox with tailscale for networking. Besides having to have a VPN connection and remembering to shut it down while i'm on the same LAN back home to reduce latency and bottlenecks (which already barely exist) it works as if everything is just a public website instead of * my own jerryrigged laptop masquarading as a server, behind a flimsy 1gbit router *

  • @RobertHouse101
    @RobertHouse101 Місяць тому

    Great ad. Just installed on my android. Thanks.

  • @VanyaKokorev
    @VanyaKokorev 29 днів тому

    Main risk using Tailscale: they sometimes ban nodes based on geoip (like all Russian nodes recently). So an only safe way is to install open-source reimplementation of their control server called headscale, it is compatible with their clients

  • @tenekevi
    @tenekevi 26 днів тому

    I'm using Tailscale. I've set up multiple tailnets for other people. I'm also expecting a rug-pull at some point and try not to set up stuff in a way that can't be done without tailscale, even if it requires a bit more elbow grease.

  • @ghangj
    @ghangj Місяць тому +1

    The amount of automation i have been able to leverage with Tailscale being the highway is the best. Also SSH keys handling is a breeze

  • @inputoutput1126
    @inputoutput1126 Місяць тому +4

    Real Truman Show opening

  • @EasyMoney322
    @EasyMoney322 23 дні тому

    Airdrop might not work if there are multiple APs or devices connected to different frequencies (2.4, 5, 6Ghz), or if one devices is wireless and the other is wired. Due to TTL=1, if there is no client-to-client multicast forwarding turned on (which is off by default on many devices, including Mikrotik)

  • @PHiAX
    @PHiAX Місяць тому +1

    This sounds good, but then you make yourself dependent on some cloud service for the key exchange part. Which I don't like. If since learned about headscale which enables that part as self-hosted. So that's even nicer.

  • @jamesdk5417
    @jamesdk5417 Місяць тому

    Wow, this sounds amazing. Thanks.

  • @skypickle29
    @skypickle29 Місяць тому

    How does tailscale get around the NAT? Synology for example will connect your laptop to your NAS over the net but that requires software for each device to talk to a synology server first. The NAS and the laptop independently talk to the synology server. The synology server then looks at the packets and pulls the port info and allows the laptop to talk to the NAS by crafting an IP packet with the correct incoming/outgoing ports to get around the NAT. Does tailscale open new ports as well through UPNP? [EDIT] OOPS, I should have waited till 14:39 but there were no details.

  • @BigHeadClan
    @BigHeadClan Місяць тому +3

    We have some Tailscale nodes setup for one of my clients in place of a formal IPSec configuration, we've had ISPs change static IP addresses not configure the Router correctly and in some cases took days or weeks to notice because of how it routes traffic and just kept working. We've also have it running as a backup interface for some of our backup solutions for our clients so we can remotely access them without the need for more hardware.
    That said it does introduced some latency (only about 15-20ms though) and at least in some of the cases we have it running it will randomly inject its own DNS entries into the Domain Controller and cause other routing issues although that admittedly could just be a misconfiguration on our part.
    Its a slick piece of software, honestly for home labs it would be without question the best way to access your own personal enviroment.

  • @Yavoreks
    @Yavoreks Місяць тому +3

    This is like a breath of fresh air, thanks so much for making this and sharing. Kudos o7

  • @nikstalwart
    @nikstalwart Місяць тому +5

    So you're being snide over paying $10/2TB/month and being locked into Apple's ecosystem, but paying $5/User/month to be locked into Tailschale's ecosystem is alright?
    I don't get the logic here.
    I should mention Headscale - it's a community-driven coordination server. It isn't as full-featured as the primary server, but at least there's less vendor lockin there.

    • @xlrsecurity
      @xlrsecurity 26 днів тому

      Isn't there a free tier in Tailscale that allows 3 users & 100 devices? How is that locked in?
      If you need more than three users, you're probably working in an organization that can afford to pay a monthly fee.

    • @nikstalwart
      @nikstalwart 24 дні тому

      @@xlrsecurity Price and vendor lockin are two independent concepts. Vendor lock-in is where it difficult to switch vendors and you are forced to stick with one vendor for legacy reasons. In the case of relying on Tailscale's coordination server, you have no choice to migrate (easily, that is) to another provider if something happens with Tailscale. A few weeks ago there was a big bruhaha over Tailscale geoblocking some country or another. Now, if you're using Headscale, you could theoretically dump the database and recreate your own coordination server or keep using your local version of headscale or somehting else. If you have access to the database you could probably transition everyone to using Innernet or Nebula or something of the sort. If you use Tailscale for IAM and firewalls and everything else, all of your cyber eggs are in one vendor-locked basket and you cannot easily move. Going back to Stallman, there is a difference between Free Beer and Free Software.

  • @maxheadrom3088
    @maxheadrom3088 Місяць тому

    Great idea, nice interview! Path Dependency is an important concept to learn - I first heard of it watching Political Science lectures. One example is the difference between streaming music and video: why can't every video streaming service stream everything like it happens with music? Because of legal decisions and legislation from a long time ago ...

    • @SteenLarsen
      @SteenLarsen Місяць тому

      Yes it's called policy. It is also policy which decides that most devices on the Internet cannot connect everywhere. It's for security policy reasons to stop everyone from being hacked all the time.

  • @kellymoses8566
    @kellymoses8566 Місяць тому +2

    TailScale can be used on every server and/or VM to create a ZeroTrust environment.

    • @andrewjohnston359
      @andrewjohnston359 25 днів тому

      I think you might have things the wrong way round? The zero trust model assumes that you can't trust any device or any user without some kind of authentication. So the public internet/WAN is (and always has been) a ZeroTrust environment...BUT...the ZeroTrust model is actually trying to tackle the old school idea of zones that are trusted and untrusted, such as a a local LAN behind a firewall/NAT. ZeroTrust says that even a LAN should not be inherently trusted. So if you were thinking that tailscale somehow can move you from a ZeroTrust envrionment to a Trust environment then you're setting yourself up for a wide open attack vector, where one compromised machine on the "Trusted" network can wreak havoc - as it's just blindly trusted and given access to potentially jump across to other machines via file shares or through an unpatched exploit as the computers local firewalls are often disabled due to them being on a 'trusted' network. Long story short, trust no user or device anywhere ever. How practical this is to implement and manage is another story for sure...security and convenience/usability are always a point of tension and a juggling act

  • @andreidoimetri
    @andreidoimetri Місяць тому +1

    brilliant content

  • @praetorxyn
    @praetorxyn Місяць тому +1

    One thing I'd like is for on my phone, the client that keeps Nextcloud autosynced and whatever else I decide to go through Tailscale to reach my network but regular stuff not to, and with minimal battery impact. Can Tailscale do this? At the moment I've just got my own domain and am open port that forwards to my reverse proxy.

    • @JaydenLitolff
      @JaydenLitolff Місяць тому +4

      If you don't point your phone to an exit node, what you want is already the default tailscale behaviour. Your traffic to the wider Internet still goes straight out without going through a tunnel, but there is a second subnet you can reach that magically has all of your devices on it.
      If you want to access devices in your home network that don't have tailscale and don't want to turn on an exit node (full tunnel ie normal self hosted vpn) you can set up your server to be a subnet router.
      My subnet router means that my nas (that doesn't have tailscale on it) is always accessible to me by it's local ip no matter what network I'm on

    • @praetorxyn
      @praetorxyn Місяць тому

      @ Thanks for the info. I’m meaning to migrate my setup from being on my NAS to being on a MS-01 Proxmox VM / LXC and using the NAS shares over NFS for storage, while migrating from swag to traefik. I guess I’ll look into using Tailscale while I’m at it.

  • @justbob8294
    @justbob8294 Місяць тому +1

    i just setup up tailscale on my truenas last month and i wish i would have done it sooner.

  • @pedrotoledo9070
    @pedrotoledo9070 Місяць тому

    Thank you Tailscale!

  • @Maxjoker98
    @Maxjoker98 Місяць тому +5

    I don't like the notion of "You don't need to secure your Wordpress instance because it's behind a VPN". There are many security scenarios where this will still get you in the end. Tailscale might help prevent access from the entire internet, but not to all other people. Imagine if you had an ex-employee that left the company, but still has login credentials. Or one of your client computers is compromised, giving whoever access to your vulnerable Wordpress instance. You really can't get away from updating often.

    • @andrewjohnston359
      @andrewjohnston359 25 днів тому

      spot on - I just had a rant to another commentor here about the ZeroTrust model

  • @SeaJay4444
    @SeaJay4444 Місяць тому

    Always wanted something like this, will have to give it a go.

  • @CannedLaughter00
    @CannedLaughter00 Місяць тому

    😮 just installed this two days ago. This looks like foreshadowing 😆

  • @versita3827
    @versita3827 Місяць тому +2

    Tailscale has completely changed how I access resources on my home network.

  • @Bob-of-Zoid
    @Bob-of-Zoid 20 днів тому

    So it's exactly like the DIY VPN's we used to setup and run ourselves before it became impossible to find any VPN software anymore, and after there being no such thing anymore for some 6 years, suddenly Corporations started selling the modern version under corporate control, as if it was a new tech and previously impossible, and as usual most people fell for it, instead of asking why they can't setup their own peer to peer networks over the internet!
    Windows 3.1 came with a VPN utility, and MIcrosoft killed it too! I don't do Microsoft anymore, haven't for over a decade!
    HAIL THE MIGHTY TUX!! HAIL LINUX!!!

    • @gg-gn3re
      @gg-gn3re 8 днів тому

      run "headscale" yourself, that is the control server and then everything is "self hosted" anyway all of the vpns you complain about still exist. Those were using specific older now insecure vpn protocols like IPSEC. openvpn also is very old but still around, and still can run it all yourself. Wireguard is the new guy and that is what tailscale uses

  • @IvanZupancic
    @IvanZupancic Місяць тому

    sounds like consul/envoy/istio wrapped together. love it

  • @invisiblesilver3001
    @invisiblesilver3001 Місяць тому

    Luckily my ISP gives a public IP on my connection so I can just open ports for things when needed. That said my only ISP option here is centurylink and their DSL is quite slow even if we’re talking internet speeds 10 years ago. I could go and get myself Starlink but their monthly pricing is still a tough sell. Still it’s nice to know that if I go Starlink or another new ISP arrives and goes CGNAT I can use this to run NAS and servers.

  • @Appl_Jax
    @Appl_Jax Місяць тому

    Sounds cool! I'm still in a bit of configuration hell with my setup. Got my home network all set, couple of basic services (plex, torrents, vpn access) and recently added VPN... It was working before but now I'm still trying to figure out how to get the ports open correctly when on VPN without being completely in the open... would this be able to help?

    • @krisiscove
      @krisiscove Місяць тому

      Depending on your Plex use case, the only port you would need to open would be for Plex. If you are using a VPN like Wireguard, OpenVPN, ipsec you will need to open ports for those services. If you replace your VPN server with a tailscale exit node you will NOT need to open any ports for VPN access.

  • @27klickslegend
    @27klickslegend Місяць тому +6

    Tailscale is cool and all, but I find just wireguard is what I want 99% of the time, maybe when my ISP removes my IP It will be handy

    • @HaartieeTRUE
      @HaartieeTRUE Місяць тому +5

      if your setup is simply a site-to-site tunnel, then yes, just a simple straight up wireguard is supperior, EXCEPT if you CAN connect the 2 locations. Some places have double router setups and it become impossible to set something like that up.

  • @kuhluhOG
    @kuhluhOG 28 днів тому

    23:20 The only problem I would have with Tailscale is the difference between Personal Plus and Starter.
    I know families who would need to go with Starter and well, not only is the price difference quite drastic, the amount of features are also a lot less.