Remix.run Logo
dec0dedab0de 5 hours ago

Wouldn't the FOSS alternative be to simply use wireguard?

newsoftheday 5 hours ago | parent | next [-]

I do, I use a VPS (at OCI free) to host Wireguard. My home systems (running my production web sites and email) are on my VPN and mine and my wife's phones. I hand configured it all but it wasn't difficult for me.

iso1631 5 hours ago | parent | prev | next [-]

Most posters on HN barely know what a subnet is so it's not that simple

There's two key features

1) Tunnel management

Tailscale will configure your p2p tunnels itself - if you have 10 devices, to do that yourself you'd have to manage 90 tunnels. Add another device and that goes upto 100. Remove a device and you have 9 other devices to update.

2) Firewall punching

They provide an orchestration system which allows two devices both behind a nat or stateful firewall to communicate with each other without having to open holes in the firewall (because most firewalls will allow "established" connections - including measuring established UDP as "packet went from ipa:porta to ipb:portb 'outbound', thus until a timeout period any traffic from ipb:portb to ipa:porta will be let through (and natted as appropriate)".

The orchestration sends traffic from ipa to ipb and ipb to ipa on known ports at the same time so both firewalls think the traffic is established. For nats which do source-port scrambling it uses the birthday paradox to get a matching stream.

I believe you can run a similar headend using "headscale" yourself.

NoiseBert69 5 hours ago | parent | prev [-]

Yes and no. It's much manual work to get WG to behave like Tailscale.