Remix.run Logo
MarsIronPI 2 days ago

Huh? I thought one of the appeals of Tailscale is that security is done at the network level; plus that your network is private, so you don't get randos knocking at your ports.

akho a day ago | parent [-]

What does “at the network level” mean?..

Anyway; Tailscale is not your only network. If you’re on a laptop, you need to be able to log onto rando wifi networks. If you’re at home, you need to be mindful of your smart fridge going rogue. You need to run a firewall. Tailscale adds a separate, Tailscale-specific, firewall with centralized management. Now you have two firewalls.

MarsIronPI a day ago | parent [-]

Ah, I see what you mean now. Yes, that's true; you'd still need a firewall for LAN.

> What does “at the network level” mean?..

I meant the normal non-Tailscale firewall (e.g. iptables).