Use NextDNS everywhere you use Tailscale
tailscale.com
tailscale.com
But. This just solved all those issues. Threw my nextdns address into tailscale and away i go. I swear every single time I run into some modern inconvenience of the web Tailscale (by mission statement) is there to solve it.
Then I wondered why I needed NextDNS at all, so I just replaced everything with pi-hole and zerotier (tailscale but plays better with custom networks. It's a simple interface with an IP address. )
Tailscale is cool and shiny, but it's one of those automagic software that don't leave much space for customisation and hacking. I guess I'm not the intended audience.
That's like saying "it's like Cisco Anyconnect, except with less GUI applications"
They're both VPNs, that's basically all they've got in common.
Tailscale builds upon wireguard and creates a pretty polished interface for it. Zerotier has their own VPN technology and also provides hardware appliances for VPN termination
Ofc, as soon as I enable the use of exit nodes I will be back in Germany again. But I don’t always need exit nodes. Split can be sufficient and this solved one of the issues I had with my use case.
https://github.com/tailscale/tailscale/issues/2452 links to all the client commits.
There was also a lot of control plane stuff to let you specify config for different NextDNS profiles per tags/groups/users/etc.
And NextDNS improved some things on their side too, especially around passing device info to them.
And then, yes, we publicized it after working on it. And closed that bug.
The built-in resolver at 100.100.100.100 handles the *.your-tailscale-suffix names in your tailnet and the rest that doesn't match goes upstream. Basically.
Using ipv4 NextDNS servers returned 'youre using NextDNS but without configuration'.
And there's a little UI polish coming for the admin panel to show NextDNS configuration a bit more cleanly, but that's not live yet.
However I stopped because I started using protonVPN, and there is no way to run a normal VPN on top of Tailscale, without having some kind of exit-node which will add even more latency.
It would be cool if Tailscale would support some kind of wireguard import, so if the data is not sent to Tailscale recepients, it will send it through the normal Wireguard tunnel.
In my experience the app also had other issues, like excessive battery usage on Android.
Other than that, Tailscale + Head scale, the best mesh network implementation you can find IMO.
They don’t want to, because it’s Hard and if (when?) some part of it fucks up you get blamed. They’ll let you use your own but only if you pay them enough.
I use NextDNS on my devices and turn it off temporarily when something I need to access doesn’t work because of something getting blocked by the filter lists (I do manage the allow list on my NextDNS account for any permanent or long term changes).
Seems like this doesn’t support multiple NextDNS profiles (says it’s in alpha) and the UX looks a bit rough to me.
[1]: I don’t seem to have a need to use Tailscale so far since the devices in my home network are shutdown when I travel and I don’t need access to them at all.
[2]: Besides, I don’t wish to signup for something through a Google or Microsoft or GitHub account (or other third party account), which are the only options supported by Tailscale. I’ll consider Tailscale if/when it supports a simple email/password account registration.
> Does NextDNS assign a unique IPv6 address for each account to know this is my account and to apply my chosen filter lists?
NextDNS does assign a unique IPv6 address for each profile in an account, and the IPv6 address actually ends with the exact profile name. For example, if my NextDNS profile is a7bae4, the IPv6 address would be like 2d17:a4c3::a7:bae4.
How could it possibly have lower latency than something that's literally on your local network? Once it caches a request it's nearly instantaneous.
I believe, what they mean is, NextDNS, given its global footprint, is lower latency than pi-hole in your local network connected via Tailscale over public Internet.
For one user never leaving your house, you're correct.
But once you have two or more users in different cities (or you're traveling), then your Pi at home will almost always lose compared to a geo-replicated service.
>Difference being you can now set IPv6 DNS servers. It's been a while since I tried but this wasn't possible or I did something wrong prior. Using ipv4 NextDNS servers returned 'youre using NextDNS but without configuration'.
What's new is that your NextDNS configuration profile is preserved even if your client can't do IPv6. We did DNS-over-HTTPs previously for the big public DNS providers, but now we also do DoH for NextDNS, using IPv4 or IPv6 for the underlying TCP connection as needed, but always passing through your NextDNS configuration.
The current UI just makes you paste in your NextDNS config-specific IPv6 address as a means of parsing out your config from the lower bits of the address. We have better UI coming.
(We don't do the NextDNS traditional port 53 DNS. They don't really support it with IPv4. There's a IP linking mechanism but it doesn't work with multiple devices)
You can also have the pi-hole configured to use NextDNS as its upstream nameserver, and that works very well. Also, you can set up the server as a subnet router, and have access to all your machines on the LAN, even if you can't install tailscale on all of them.
Tailscale is truly incredible!