Travelling with Tailscale
mrkaran.dev
mrkaran.dev
I use a raspberry pi connected to my router as a DNS server and exit node and the experience is seamless. And as a bonus I get to keep using my home IP address for all traffic.
This is, honestly, one of the things I like the least about tailscale, and also one of the things they are least likely to change. I understand why they do it, but it feels a bit like too much magic. Tailscale is an incredible bit of kit though.
How is it any better than running my own WireGuard instance?
Tailscale works well for situations where you have lots of roaming devices that perhaps want to talk to each other as well as to central hubs or you want to gate all of this behind some kind of SSO.
If your remote endpoint address changes, the only way your client will find out is either if you restart the tunnel on the client device by hand, or in the lucky case, if the remote endpoint happens to send some data to you at the right time while your client is still hopefully reachable at the same IP+port, which may not be a given behind a NAT if a port mapping times out from inactivity or if it changed network in the meantime.
Tailscale/Headscale is to Wireguard, what Ubuntu is to Linux.
https://tailscale.com/blog/how-nat-traversal-works
Of course if you don't need this, or can set up NAT traversal yourself, and don't need anything else Tailscale does aye set up your own WireGuard network, no worries.
All the reasons I use tailscale after initial connection are indeed the same as if I'd set up any other VPN (direct connectivity, secure connection, private connection, etc)
At its very basic level it's a nice wrapper around WireGuard that handles the fiddly bits that might stop the initial connection for you.
Since I've done that work already, would TailScale buy me anything?
But no, if you don't need that and if you've done the setup part, and you're just looking at the VPN part, you wouldn't gain anything.
Tailscale magically works, recovers well from crashes/network changes (I've had a few issues here with WG native client), manages your keys (and rotation of), creates point to point tunnels (which is just confusing via a plain text config with several devices).
That being said, none of my WG peers really ever need to talk to each other (but the way I have it set up the remote IP subnet does route within it, so I guess they could).
If you install Tailscale, then you don’t need to think of connectivity for other applications: media servers, file sync, RDP, etc. Otherwise, for each of them, you have to think of networking all over (port forwarding, relays, UPnP, …).
Cons: You have to install an agent running as root on all devices, trust the coordination server to some extent, much bigger attack surface!
I've never had an issue accessing banking portals from Europe.
But that won't affect you if you're just travelling. Even if you get a new phone, your account is still set to your original country.
Maybe once passkeys or hardware keys are widely adopted they can remove the atrocious fraud detection.
Whereas 99.999%? of the users won't use tor/$vpnCompany/cloud provider IPs. It's all in terms of which is less likely to lead to a support request.
I worked with a relatively big bank that used a tool like Akami or Cloudflare. With those tools you can just ban/block entire countries (think any IP from Iran, Russia, etc) or entire ASNs.
The best thing would be to have your own physical machine act as an exit node instead of relying on a cloud instance. That would bring a whole series of new problems for keeping a machine up and running while you are away, but doable
It’s probably the second most common geo rule after geoblocking.
For me, I have a NAS that's running Tailscale just inside my edge at home that can be an exit node as well as provides full subnet router access for my home "servers" subnet so I can get to anything from any device that I authorize a Tailscale client for as if I'm on my home LAN... anywhere.
It was also really easy to share my NAS to someone else for exit node access while traveling, and they reported back a flawless experience streaming movies while overseas via the exit node off my residential 1000/1000 fiber.
And for the 'average person' with an Apple TV? Just grab the Tailscale tvOS app and fire up an exit node of your own for when you travel later on, too!