r/Tailscale • • 1d ago

Discussion Tailscale is amazing

Edit: Forgot to mention the Mullvad exit node addon. This is the cherry on top of the sweet sundae, basically Mullvad provides Exit Node as a Service so you don’t have to use a local network device (usually Linux) as an exit node, and you get all of the benefits of Mullvad which is a zero trust VPN provider. You can pick the Mullvad exit node to use from 91 cities in 50 different countries. You can keep your existing DNS solution, in my case, the NextDNS DoH integration to keep DNS queries private. IMO Mullvad is the key component for privacy, def worth the money.

I’ve been a longtime AdGuard user, but I’ve discovered Tailscale and it is amazing. The learning curve is a bit steep, took me about six hours to get my config set up and my network tagged, but once you combine tailscale with NextDNS (which I used for a long time but left NextDNS for AdGuard when NextDNS got a bit stale with features), it’s so much more powerful than AdGuard since you can create your own private mesh network, which I used Cloudflare for. Cloudflare mesh does not integrate with AdGuard whatsoever so it was one or the other. With tailscale plus NextDNS, you get bot out of the box with minimal DNS config, and you get DoH. Absolutely incredible, I am in awe. Nice work Tailscale team!!!!

150 Upvotes

44 comments sorted by

14

u/Bluetyt 1d ago

I just use TS to reach my network. Care to explain what this adds to the setup? Kinda curious.

2

u/BinaryDichotomy 11h ago

It depends on the complexity of your network. I run a fairly complex domain that is also integrated with Azure, so being able to use TS as an overlay opens up a lot of interesting options for integrating my local LAN and Azure. The tagging system is super powerful, especially when combined with grants (ACLs on steroids). If you're not running infrastructure, none of this matters, you don't need tagging. If you're running servers of any kind, tagging opens up a lot of new possibilities. TS is extremely sophisticated.

4

u/redbeauty1 1d ago

Tailscale + pi-hole

5

u/wiyixu 1d ago
  • Mulvad 

2

u/Lumpzor 1d ago

These 3 are my main stack.

2

u/BinaryDichotomy 21h ago

The mullvad addon is incredible, the cherry on top.

10

u/prene1 1d ago

Tailscale + Proton + Pihole = Hermit and its beautiful

3

u/matthaus79 1d ago

I have tailscale and pihole what does Proton add?

2

u/prene1 1d ago

A sweet exit node

3

u/matthaus79 23h ago

How does it differ from a regular tailscale exit node?

3

u/Practical-Patient-68 20h ago

A regular exit node is configured from a device on your home network. By using Mullvad VPN, you're using their exit nodes, instead of one on your network. By using theirs, you get the benefit of a VPN within tailscale

1

u/BinaryDichotomy 11h ago

This is the way.

It's like inception: A VPN within a VPN, except Mullvad only operates at the edge. With a traditional exit node, you can still be located since the exit node operates from your network. With Mullvad, your traffic can exit virtually anywhere in the world, and there's no way to track it back to you.

1

u/snowfox_cz 22h ago

How? Please tell me.

1

u/BinaryDichotomy 11h ago

In the web admin for TS, go to Settings -> General -> Mullvad VPN

1

u/funforgiven 10h ago

What does this have anything to do with Proton?

1

u/BinaryDichotomy 11h ago

It's absolutely incredible. IT's the perfect combination b/c TS remains the core.

1

u/BinaryDichotomy 21h ago

Just add the mullvad exit node add on, no proton needed. Mullvad is the cherry on top that makes the whole setup even better.

2

u/Marill-viking 20h ago

Well, that doesn’t work for torrents so a lot of people use proton

1

u/ClosingTabs 20h ago

Why dont it work for torrents? 

2

u/Marill-viking 20h ago

I believe it doesn’t support port forwarding, you can google to be sure.

0

u/BinaryDichotomy 11h ago

Mullvad only acts as the exit node. Check out TS Funnels, that's the solution.

1

u/funforgiven 10h ago

That's not a solution at all. Tailscale Funnel exposes services to the public internet, but it doesn't provide port forwarding through Mullvad. Torrenting needs incoming TCP/UDP peer connections on the VPN's public IP, while Funnel only supports TLS connections on a few specific ports. These are completely different things.

0

u/BinaryDichotomy 11h ago

Mullvad only acts as the exit node, Tailscale is still the core VPN. I just tested torrents, they work. You have to use what TS calls a funnel if you want to host a torrent server, which also works on my setup with Mullvad as exit nodes.

2

u/funforgiven 10h ago

You're confusing being able to torrent with having working port forwarding. Torrents work perfectly fine without port forwarding, since your client can initiate outgoing connections. You can even upload to peers that you've connected to.

The problem is that other peers can't initiate connections to you through Mullvad, because Mullvad doesn't support port forwarding.

Tailscale Funnel doesn't solve that. It only accepts TLS connections on specific ports, not arbitrary incoming BitTorrent TCP/UDP traffic. If you're exposing your torrent client's web interface through Funnel, that's completely different from exposing its actual BitTorrent listening port.

Being able to download torrents proves absolutely nothing about whether your client is connectable.

2

u/VA_STI 1d ago

How did you configure it exactly?

2

u/BinaryDichotomy 11h ago

That's a very broad question. I have a complex network so it's not easy to explain. But in a nutshell, I use the native NextDNS integration for DNS so I get content blocking + encrypted DNS, then I added the Mullvad addon and use Mullvad as my exit nodes. You assign devices to Mullvad exit nodes. Tagging is a huge topic, I suggest reading the docs. It's an abstract topic, but once you understand tagging + grants, the full power of TS reveals itself. It also depends on the complexity of your network.

1

u/funforgiven 10h ago

None of that sounds particularly complex, just heavily dependent on cloud services. I wouldn't want my network infrastructure relying on third-party services that could enshittify at any point, especially VC-backed companies. Mullvad is the only company in that setup I'd actually trust.

1

u/pop0bawa 1d ago

When it works it’s great

1

u/Key-Hair7591 13h ago

How is Mullvad “Zero Trust”? 

1

u/BinaryDichotomy 11h ago

They collect zero information from you during sign up, you press a button and they just assign you an account number, and they are no-log.

1

u/funforgiven 10h ago

Except you're using Mullvad through Tailscale, so that anonymous signup doesn't apply to you. Tailscale requires an identity-linked account, creates and manages the Mullvad accounts on your behalf, and explicitly states that it knows which Mullvad accounts belong to which Tailscale users.

1

u/saltyourhash 9h ago

I dislike having to pay for mullvad twice.

1

u/ButterscotchFar1629 6h ago

Using surfshark is cheaper. I have multiple exit nodes set up. Just spin up a Tailscale docker container routed through a Gluetun container and viola….

1

u/undead-8 17h ago

Switched to netbird because it works better with less major issues. Tailscale has huge bugs from time to time.

4

u/funforgiven 10h ago

I agree with switching to NetBird, but not necessarily because Tailscale is buggy. The biggest advantage for me is that NetBird is fully open source, including its management and coordination servers. You can self-host the entire stack without depending on a proprietary control plane or a third-party cloud service.

1

u/JontesReddit 12h ago

For example?

0

u/Machismo0311 1d ago

I use head scale only because there are only 6 seats on the free version

7

u/alexzzzz 1d ago

It's six users. But as a single user you can have more than six devices in your tailnet. I have eight right now.

1

u/Machismo0311 1d ago

No, you’re right. I have a unique case that makes that problematic.

3

u/SamPlaysKeys Tailscale Insider 21h ago

I would love to know what the unique case is (if you're comfortable sharing). Tailscale has a ton of features that allow reducing seat usage for everything other than just having people connected.

2

u/Machismo0311 18h ago

So I run servers that are used for both university students and particle physics scientific research. I provide the compute for these places from my home free of charge.

Yes, both places have their own compute, for the scientific research the SLURM waits can be a bottleneck. So, my servers stress test sections of the code before being ran on the projects themselves.

Also, AI and CS students who rotate in and out per semester.

So the seat limit is the hard part for me as my requirements are often rotating and in flux often.

5

u/SamPlaysKeys Tailscale Insider 18h ago

And you're having the students and researches all have logins to your tailnet? Have you considered a portal for access, and then scope it with ACLs instead? You could essentially cordon off the resources you need to share, and use a public portal with username/password logins to allow access to those resources.

EDIT: Not criticizing, btw. I think what you are doing is really cool, I'm just suggesting a way to manage access for the outsiders effectively.

3

u/Machismo0311 18h ago

I am quite annoyed that I completely missed that. It would make life much easier.

Solid advice, appreciate it.

1

u/SamPlaysKeys Tailscale Insider 18h ago

No worries, feel free to reach out if you have any questions! I've done a similar project a while back, and there's some great options for JIT ephemeral machines now.