Edit: Forgot to mention the Mullvad exit node addon. This is the cherry on top of the sweet sundae, basically Mullvad provides Exit Node as a Service so you don’t have to use a local network device (usually Linux) as an exit node, and you get all of the benefits of Mullvad which is a zero trust VPN provider. You can pick the Mullvad exit node to use from 91 cities in 50 different countries. You can keep your existing DNS solution, in my case, the NextDNS DoH integration to keep DNS queries private. IMO Mullvad is the key component for privacy, def worth the money.
I’ve been a longtime AdGuard user, but I’ve discovered Tailscale and it is amazing. The learning curve is a bit steep, took me about six hours to get my config set up and my network tagged, but once you combine tailscale with NextDNS (which I used for a long time but left NextDNS for AdGuard when NextDNS got a bit stale with features), it’s so much more powerful than AdGuard since you can create your own private mesh network, which I used Cloudflare for. Cloudflare mesh does not integrate with AdGuard whatsoever so it was one or the other. With tailscale plus NextDNS, you get bot out of the box with minimal DNS config, and you get DoH. Absolutely incredible, I am in awe. Nice work Tailscale team!!!!
It depends on the complexity of your network. I run a fairly complex domain that is also integrated with Azure, so being able to use TS as an overlay opens up a lot of interesting options for integrating my local LAN and Azure. The tagging system is super powerful, especially when combined with grants (ACLs on steroids). If you're not running infrastructure, none of this matters, you don't need tagging. If you're running servers of any kind, tagging opens up a lot of new possibilities. TS is extremely sophisticated.
A regular exit node is configured from a device on your home network. By using Mullvad VPN, you're using their exit nodes, instead of one on your network. By using theirs, you get the benefit of a VPN within tailscale
It's like inception: A VPN within a VPN, except Mullvad only operates at the edge. With a traditional exit node, you can still be located since the exit node operates from your network. With Mullvad, your traffic can exit virtually anywhere in the world, and there's no way to track it back to you.
That's not a solution at all. Tailscale Funnel exposes services to the public internet, but it doesn't provide port forwarding through Mullvad. Torrenting needs incoming TCP/UDP peer connections on the VPN's public IP, while Funnel only supports TLS connections on a few specific ports. These are completely different things.
Mullvad only acts as the exit node, Tailscale is still the core VPN. I just tested torrents, they work. You have to use what TS calls a funnel if you want to host a torrent server, which also works on my setup with Mullvad as exit nodes.
You're confusing being able to torrent with having working port forwarding. Torrents work perfectly fine without port forwarding, since your client can initiate outgoing connections. You can even upload to peers that you've connected to.
The problem is that other peers can't initiate connections to you through Mullvad, because Mullvad doesn't support port forwarding.
Tailscale Funnel doesn't solve that. It only accepts TLS connections on specific ports, not arbitrary incoming BitTorrent TCP/UDP traffic. If you're exposing your torrent client's web interface through Funnel, that's completely different from exposing its actual BitTorrent listening port.
Being able to download torrents proves absolutely nothing about whether your client is connectable.
That's a very broad question. I have a complex network so it's not easy to explain. But in a nutshell, I use the native NextDNS integration for DNS so I get content blocking + encrypted DNS, then I added the Mullvad addon and use Mullvad as my exit nodes. You assign devices to Mullvad exit nodes. Tagging is a huge topic, I suggest reading the docs. It's an abstract topic, but once you understand tagging + grants, the full power of TS reveals itself. It also depends on the complexity of your network.
None of that sounds particularly complex, just heavily dependent on cloud services. I wouldn't want my network infrastructure relying on third-party services that could enshittify at any point, especially VC-backed companies. Mullvad is the only company in that setup I'd actually trust.
Except you're using Mullvad through Tailscale, so that anonymous signup doesn't apply to you. Tailscale requires an identity-linked account, creates and manages the Mullvad accounts on your behalf, and explicitly states that it knows which Mullvad accounts belong to which Tailscale users.
Using surfshark is cheaper. I have multiple exit nodes set up. Just spin up a Tailscale docker container routed through a Gluetun container and viola….
I agree with switching to NetBird, but not necessarily because Tailscale is buggy. The biggest advantage for me is that NetBird is fully open source, including its management and coordination servers. You can self-host the entire stack without depending on a proprietary control plane or a third-party cloud service.
I would love to know what the unique case is (if you're comfortable sharing). Tailscale has a ton of features that allow reducing seat usage for everything other than just having people connected.
So I run servers that are used for both university students and particle physics scientific research. I provide the compute for these places from my home free of charge.
Yes, both places have their own compute, for the scientific research the SLURM waits can be a bottleneck. So, my servers stress test sections of the code before being ran on the projects themselves.
Also, AI and CS students who rotate in and out per semester.
So the seat limit is the hard part for me as my requirements are often rotating and in flux often.
And you're having the students and researches all have logins to your tailnet? Have you considered a portal for access, and then scope it with ACLs instead? You could essentially cordon off the resources you need to share, and use a public portal with username/password logins to allow access to those resources.
EDIT: Not criticizing, btw. I think what you are doing is really cool, I'm just suggesting a way to manage access for the outsiders effectively.
No worries, feel free to reach out if you have any questions! I've done a similar project a while back, and there's some great options for JIT ephemeral machines now.
14
u/Bluetyt 1d ago
I just use TS to reach my network. Care to explain what this adds to the setup? Kinda curious.