Tailscale¶
TL;DR / when to use this: Tailscale is the zero-config overlay network I use for LAN access on the go and for exposing a handful of services publicly via Funnel. Use Tailscale when you want mesh networking without maintaining a VPN server; use WireGuard when you want a self-hosted, fully-controlled tunnel.
Flags I use constantly¶
sudo tailscale up \
--accept-dns=false \
--advertise-exit-node \
--advertise-routes=192.168.4.142/32 \
--reset
--accept-dns=false— keep local DNS (needed for local resolution and split DNS setups)--advertise-exit-node— this node can serve as an exit node--advertise-routes=— publish a LAN subnet/host to the tailnet--reset— clear previously persisted flags so the current set applies cleanly
Funnel¶
Expose a service on a port to the public internet:
If Funnel isn't enabled on your tailnet, the command prints a URL — click it to enable. Note: Funnel does not support CNAME records (custom domains pointing at *.ts.net names don't work), so you get the *.tailscale-funnel.app hostname.
Tailscale vs WireGuard¶
| Tailscale | WireGuard | |
|---|---|---|
| Setup | Install + auth, done | Self-hosted server, keys, config files |
| Control | Managed control plane (open-source clients) | Everything on your box |
| NAT traversal | Trivial (derp + hole punching) | Needs port forwarding |
| Good for | Devices on the move, quick mesh | A single trusted tunnel to your own server |
The two coexist fine: Tailscale for device convenience, WireGuard for a self-hosted tunnel. The GeoIP whitelist in SWAG treats 100.64.0.0/10 (the Tailscale range) as LAN.
See also¶
- WireGuard VPN
- Blog posts: Cheat sheet for Tailscale · Tailscale Funnel