What is our primary use case?
My main use case for Tailscale is for my homelab, where I have several services, including professional services. I use it to connect remotely from different places and access my services. I used to work from two different homes, where all the infrastructure was in the first home, but I was in the second home, so I was always connecting to the first home. I actually did that internationally, across two different continents, and it worked very well. The first use is to connect to the infrastructure, to be able to manage it, and to be able to administer it. I also used Wake on LAN for different devices through Tailscale network. That was a very good use case.
Additionally, since I have it, I use it on public networks when I want anonymity, for example, in an airport. I forward all the traffic from my mobile device through Tailscale network to the other home, and there I can have all my information encrypted in the airport.
I have many devices that use Tailscale, including many non-technical users who need to connect to the infrastructure to obtain certain files and make certain changes. Tailscale app, especially for iPhone, works very well. It is very easy to turn on and off, and it is very easy to do all the setup. Comparing it directly with WireGuard, with WireGuard, I have to create each of the peers and each of the configuration files for each of the devices. On top of that, for the server that I was using with Tailscale service, several peer files were needed because one redirected all the internet traffic and the other only to the services that were needed, depending on what I wanted to do at that time. I had to create two peers for each of the devices, and it was honestly a lot of hassle to manage. With Tailscale, it is really very easy to configure it, add the emails of all these people within the main console, and that allowed non-technical users to use the entire infrastructure by connecting, either forwarding all internet traffic through Tailscale or only forwarding the specific traffic of the services.
Another good thing about Tailscale is that since it runs on top of WireGuard, I really notice very few performance differences. The performance is quite good, and the stability as well, because I have used it to send many gigabytes of data over the internet, in fact, across continents, from one continent to another, using the entire Tailscale network. I used the SMB service to share files, and I am sometimes talking about transferring 50, 70, or 80 GB all through the VPN. It worked super well. Having firewall passthrough directly passes NAT passthrough. That is much easier to configure than configuring all the ports. Everything updates automatically, which is also very helpful. I actually have it with auto-update both on the server and on all users. That also greatly improves the overall experience. I haven't had any major problems, and the fact that anyone can use it is very good.
How has it helped my organization?
It is positive because in a very easy way all users can connect, they can see files, they can access certain services, and I can privately manage all the infrastructure while being on different continents.
What is most valuable?
I haven't used Tailscale in corporate terms, but I know it has many features that I am currently not using. The fact that the UI and UX are so good, that it works so well, that it is clear, and this Exit Node feature that can be activated in a very easy way, allowing me to access all the infrastructure, makes it very easy to use. That is a good advantage.
This allowed less technical users to use all my infrastructure, which before was more complicated. Before, I spent a lot of time setting up all the peers, and now I disabled all the peers I had in WireGuard and I rely simply on Tailscale. At most, I just add the Gmail accounts. Something very good they added is that before I wanted to have an account where I could log in with my own email in Tailscale, and I couldn't. I had to log in with Google and Gmail, which actually bothered me quite a bit. That was pretty bad because I don't use Gmail as my primary account. I have Gmail as a second or third account, but there was no provider for the email I used, which is ProtonMail. I know that now you can create an account. I've never done it and I kept the Gmail account that I only use for Tailscale and very few other things.
This is also worth mentioning because it provides simplicity and flexibility in user management, which is essential for less technically inclined individuals.
What needs improvement?
At the moment, I don't know because it's been working very well for me, and I haven't been managing it much lately. I still use it because I connect from different phones, but everything is already configured, and I simply use it as a tool. For my use case, it works perfectly.
One somewhat negative point that I see is that if you want to use Exit Node and that is installed on a device within the network, then you have a bit more latency because instead of the packets going from a mobile device to the router at the other home and from the router going out again to the internet, for example, now they have to enter the network, enter the device that has Tailscale, and only then go out. That sometimes adds about 3 milliseconds. This is crucial if you are sending many gigs. If there were a feature, it would be great if Tailscale could integrate with different providers in routers or commercial devices. They would have to negotiate, and I know it's not easy, but so that the router itself or a piece of equipment that is at the edge of a network could have Tailscale installed and run from there. With that, you can reduce a few milliseconds, and you also wouldn't be overloading the internal network or the switches at the other home. That is an important point to take into account.
For how long have I used the solution?
I have been using Tailscale for approximately two years.
What do I think about the stability of the solution?
I consider Tailscale to be stable.
What do I think about the scalability of the solution?
I cannot answer that because I don't have very scalable, very large environments. They are small environments.
Which solution did I use previously and why did I switch?
I used L2TP and OpenVPN before Tailscale, and then I started deploying Tailscale and WireGuard. At first, WireGuard was hard for me. It was difficult to install, and due to time, I didn't do it. I deployed it later and I still have it partially, but I primarily use Tailscale because it runs on top of WireGuard, it is more efficient than L2TP, and more efficient than OpenVPN, and installation is super easy.
How was the initial setup?
I experienced reduced technical effort and implementation time since using Tailscale.
What's my experience with pricing, setup cost, and licensing?
I have not had any problems with Tailscale's costs, initial setup, and licensing. I did not incur any costs and I stay entirely on the free tier. I don't think I had any licensing issues either. I haven't hit any limits yet, and I would have to check which features are paid, but for now, the free ones work very well for me.
Which other solutions did I evaluate?
When I learned about Tailscale, it was recommended to me, and I investigated it, saw that it was very good, and started using it.
What other advice do I have?
There are several or many minutes of time saved, especially with WireGuard and in management, and in the mental management, it also has an impact because having to manage so many peer files with WireGuard was a bit more complex. With Tailscale, it is honestly super easy. A friend had recommended it to me, so all of that is very good.
In fact, I did something very important, which is that I conducted a comparison study for my university thesis where I specifically compared four VPN services. I compared L2TP, OpenVPN, Tailscale, and WireGuard. The tests I did in the benchmark were on two different continents, in Europe and Latin America. I tested it with the transfer of a 500 MB file over the internet using the Windows SMB protocol, wanting to see the overhead between each of the different VPN services. Speaking of L2TP, it completed the transfer in 1 minute and 10 seconds. Then OpenVPN had a slightly better performance than L2TP with 1 minute and 7 seconds. Then comes Tailscale with 1 minute and 6 seconds and finally WireGuard, which was the fastest at 1 minute and 5 seconds. Although WireGuard technically won in speed, it is not worth that one second of difference in transfer time versus the fact that it is actually much faster to deploy the VPN and the infrastructure with Tailscale. I much prefer Tailscale over WireGuard for that reason.
I always recommend to others who are considering using Tailscale to go for it.