All articles
Complete technical guides for Tailscale overlay networks, WireGuard DERP relay latency optimization, ACL security policies, and MagicDNS configuration.
-
Headscale vs Tailscale Explained: What Actually Differs
Headscale replaces one Tailscale component: the control server. What that buys you, the three features it does not implement, and where the pricing flips.
-
Tailscale Subnet Router Configuration: Routes, ACLs, Tests
Advertise LAN routes, approve them with autoApprovers, scope access with grants, and handle the SNAT, MTU and overlapping-subnet traps before they bite.
-
Tailscale Exit Node Setup: Linux, ACLs, VLANs, and Tests
Configure a Linux Tailscale exit node, approve it, scope access with grants, isolate it on a VLAN, and verify IPv4, IPv6, DNS, and tunnel performance.
-
Tailscale vs ZeroTier vs NetBird: Mesh VPNs Compared
Self-host the control plane or not, L3 overlay or L2 bridge, policy file or console. The three questions that pick between Tailscale, ZeroTier and NetBird.
-
Tailscale Slow? Fix DERP Relay and Throughput Issues
Fix slow Tailscale transfers by checking for a DERP relay, restoring direct UDP, then tuning Linux offload, CPU, MTU and subnet routers.
-
How to Set Up Tailscale: First Tailnet Guide
Install Tailscale, connect two devices, verify a direct path, configure MagicDNS, replace default allow-all access, and add subnet or exit routes.
-
How a Tailscale Mesh VPN Works: Coordination, NAT and ACLs
Understand the tailnet model: WireGuard mesh tunnels, the coordination plane, DERP relays, identity-based ACLs, subnet routers and exit nodes.