{"id":2552,"date":"2023-07-27T14:51:12","date_gmt":"2023-07-27T18:51:12","guid":{"rendered":"https:\/\/increasec.com\/?p=2552"},"modified":"2024-06-14T12:43:13","modified_gmt":"2024-06-14T16:43:13","slug":"why-tailscale-wireguard","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=2552","title":{"rendered":"Remote Access Comparison \/ why TailScale"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p><strong>TailScale<\/strong>: A cloud hosted version of WireGuard with a pretty web GUI.<br>Pros:<br>No server installation, just sign-up<br>Doesn&#8217;t require any VIPs or TCP port forwards on your firewall (more secure)<br>Double NAT friendly<br>Asymmetric Routing friendly<br>Overlapping subnets are usable with manual switching<br>Subnet router (requires a Linux endpoint)<br>Clients for Windows, Linux, MacOS, Android, iOS, Synology, TrueNas Scale, Home Assistant, pfSense, OPNsense&#8230;.very etc.<br>Auth, including MFA provided by 3rd party ie Microsoft\/Google\/GitHub etc<br>Auth can stay logged in for long periods, not prompting for MFA<br>Supports Mesh, Client-Server, Peer2Peer<br>Does NOT require static IP on Firewall or Dynamic DNS<br>After version 1.66? Tailscale client can be remotely updated from the Web Console, Machines tab<br>Want to manage a remote server? Tailscale + Windows Admin Center.  No firewall rules or VPN req&#8217;d.<br>Free for small networks; 3users, 100devices. Standard is $6\/user\/m<br>The Business network can also get to the client, to check for updates or if a user leaves and refuses to return company laptop the biz can remotely delete company data.<\/p>\n\n\n\n<p><br>Cons:<br>All the eggs in 1 basket. You&#8217;re trusting that TailScale has no code bugs or backdoors.  <br>Client needs to be installed, same for any vpn but no client for RdWeb<br>The Free version allows you to be logged onto 1 network at a time<br>Remember to right click tray icon, prefs, run unattended or it won&#8217;t work when logged out or a different user is logged in.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Competitors:<\/p>\n\n\n\n<p><strong>RdWeb\/Citrix<\/strong>:<br>Pros: <br>no client needs to be installed<br>can use published apps or full desktop<br>Cons:<br>Client OS must have RDP software.  not available on all OSs and not all compatible with modern protocols\/encryption<br>must connect to a Firewall, static IP +DNS recommended, no peer to peer<br>Server OS must be Windows<br>Licensing costs   RDS User CALS ~$200us\/user  (concurrent per 90days?)<br>Needs DUO or equivalent for MFA   $0 for 10users, $3\/6\/9\/user\/m depending on features<\/p>\n\n\n\n<p><strong>IPSec VPN<\/strong>:<br>Pros:<br>mature (not buggy)<br>inter-device compatibility is high<br>Layer 3 = high software compatibility<br>supports both site2site and client2site<br>Cons:<br>must connect to a Firewall, static IP +DNS recommended, no peer to peer<br>hardest to understand and configure<br>does not connect thru double NAT<\/p>\n\n\n\n<p><strong>SSL VPN<\/strong>:<br>Pros:<br>Easier to setup than IPSec VPN<br>may not require client software<br>Cons:<br>Buggy and insecure (in the news a lot lately)<br>Not true routing, just port forwarding<br>must connect to a Firewall, static IP +DNS recommended, no peer to peer<br>does not connect thru double NAT<\/p>\n\n\n\n<p><strong>VIP \/ PortForwarding + RDP<\/strong><br>Pros:<br>convenient, easy to understand + setup on server side<br>no client required on client side<br>Cons:<br>Super Insecure! Don&#8217;t ever do this! <br>Still insecure with MFA because the Protocol is buggy<br>must connect to a Firewall, static IP +DNS recommended, no peer to peer<\/p>\n\n\n\n<p><strong>Guacamole<\/strong><br>Pros:<br>Free<br>supports multiple MFA schemes via add-ons<br>Cons:<br>Setup requires intimate knowledge of Linux\/Docker<br>Docker wasn&#8217;t reliable, could be my limited knowledge<br>must connect to a Firewall, static IP +DNS recommended, no peer to peer<\/p>\n","protected":false},"excerpt":{"rendered":"<p>TailScale: A cloud hosted version of WireGuard with a pretty web GUI.Pros:No server installation, just sign-upDoesn&#8217;t require any VIPs or TCP port forwards on your firewall (more secure)Double NAT friendlyAsymmetric&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[206],"class_list":["post-2552","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-remoteaccess"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2552","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2552"}],"version-history":[{"count":29,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2552\/revisions"}],"predecessor-version":[{"id":2941,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2552\/revisions\/2941"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2552"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2552"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2552"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}