9 ms·
Choose your own IP
- BonoboIO 3y agoNext thing: Vanity 100.xxx.xxx.xxx IP addresses.
- evntdrvn 3y agoThank you to everyone at TS involved in this feature!! It will solve a big pain point for us re reserved CGNAT ranges that were causing conflicts. Cheers
- wheybags 3y agoThe one feature I feel is missing now is attaching to multiple tailnets from the same client. Since you can configure address ranges, I could set up non-overlapping ranges on my personal and work tailnets, and then use both on my phone, for example.
- arittr 3y ago"One thing you can rely on with IPv4: whatever the problem, Network Address Translation is part of the solution." NAT... the cause of, and solution to, all of life's problems.
- BLKNSLVR 3y agoI thought it was always DNS?
- H8crilA 3y agoI thought it's BGP? Or maybe that's just the cause of all problems, hmm...
- Affric 3y agoMy understanding of BGP is that it’s so old (and was relatively well designed) that it could now be considered an arcane magic once widespread but now only known by some old wizards.
- silisili 3y agoThe problem with both is that they were both designed long ago, without much regard to bad actors. They have been around so long replacing would be a herculean effort.
- AeroNotix 3y agoFor some reason whenever I interview very junior candidates - every _single_ one of them has BGP on their resume as a skill. 0% of them have correctly been able to explain what BGP is used for.
- glitchcrab 3y agoJunior candidates for what position?
- vikarti 3y agoWould answer "I use it host servers at home and have load-balanced access to internet via several end-users ISPs(no BGP sessions with ISPs so 2 VPN tunnels from home to server + 2 BGP sessions from home to said server via tunnels and server itself have session with it's ISP) count?" :) Would "I'm just getting lists of IPs blocked by local censorship authority/IPs which are better to access via IP from OTHER country to put them all in VPN" count? :) p.s. I'm not network admin and never put "BGP" on resume.
- AdamJacobMuller 3y ago> To address this (no pun intended), Liars, you definitely did. I was a bit surprised when I learned tailscale was addressing out of a single global pool and wondered how they would fix it when they ran out of IPs (and I knew they would, Tailscale was and is obviously that good to me). I vaguely suspected this would be kind of solution they would employ because it's really perfect from an end-user experience point of view, but, thought they might not because it's definitely more complex on their side. Shame on me for misunderestimating the tailscale team.
- hughesjj 3y agoHot take: The Tailscale team is the highest concentration of leading network engineers from any company in the world today, at least when it comes to consumer products. If we ever get a true 'next gen' internet that removes the protocol cruft we've layered on over the years, I could see it coming out of them moreso anyone else.
- aqfamnzc 3y agoI'm a very happy Tailscale user and am impressed by its quality and reliability... But why is the team constantly put on the highest of pedestals here on HN? They seem like one of many groups of competent people making good software to me. Perhaps the answer is that they're so good that I vastly underestimate the complexity of the problem Ts solves?
- pluto_modadic 3y agothey take a complex problem, AND a complex solution, and make it beautifully simple so /it just works/, in a way no other system has. The documentation is superb and frequently just makes sense when you do it.
- boredtofears 3y agoTheir devrel is incredible, and to be fair the UX of their product is really good and resembles magic to someone unfamiliar with wireguard. HN falls for dev marketing really hard every time (see: vercel, stripe, etc)
- moduspol 3y agoI just set up Tailscale for work last week. I've been really impressed with it.
- MuffinFlavored 3y agoWhat does it give you that Wireguard doesn't (or OpenVPN)? Just easier to configure + setup + a nice UI? Just making sure I'm not missing something, not trying to knock Tailscale. Do the "minimalist" people have good reason to prefer "anything-else" other than "heavy feature-rich Tailscale"?
- anderiv 3y agoFor me the key additions are: 1) integration with our org Identity Provider 2) NAT traversal + DERP relay fallback 3) Tailscale’s ACL functionality.
- tptacek 3y agoCertainly, don't use OpenVPN in 2023 if you can avoid it. WireGuard is much faster and more secure, and significantly easier to set up. If you're a home user, the advantage to Tailscale is that it's going to "just work", with a couple clicks, on any supported device (of which there are lots). There's no configuration to get started and, for a lot of users, no configuration ever after that. The onboarding experience is spooky; it's upsettingly good. If you're a corporate user, the advantages are drastically greater: you get SSO integration (this is historically one of the annoying pain points of corporate access VPNs, to the point where a significant fraction of pre-Tailscale netsec teams just punted on this problem and hand-provisioned VPN creds for people, which is a nightmare) and trivially simple group-based access control.
- mato 3y agoThe combination of 'it just works' and 'SSO integration' is a killer. To be honest, in 20+ years of working in IT, I never understood the point of the latter until recently, on a gig salvaging systems for a client with ~650 users after their sole IT guy unexpectedly resigned after 20 years and left for the mountains. IRL, SSO is gold. Many hackers, like me, underestimate it.
- GauntletWizard 3y ago1:1 Nat is a great solution... except in cases where IP Addresses of peers are transmitted as part of the protocol, like in Gossip structures or (Not that anyone should be using this!) FTP. Most games do this, though explicitly to get around NAT so they understand which packets are coming from where. Honestly, in none of my use-cases will it matter - I can't see myself running a gossip protocol across servers that I do and don't control.
- notpushkin 3y ago> Most games do this, though This can be fixed by manually setting the IP in the Tailscale console though, so for this particular usecase I think it's okay, too.
- jakedata 3y agoI hope they are working on improving firewall traversal. Lots of firewalls don't allow symmetrical UDP NAT ports, causing clients to fall back to DERP relays on TCP port 443. It's a lot slower. It is possible to work around this by statically mapping inbound UDP ports but that is clearly not an ideal situation. I generally love Tailscale though, amazing work all around.
- incahoots 3y agoOh I wasn't aware of this, thanks for sharing this.
- wtatum 3y agoDo you know of a straightforward way to identify that this is happening: where one node is using DERP or one link between your nodes is falling back to DERP?
- cassianoleal 3y ago`tailscale status` should tell you which nodes do or don't have a direct connection.
- ianlevesque 3y agoFrom the extensive blog posts about all the tricks they already use, I’d assume they’ve squeezed all the juice from that orange. https://tailscale.com/blog/how-nat-traversal-works/ https://tailscale.com/blog/how-nat-traversal-works/
- incahoots 3y agoTailscale is needed if you require site to site connectivity via something like Starlink. I may be putting my ignorance on display here, but I recently completed a site-to-site network between two farms in rural America, no other ISP can serve these farms, and they needed to communicate cow data between the different farms. Tailscale did the majority of the heavy lifting thankfully, and we were able to get them all sorted out. I could not get Wireguard to work, and that may be down to my limitations in networking, but I was sucessful with tailscale, so make of that as you will.
- howeyc 3y agoIf I had to guess, it's probably the NAT hole-punching or use of tailscale servers as an intermediary. If you signed up for a $5 VPS to forward packets you probably would have been fine.
- toomuchtodo 3y agoTailscale is free for 3 users and up to 100 devices, so it's a fine solution vs running your own VM for hole punching. Consider your time value. You can even pay for Mullvad exit node access for devices in your net and configure the coordination layer accordingly.
- incahoots 3y agoFree was the price, client didn't want to pony up for any additional monthly fees. In the past I would've included it into my monthly "on call fee" but now I value my free time too much to the point where clients aren't interested in having me as an emergency line. I'm sure I'm leaving money on the table, but I'm a one man show, and I have trust issues with relying on others, so here we are.
- toomuchtodo 3y agoWho takes care of the VPS then? You're paying for something somewhere if you're not donating your time for free to the client.
- cyrnel 3y ago> We all know how well IPv6 adoption has gone What frustrates me is that people keep building solutions like this that heavily rely on IPv4, even when forward-compatible options exist. With clever use of IPv6 transition technologies, you could have retained support for legacy devices while generally using IPv6 everywhere else.
- sgjohnson 3y agoTailscale supports IPv6. But their IPv6 support is useless to you if your ISP doesn’t support IPv6. This is a needed feature if you have no IPv6 AND are stuck in CGNAT hell. And I’m an IPv6 evangelist.
- H8crilA 3y agoNo, Tailscale creates both IPv4 and IPv6 connectivity over .. well pretty much anything. If there's IPv4 - it will use it, if there's IPv6 - it will use it. If there's some traversable NAT - it will use it. I think we should dig out the old meme about ADSL running over a pair of wet strings.
- sgjohnson 3y ago> If there's some traversable NAT - it will use it. But there is no traversable NAT if you’re stuck in CGNAT hell with no IPv6 and the CGNAT subnet they gave conflicts with the one you have. Unless you NAT it again or do some other route fuckery. NAT4444 sounds really great!
- cyrnel 3y agoIf you have an agent installed on every node that can already traverse NAT, you don't have to care about what your ISP supports. There are many more IPv6-centric solutions to their problem. Sounds like they didn't even try to think of alternatives and instead reached straight for NAT. That wasn't necessary, at least from the amount of information we can glean from this one post.
- 3y ago
- timenova 3y agoI'm glad they released this feature. There are databases/services which require you to input the IP address to listen on instead of the network interface. This will greatly simplify configuring those services.
- jedberg 3y agoWhat is the advantage of using the CGNAT range instead of 10/8?
- chrisfosterelli 3y agoThat'd probably have a lot of conflicts with people's LANs.
- rollcat 3y agoYou're much more likely to be already using 10/8 as a part of your setup, whereas 100.64/10 has only really been a thing for residential/mobile ISPs. (I have no idea what happens to Tailscale when your carrier gives you a 100.64/10.)
- samcat116 3y agoTypically that CGNAT IP would just sit on the WAN port of your router. So in theory none of your LAN devices would hit that IP anyway (the router would be NATing everything). Your clients having a route to 100.64/10 pointing to the tailscale VPN interface shouldn't have an issue (unless you install Tailscale on your actual router, that would take some special setup).
- tambourine_man 3y agoBy reading the title I imagined a brand new way address routing. That’s how high I regard Tailscale, I guess. I remember watching many years ago a talk about a mesh network scheme where its users would unambiguously assign themselves addresses through some hash function. I was fascinated by this concept of generating my own address (instead of having it assign to me) and that it could possibly be mine forever, perhaps associated with some biometric marker. Anyway, this is also cool, just less ambitious :)
- codethief 3y ago> I remember watching many years ago a talk about a mesh network scheme where its users would unambiguously assign themselves addresses through some hash function. Was it this one -> https://github.com/cjdelisle/cjdns/ https://github.com/cjdelisle/cjdns/ ? Anyway, I fully agree with you. Assigning meaningless (and therefore collision-prone and spoofable) numbers to people/machines just seems like such an arcane idea in light of all the cryptographic advances people have made. Whatever network I configure, I always need to worry about collisions or possible misconfigurations. Whether I set up some private VPN for myself and have to worry about potential spoofed IP packets from outside, or whether I connect to a corporate VPN from home and suddenly I can no longer ping 1.1.1.1 because their IT department couldn't be bothered to configure their routes correctly. It's insane.
- tambourine_man 3y agoMaybe it was cjdns, I don’t know, but I couldn’t find the particular talk on YouTube by that name. But yes, someday, maybe we’ll laugh at the current state of things and the shortage of IPs.
- linsomniac 3y agoI was thinking it might be https://yggdrasil-network.github.io/ https://yggdrasil-network.github.io/
- pbnjay 3y agoOk that’s fun. My home network is 10.3.x.x … can I somehow script to get my tailnet onto 100.103.x.x ? Now I need to investigate!
- SparkyMcUnicorn 3y agoLooks like you can configure that in the tailnet policy, according to the article.
- lucw 3y agoI setup a proxmox on a bare metal server to create development VMs. The solution that works for me is IPv6. Every VM that I create is publicly accessible, it's secured by a firewall and openssh public key only access. It's standards compatible, every smartphone and tablet has access, including chromebooks. Tailscale is not available on chromebooks. If tailscale looks interesting for your use case, but you'd rather have a standards compliant solution, look into IPv6. From an engineering perspective, it's a much cleaner solution.
- samcat116 3y ago> It's standards compatible What standard is Tailscale breaking? I agree your solution is more elegant and simple with less running components, but the trade off is more setup.
- deleted 3y ago[deleted]
- SparkyMcUnicorn 3y agoYou can install Tailscale on a Chromebook[0], you can also install it in the linux environment, and you can even get an SSH console from a browser that uses WASM to spin up an ephemeral node[1]. I used to have open ports publicly, but have since closed everything down and set up tailscale. Got tired of having to manage a firewall, religiously keeping everything up to date, and script kiddies trying to get in. Tailscale reduces management to near zero, or as close to zero as you can probably get. Even family members can use it, and without my help. On Android I don't want Tailscale connected all the time, so I have Tasker auto-connect whenever I open an app that needs LAN access. It's pretty convenient, but I'd still say it's the most inconvenient part of my current setup. [0] https://tailscale.com/kb/1267/install-chromebook/ https://tailscale.com/kb/1267/install-chromebook/ [1] https://tailscale.com/tailscale-ssh-console/ https://tailscale.com/tailscale-ssh-console/
- 1_ui2mas 3y agoStumbel guis
- tonymet 3y agoHow about IPv6 with distributed acl?
- lnxg33k1 3y agoThe only thing preventing me from using tailscale is that to register I need to give my data to shitty companies like Google, Microsoft or apple but i used it when I was at a company where I had a company github account and it was nice, but personally it’s not even for privacy, i just want nothing to do with those companies So i hope one day you will be able to register with user and password
- Operyl 3y agoDoes this not work for you? https://tailscale.com/kb/1240/sso-custom-oidc/ https://tailscale.com/kb/1240/sso-custom-oidc/
- hashworks 3y agoFor companies this is the way. But I guess for personal use a private Keycloak instance is a bit overkill?
- agarsev 3y agoI setup authelia specifically for this and it was barely a morning's work, and works beautifully.
- Operyl 3y agoYou certainly don't need a full on Keycloak installation here, if you don't want to go that far. There's various OIDC providers, some more complex than others!
- stryan 3y agoIf you already have LDAP or some other backing auth, setting up Dex for OIDC is pretty easy. Took me less than an hour or so. If you want something fancier Authelia isn't too bad, I got that running in an evening and hooking it up to Tailscale took another hour or two. Most of that spent figuring out how I want to do webfinger.
- 3y ago
- slt2021 3y agoThis blog is blocked by DNS Security solution because of "personal VPN".
- anonymousiam 3y agoI'm not sure how many have done this as well, but I've deliberately allocated lots and lots of elastic IPs on AWS in order to find one that I liked, for use by a long-living instance.
- noahjk 3y agoThere’s gotta be an overlap of people who do that and people who pick their phone numbers based on look, right? Which I do. I also recently changed my Tailscale host name (animal-animal.ts.net) and spent enough time cycling through choices to find a short, memorable, and pleasing one that I even started to question how I was spending my time.
- teddyh 3y agoThe eternal problem with companies like Tailscale (and Cloudflare, Google, etc. etc.) is that, by solving a problem with the modern internet which the internet should have been designed to solve by itself, like simple end-to-end secure connectivity, Tailscale becomes incentivized to keep the problem. What the internet would need is something like IPv6 with automatic encryption via IPSEC, with IKE provided by DNSSEC. But Tailscale has every incentive to prevent such things to be widely and compatibly implemented, because it would destroy their business. Their whole business depends on the problem persisting.