Tailscale

Just want to report that Tailscale was ridiculously easy to set up and is ridiculously great. No more need to leave an open port on my router to reach SecuritySpy remotely.

In his last Security Now! podcast episode the estimable Steve Gibson said that overlay mesh VPN networks such as Tailscale are now the clearly preferred solution for many purposes, essentially obviating hardware VPN's.

For those interested, Steve's comments:

"VPNs are definitely useful when you want to protect your use of the Internet for example, from your prying ISP. But setting up your own VPN server to provide incoming access is probably no longer the optimal solution. For all of those needs you really want to look at an overlay network. Think “TailScale” or “ZeroTier.” Overlay networks is the newer, better, more secure and much more powerful and flexible way to solve this sort of problem. We’ve talked about these before and I’ve received a bunch of feedback from our listeners who have said that they have been astounded by how easily the system was to install, setup and get running. And another advantage is that they run through NAT routers without needing any static port forwarding, so no bots are going to be probing for a connection. TailScale has a comparison page with ZeroTier which I’ve looked at in the past. It appears to be quite even handed. Since nothing else has claimed GRC’s shortcut of the week so far https://grc.sc/952 will take you directly to that page.https://tailscale.com/compare/zerotier/ I’m very glad that Michael asked this question since today’s new overlay network solutions really do represent a useful advance and a better way to solve the need for roaming access to a remote network."

Comments

  • Great to hear this was an easy setup and good solution for you. In our opinion, both Tailscale and ZeroTier are great solutions. For users wanting to use this method for remote access to SecuritySpy, full setup instructions can be found in our blog post Remote Access Without Port Forwarding.