
Tailscale Subnet Router Configuration: Routes, ACLs, Tests
Advertise LAN routes, approve them with autoApprovers, scope access with grants, and handle the SNAT, MTU and…
Featured Headscale replaces one Tailscale component: the control server. What that buys you, the three features it does not implement, and where the pricing flips.
Read the article →
Advertise LAN routes, approve them with autoApprovers, scope access with grants, and handle the SNAT, MTU and…

Configure a Linux Tailscale exit node, approve it, scope access with grants, isolate it on a VLAN, and verify…

Self-host the control plane or not, L3 overlay or L2 bridge, policy file or console. The three questions that…

Fix slow Tailscale transfers by checking for a DERP relay, restoring direct UDP, then tuning Linux offload, C…

Install Tailscale, connect two devices, verify a direct path, configure MagicDNS, replace default allow-all a…

Understand the tailnet model: WireGuard mesh tunnels, the coordination plane, DERP relays, identity-based ACL…
Four pages cover most of what people arrive looking for.
The model underneath everything else: coordination plane, NAT traversal, DERP relays, identity-based access rules.
Install to first tailnet in the order the decisions actually arrive, including closing the allow-all policy a new tailnet ships with.
Diagnose in priority order: relayed path first, then NAT traversal, then offload, CPU and whatever is forwarding in the middle.
Control plane ownership, network layer and policy model are the three questions that decide it. Headscale placed as well.
Put your own measured baseline against direct, peer-relay and DERP paths and see which ceiling is binding.