#wireguard
-
Headscale vs Tailscale Explained: What Actually Differs
Headscale replaces one Tailscale component: the control server. What that buys you, the three features it does not implement, and where the pricing flips.
-
Tailscale Subnet Router Configuration: Routes, ACLs, Tests
Advertise LAN routes, approve them with autoApprovers, scope access with grants, and handle the SNAT, MTU and overlapping-subnet traps before they bite.
-
Tailscale Exit Node Setup: Linux, ACLs, VLANs, and Tests
Configure a Linux Tailscale exit node, approve it, scope access with grants, isolate it on a VLAN, and verify IPv4, IPv6, DNS, and tunnel performance.
-
Tailscale Slow? Fix DERP Relay and Throughput Issues
Fix slow Tailscale transfers by checking for a DERP relay, restoring direct UDP, then tuning Linux offload, CPU, MTU and subnet routers.
-
How a Tailscale Mesh VPN Works: Coordination, NAT and ACLs
Understand the tailnet model: WireGuard mesh tunnels, the coordination plane, DERP relays, identity-based ACLs, subnet routers and exit nodes.