TailscaleGuide

Mesh path estimator

Tailscale latency and throughput estimator

Work out what a peer link should be capable of before you go hunting for the cause of a slow one. Put in your own measured baseline and the path type tailscale status is reporting, and this shows the round trip and the ceiling that follows from them.

Ping between the two sites over the public internet, outside the tunnel.

Whatever tailscale status prints next to the peer.

Extra round trip through the relay. tailscale netcheck lists your DERP latencies. Ignored on a direct path.

Usually one end's upload speed, not its download speed.

Coarse planning defaults, not measurements. Override if you have a real number.

What one WireGuard tunnel can push on that machine.

Tailscale documents that DERP relays offer lower maximum throughput because quality of service on them is limited, but publishes no figure. This is your assumption, not a specification. Ignored on a direct path.

Estimated round trip
24 ms
Estimated throughput ceiling
1000 Mbps

These are planning estimates derived from the numbers above, not measurements of your network. Confirm anything that matters with iperf3 run in both directions, over the tailnet address and then over the LAN address, between the same two machines.

Reading the three path types

Shown as What it means What to do
direct Peer-to-peer UDP tunnel. Lowest latency, highest throughput. Nothing. If it is still slow, the endpoints or the link are the limit.
peer-relay Forwarded by another device in your own network. Usually faster than DERP because it avoids distant routing, but still an extra hop. Acceptable. Worth chasing a direct path if the pair carries bulk transfers.
relay Traffic is crossing a Tailscale-operated DERP server. Works everywhere, slower than both of the above. Fix NAT traversal: dynamic port mapping, bridge a double NAT, or forward a UDP port.

How this estimate is built

Round trip is the underlying RTT, plus the relay detour when the path is not direct. A peer relay is charged an arbitrary one third of the DERP detour you enter. Tailscale documents only that peer relay is usually faster than DERP because it avoids a geographically distant server, and publishes no ratio, so that fraction is this page's rule of thumb and nothing more. If you have measured your own peer-relay hop, enter it directly as the detour and pick DERP instead.

Throughput is the lowest of three ceilings: the slowest link in the path, what the forwarding node's CPU can encrypt for a single tunnel, and the relay ceiling when the path is relayed. The result is reported as whichever of the three is binding, because that is the one worth acting on.

Nothing here models packet loss, congestion, disk speed at either end, or the overhead WireGuard adds per packet. Treat the output as an upper bound.

Next steps