Spent some time messing around with Headscale (self-hosted implementation of the Tailscale control server).
I couldn't get "raw" WireGuard to work the way I wanted through nested firewalls and CGNAT so this seems like a good way to blow all that complexity out of the water. Less complexity is usually more reliable.
Headscale is pretty neat. Painless install on Debian.
Configuring Linux and Windows nodes is simple too - at least from a basic connectivity point of view.
I need to figure out how I'm going to deal with multi-homed DNS scenarios for clients. Something with very little thought and work through yet. Ha.
Now the hard part, picking apart the security and edge cases to use it regularly.
#Headscale #Tailscale #VPN #CGNAT #WireGuard #HomeLab #SelfHosted #SelfHosting #VPS
@RootMoose interesting. Any thoughts compared to Pangolin which I'm planning to use. I want remote access, so Pangolin on a cheap VPS is my plan. I'm new to this, but amazed how easy what I've done so far had been (OpenWrt router connected to mobile broadband, one Proxmox node, so far running a VM with HomeAssistant OS).