Table of Contents

Tailscale

A Mesh VPN system I dearly wish had existed a few years prior.

Authentication & Authorisation

Currently using the official control server with an MSOL account. Single tenant, not very pleased about it, but they won't give me a single-user enterprise account.

SSH

Honestly one of the best things about Tailscale. In use on all machines that support it.

ACLs

Plans

iptables-save output
-A PREROUTING -i tailscale+ -p udp -m udp --dport 53 -j DNAT --to-destination 172.21.0.53
-A PREROUTING -i tailscale+ -p tcp -m tcp --dport 53 -j DNAT --to-destination 172.21.0.53
-A POSTROUTING -s 172.21.0.53/32 -o tailscale+ -m mark --mark 0x40000 -j MASQUERADE