Hacker News new | ask | show | jobs
by pmarreck 398 days ago
Honest question- Would a full IPv6 implementation across the board, hurt Tailscale's M.O. and bottom line, assuming all routing worked properly (a big assumption, to be sure)?

You can probably guess the next question, if the answer to that one is anything like a "yes"

That said, my experiences with Tailscale have been nothing but positive and I appreciate the work they're doing to simplify Internet connectivity between endpoints inside different LANs and WANs

5 comments

I used to operate a home network all enterprisey and public Internetish, with VLAN, inter-VLAN routing & firewalling, a public IPv4 on the outside of an OPNsense router, and a Hurricane Electric free public /48 block (through their tunnel service) so that every node has at least one public IP... I ditched it all - I now operate a flat LAN with the ISP's standard box - and Tailscale everywhere. The only major functional difference is that services hosted on the LAN require an external reverse proxy (which I run on a free Oracle Cloud Ampere host)...

As a bonus, my family can call the ISP's tech support if anything dysfunction while I'm traveling: my self-hosting crap is perfectly independent from the ISP's standard service. And wait, there's more - I can add services anywhere, such as a backup server at my parent's, regardless of their configuration and with no impact.

So yes, Tailscale all the things... I'm nostalgic for the IPv6 flat end-to-end dream but, in our world of ubiquitous IPv4 NAT horrors, Tailscale functionally surpasses it.

    > Honest question- Would a full IPv6 implementation across the board, hurt Tailscale's M.O. and bottom line, assuming all routing worked properly (a big assumption, to be sure)?
Despite what people say, absolutely. Tailscale's moat is the centrally deployed NAT traversal solutions built with an easy-to-use interface and (somewhat) friendly pricing model. At one point they wrote a blog post (looks to be deleted) basically saying that IPv6 and direct connectivity in general is 'bad actually' or something along those lines.
Tailscale also goes through firewalls, not only NAT boxes. IPv6 won’t change firewall needs.
Can tailscale work when firewalls block outgoing udp from everywhere except the company web proxy server ?
I think I actually have that in production somewhere, going through DERP always
Tailscale can work anywhere you can get an https connection... but it might not be fast, since the relays used for this have various limits.
In my view, no.

The key thing it gives you is the ability to define policies about who can talk to what, irrespective of where the endpoints actually are, while also cryptographically protecting your traffic.

On the other hand, if you never ever use anything but HTTPS, then you probably don’t need it and you could do away with it today.

Yes.

But I haven’t the foggiest what the next question is.

Many network technologies/services exist to manage suboptimal circumstances, which would not be needed in better circumstances.

Would a full IPv6 implementation across the board, hurt Tailscale's M.O. and bottom line, assuming all routing worked properly?

Maybe, but even asking the question is kind of conspiratorial. Companies like Cisco, Google, and Apple have been pushing IPv6. A small startup can't somehow hold back IPv6 "world domination" even if they tried.