Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The big distinction is that for Tailscale both endpoints know they want to talk to each other, and that both have Internet access. That's not the usual case firewalls are designed for.

Tailscale doesn't strictly need NAT traversal. They can run only their DERP servers and still continue to work. If your firewall tries to block two devices from communicating and yet allows both devices internet access, you have already lost.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: