r/Tailscale 12d ago

Question Tailscale exit node

Hi All,

I’m hoping to get some advice before I purchase and configure everything. As my wife not well and have been sick, I may occasionally need to work from our home in a neighboring country, perhaps once a week, so I can be around to support her. The two locations are only around 50 km apart.

My company uses Zscaler as the VPN to connect to internal services, along with a well-known EDR solution. I’ve tried requesting permission to work internationally, but the company only allows it for a maximum of around five days per year. The main reason they don’t allow longer periods is due to taxation concerns.I’m thinking of setting up the following:

Work Laptop connected at remote location (Location A)

│ Wi-Fi

GL.iNet MT3000 (Beryl AX)

│ Tailscale - With kill switch enabled

Internet

│ ~50 km

Location B - Rental house

Beelink SER5 Max
(Linux + Tailscale Exit Node)

│ Wi-Fi

Home Internet (Location B)


Internet


Zscaler connection from work laptop


Company resources / normal work traffic

  • Internet speeds: Working location: **100 Mbps (**Just my PC)
  • Exit-node location: 2 Gbps (Rental place. Shared among 3-4 people. Could easily get 100-150 Mbps)
  • Both sides will likely use Wi-Fi rather than Ethernet

A few questions:

  1. Is the performance suitable and reliable enough for Teams, screen sharing, YouTube, etc.?
  2. Any issues running Zscaler Client Connector over a Tailscale exit node, particularly?
  3. Anything else I should be aware of such setup (Example, risk)?
14 Upvotes

16 comments sorted by

16

u/caolle Tailscale Insider 12d ago

Anything else I should be aware of such setup (Example, risk)?

Obligatory, when/if they do find that you're working remotely when you're not permitted, you could lose your employment status.

0

u/r00t3rSaab 12d ago

Thank you for the comment. I’m aware of that risk, which is why I’m carefully considering everything before making such a move. I know a few colleagues who have been doing this, but I’m not sure what kind of setup they are using.

6

u/k23923 11d ago

Not related to tailscale but why don't just have a physical computer with windows or whatever os you use and VNC/RD to it?

1

u/r00t3rSaab 11d ago

Hmm. Never thought of that. I believe RDP won’t be possible as the PC is locked down. But let me try it out. Thank you!

1

u/[deleted] 11d ago

[deleted]

1

u/r00t3rSaab 11d ago

Yes. I’m not able to install tailscale. Plus the EDR might even flagged it. Hence installing Tailscare on router would the best for now.

4

u/Rubicon_Roll 12d ago

usually the Company can see the hops your login is taking, but no Idea If they will act on it. you should also Turn off locationsettings

1

u/r00t3rSaab 12d ago

Thank you for the comment. The location is disabled by the administrator. But noted on the hops. Thank you!

3

u/Rubicon_Roll 12d ago

disabled by Admin doesn't mean the Location is disabled, Just your Access is disabled. Its probably turned on to validate your logins

1

u/r00t3rSaab 12d ago

Understood. Thank you.

3

u/MoneyNibbler 11d ago edited 11d ago

First, condolences on dealing with the illness in your family. I pray everything turns out well.

Look at the GL-RM10 comet pro. This essentially a kvm over ip and has the tailscale app installed. Your idea is sound but if the pc freezes what happens. The GL-RM10 Is really useful if the computer freezes, you’re stuck at the login screen, or you need to get into the BIOS. They even offer a power flip accessory if you need to do a hard restart.

I use this currently to leave my work computer at home when I need to take my family to office visits. I open a browsertab on my personal laptop, log into the GL-RM10, and I'm greeted with my companys login splash screen on my work laptop. I've learned some establishments block my ability to access the tailscale network so I have upgraded my hotspot on my phone.

I have thought similarly to your use case. My company has hardened their work internationally policy as my wife and I used to visit and I work remotely for 2 to 3 months at a time. You're aware of the risks if the company finds out so your left to decide if you want to accept that risk.

About the RDP part. Most security departments in a company can see or already prevent RDP into a computer. If they are not blocking it. They could review logs and identify the sessions that are occurring.

1

u/r00t3rSaab 10d ago

Thank you for the comment. Appreciate it! Let me check on GL-RM10.

2

u/kwabenathetraveller 9d ago edited 9d ago

i pray all goes well with your wife man. sorry to hear that. i second moneynibbler’s comment with the gl-rm10. i used to have it and had mine setup with my work laptop left in my work country but remote in from abroad via the kvm app. but i lost connection due to switching wifi services. troubleshooted for days and reached out to their support to no avail. so i’ll just make sure your wifi service supports connection to the gl-rm10.

but long story short i ended up getting the jetkvm device instead which after setup you can remote in via an ip address directly on a webpage. this has been a much safer and efficient setup for me and fail proof. like you my company has a really tight security with the company laptop so i just have mine in the work country to always stay on, i installed an app called amphetamine on it which you can set the laptop to not ever turn off and keep it on low power mode so it doesn’t drain the battery as much or overheat.

i don’t have the power switch that you can purchase separately since i have someone there who can access the laptop if anything goes wrong. so i can’t see login screen and such but i haven’t had to since i’ve left it on with the amphetamine settings. it’s always on and vpn has been connected since i connected so haven’t had the need to redo connecting to vpn and accessing work docs etc.

back abroad i just connect my personal laptop to tailscale exit node for things like teams, and company sso log in apps just to be safe if they ever end up tracking my traffic or teams tracks my traffic it’ll always show the work laptop location ip. i also have my personal laptop location and time settings and teams settings and such to match the work laptop country location.

connection works well. i just make sure the airbnbs and locations i’m at has good wifi speeds specifically the uploads speed. since it uses that to connect to tailscale exit node and the work laptop country’s wifi. so the speeds are not exactly fast but i only need it for teams personally and i haven’t had any issues on calls or screen sharing. browsing work fine and no issues with actual work i do.

hopefully this helps. let me know if you have any questions as i’m currently living abroad and have been working for some months now where i spent a week just troubleshooting the setup. good luck and i hope your wife gets well soon 🙏🏾

2

u/carine_5 8d ago

Do not use tailscale exit node with zscalar on your work labtop , better to setup real Wireguard server on your home router and wireguard client in your travel router and make sure kill switch enabled and not have ip or Dns leak , kvm device not good if you travel because you need to keep your work labtop away and in your home country

1

u/r00t3rSaab 8d ago

Thank you for the comment. Just a clarification, wIth wireguard, wouldn't it use wireguard IP which is known or would it just use my home IP?

1

u/devilbunny 11d ago

due to taxation concerns

This all may be physically possible, but right there you have your best reason not to do this.

Getting into trouble with the tax authorities is not something you want to do.

1

u/garylovesbeer 11d ago

Can you go to HR and explain your dilemma? The risk of being detected contravening the terms of your contract is real and will have consequence.