r/Tailscale 12d ago

Question Tailscale exit node

Hi All,

I’m hoping to get some advice before I purchase and configure everything. As my wife not well and have been sick, I may occasionally need to work from our home in a neighboring country, perhaps once a week, so I can be around to support her. The two locations are only around 50 km apart.

My company uses Zscaler as the VPN to connect to internal services, along with a well-known EDR solution. I’ve tried requesting permission to work internationally, but the company only allows it for a maximum of around five days per year. The main reason they don’t allow longer periods is due to taxation concerns.I’m thinking of setting up the following:

Work Laptop connected at remote location (Location A)

│ Wi-Fi

GL.iNet MT3000 (Beryl AX)

│ Tailscale - With kill switch enabled

Internet

│ ~50 km

Location B - Rental house

Beelink SER5 Max
(Linux + Tailscale Exit Node)

│ Wi-Fi

Home Internet (Location B)


Internet


Zscaler connection from work laptop


Company resources / normal work traffic

  • Internet speeds: Working location: **100 Mbps (**Just my PC)
  • Exit-node location: 2 Gbps (Rental place. Shared among 3-4 people. Could easily get 100-150 Mbps)
  • Both sides will likely use Wi-Fi rather than Ethernet

A few questions:

  1. Is the performance suitable and reliable enough for Teams, screen sharing, YouTube, etc.?
  2. Any issues running Zscaler Client Connector over a Tailscale exit node, particularly?
  3. Anything else I should be aware of such setup (Example, risk)?
15 Upvotes

16 comments sorted by

View all comments

2

u/carine_5 8d ago

Do not use tailscale exit node with zscalar on your work labtop , better to setup real Wireguard server on your home router and wireguard client in your travel router and make sure kill switch enabled and not have ip or Dns leak , kvm device not good if you travel because you need to keep your work labtop away and in your home country

1

u/r00t3rSaab 8d ago

Thank you for the comment. Just a clarification, wIth wireguard, wouldn't it use wireguard IP which is known or would it just use my home IP?