Subnet routers
Use subnet routers to give devices outside your local network access to services within specific subnets. Extend your private network with Tailscale.
If your remote access is you reaching a handful of web dashboards, install Tailscale and forget about it. It's got superb polish and is seamless for that use case. My case for NetBird is specific: I wanted a control plane that's the vendor's actual product rather than a third-party reimplementation of a closed one, and I wanted to tunnel things that don't speak HTTP without asking permission from a three-port allowlist. If neither of those is your problem, NetBird's stack is overhead you don't need. If both are, there isn't really a competition.
Tailscale recently made its free tier a lot more generous this year, with the user cap going up to 6 and the hundred-device cap being axed completely. I had been using it for easy remote access for my family far before the limit change, and right after, everyone decided that they wanted access to my media server around the same time. I quickly reached 6 users, and while I was tempted to just start paying Tailscale for more space, I decided to make use of the infrastructure I was already paying for with self-hosted NetBird, and I saved myself from paying a hefty monthly fee in the process. //
Headscale exists precisely for people in my situation, and it has a key advantage, being that it replaces only the coordination server, so official Tailscale clients can continue to be used exactly as they did. //
It's not a bad solution and plenty of people use it effectively, even in the same VPS-hosted configuration that NetBird is currently in for me, but the fact that it's not official means, like many other open-source community-maintained projects, that the maintainers can simply stop maintaining it. The self-hosted NetBird solution is an official part of the NetBird product, and therefore, it gets the same official support as the cloud-based solution.
Before we get into what Tailscale is or how it compares to a traditional remote access VPN, let’s take a quick look at Tailscale in action. The main problem Tailscale solves is remote access to your internal workloads.
In my homelab, I have a server running Linux. When I’m on my home network, I can access it directly without any issues. But if I step outside and want to access the same server over the Internet, Tailscale makes that much easier and you can have it up and running in about 10 minutes for free.