Tailscale inside LXC | Secure remote access to your server | Proxmox Home Server | Home Lab

  Рет қаралды 53,025

MRP

MRP

Күн бұрын

Пікірлер: 171
@paul9812-t3i
@paul9812-t3i Жыл бұрын
Dude, you're an absolute legend. What a well explained, easy to follow tutorial. Brilliant stuff! Thank you
@thehostler0
@thehostler0 8 ай бұрын
Even though the video is just over a year old by now, the steps are exactly the same. I've followed your guide and ran into zero issues. Thank you :)
@aptiger23
@aptiger23 8 күн бұрын
Great video! Very easy to follow along. Fellow users... are you having trouble connecting to your proxmox server's GUI after a reboot? It's possibly your new tailscale container is not running! I double checked the video, and perhaps I missed it, but it does not mention to change the containers setting to "Start at boot". So please do this step! To save you the hours I spent trying to figureout what my issue was, here's my solution. You'll need access to the physical machine. Login as root. Type "pct list" to get your list of containers ("qm list" lists VMs) - This lists your containers IDs, Status, and Name. Type "pct start VMID" (eg. pct start 101) - This still start the container. You should now be able to connect to the WebGUI.
@KristijanDujakovic
@KristijanDujakovic 6 ай бұрын
Fantastic! Tried so many of the Tailscale Guides...this works from scratch, super easy 👍
@BeYourselfMan
@BeYourselfMan Жыл бұрын
Mr P, you are AMAZING!!!!! Big hug from Portugal. It works flawlessly.
@QEDAGI
@QEDAGI 7 ай бұрын
Don't know why I'd put off routing for a Proxmox server on my tailnet. You made it look so simple, I did it right away. Thanks!
@MrSamyWageh
@MrSamyWageh Жыл бұрын
This video is a life saver as I was looking for a VPN solution. As usual, detailed instructions and great guide. Thanks MRP.
@MarcelodeSouzaSilva
@MarcelodeSouzaSilva Жыл бұрын
Great! Looking forward to the next video showing how to use Guacamole in this container...
@NickSale-q6y
@NickSale-q6y 7 ай бұрын
Successfully installed Tailscale on a LXC thanks to you! Thank you!
@mijkal
@mijkal Жыл бұрын
Excellent guide - thank you! Got everything functioning in a Proxmox LXC by following along.
@hotrodhunk7389
@hotrodhunk7389 Жыл бұрын
I've tried so many other VPNs. Nothing worked with my cg-nat. But tailscale had zero problems finding a path. Works flawlessly for me.
@carlrudner
@carlrudner 7 ай бұрын
The only way i have managed to get tailscale to work on my home server! Thanks for this walk through.
@rasbe6863
@rasbe6863 Жыл бұрын
Thank you so much for your video. This is one of the most clear and concise videos I found so far to set this up.
@gasparem16
@gasparem16 Жыл бұрын
Absolutely great video! Clear, easy to follow and down to business :) Thanks a lot!
@MartinHyett
@MartinHyett Жыл бұрын
Thanks @MRPtech for such a useful video. It explained in exactly the right level of detail so I could get my Tailscale instance up and running in Proxmox, after previously struggling a bit with some of the steps needed. My only stumble was getting access to my LAN from my phone. It took me a while to realise that I needed to allow it to use the exit node. Then all worked perfectly!
@MRPtech
@MRPtech Жыл бұрын
Your welcome. Exit node will route all your traffic from your phone via your home network. Imagen it as VPN (Nord VM, Private Internet Access VPN and others). This is useful when you connected to public WiFi and all traffic goes from your phone back to your home network and then via ISP router to internet. I found this sometimes a bit slow as it need to go from my phone/laptop > home > router > ISP > internet If you want to access home network without Exit node, your tailscale instance at home can be converted into route-advertise node. Which makes that if you time local ip address for example 192.168.123.456 - tailscale will take that and push all traffic to your home network and everything else will go to World Wide Web.
@MartinHyett
@MartinHyett Жыл бұрын
Good point. I don't want to route internet traffic that way, just access those machines on my local network. So I guess I just need to use the advertise-routes argument and not the advertise-exit-node. I'm slowly beginning to understand it better. I hope!
@dimitristsoutsouras2712
@dimitristsoutsouras2712 Жыл бұрын
Nice presentation. I think you could also mention and make this guide more inclusive, by showing the way to create split or full tunnels for the clients.
@SamJones1337
@SamJones1337 Ай бұрын
Fantastic video and super helpful, thank you so much
@hypernarutouzumaki
@hypernarutouzumaki 8 ай бұрын
Hey, I really liked the setup! Could you also please do the promised video on setting up Guacamole that goes hand in hand with this tailscale setup?
@Heilzmaker
@Heilzmaker 2 ай бұрын
Exactly what I was looing for, thank you
@pr0jectSkyneT
@pr0jectSkyneT Жыл бұрын
Just found your channel. This video was very helpful to me. Subscribed
@rogerrogerovo2760
@rogerrogerovo2760 7 ай бұрын
the follow up video when? :) but a really good proxmox playlist you got here
@noquierounhandle
@noquierounhandle Жыл бұрын
Thank you so much for this tutorial. Clear as water!
@hristoistoyanov
@hristoistoyanov 5 ай бұрын
Best tutorial ever!
@Redd00
@Redd00 Жыл бұрын
Really amazing work and for something i havent ever thought of or used before! works great and the video was awesome
@HenriqueZacchi
@HenriqueZacchi Жыл бұрын
Excellent video. Short and precise!
@tonyMmonje
@tonyMmonje 11 ай бұрын
exactly what I am looking for. thank you
@daledroid
@daledroid Жыл бұрын
good work and explanation mrp, waiting for next video about guacamole
@meh8995
@meh8995 Жыл бұрын
did he post it?
@yarekm4270
@yarekm4270 Жыл бұрын
@@meh8995 im waiting as well
@jorgesoto7783
@jorgesoto7783 8 ай бұрын
Thanks a lot, worked like a treat!
@strix4040
@strix4040 Жыл бұрын
Absolutely great video, thank you
@joelcriollo3427
@joelcriollo3427 Жыл бұрын
Thanks bro! i really appreciate your video! It-s very helpful! Blessings!
@Bansmax
@Bansmax 6 ай бұрын
Works perfectly - thank you very much! Do you ever feel weird that Talescale is hosted by a 3rd party?
@MRPtech
@MRPtech 5 ай бұрын
to be honest ... i don't mind. As long as it works when i need to use it ... i am fine with that. Haven't said that, i am messing round with headscale - self-hosted tailscale server. This way i can host everything in my server, but at this moment i am not confident that i can do that fully and migrate all my connection to self-hosted state.
@Bansmax
@Bansmax 5 ай бұрын
@@MRPtech nice one! After using Tailscale for a week - it’s been a treat. So easy to use! Do you have an automated torrent setup on your proxmox?
@zxrenew5642
@zxrenew5642 Ай бұрын
Brilliant buddy thanks.
@ren3059
@ren3059 Жыл бұрын
Your video was incredibly helpful, and I want to express my gratitude. Thank you so much!
@oztechsolutions
@oztechsolutions 8 ай бұрын
Great video... thanks! Can you clear out something for me. Why do you need to SSH into that LXC container when you are already login on the terminal via proxmox?
@riskyrun
@riskyrun Жыл бұрын
Can I access the proxmox web UI from outside the LAN using tailscale?
@smneamat
@smneamat Жыл бұрын
Excellent ! Thank you so much. :)
@YourWizBlog
@YourWizBlog Жыл бұрын
Thank you so much for this excellent video. Worked like charm. For others, what I did not know is that you can access all remote IP's in that network directly from your computer if they are both connected to tailscale. Not sure what happens if both of the networks share the same IP range... but that is not the case for me.
@MRPtech
@MRPtech Жыл бұрын
What happened with your setup is "subnet advertising" Let's say you have two devices and they are 1000 miles apart. One is in Europe and another one in US. Both are connected to same Tailscale Tailnet. You have turned on in EUROPE server. that means that when you connecting from US to Europe server you can access not only Europe server but all other devices that are in same network as Europe server. I hope that make sense
@MikeDeVincentis
@MikeDeVincentis 6 ай бұрын
He's asking what happens when both sides have the same network scheme, like 192.168.1.x on both sides. Can you still access or will you have to change one of the networks?
@Kiduk90
@Kiduk90 Ай бұрын
Sorry im a little confused - I have successfully followed all the instructions and all seemed fine. After setting this up, how do I access my Home Proxmox Server remotely when say I am at my work office?
@MRPtech
@MRPtech Ай бұрын
if you want to access proxmox stuff from your office (from another network) you need to have another tailscale device in that location: laptop, computer, phone ect. that device you have to connect to proxmox server via tailscale-subnet-advertising feature tailscale.com/kb/1019/subnets
@Whoamiv
@Whoamiv 18 күн бұрын
Good and clear instructions. But I have the same question. Installation is complete and lxc host added to tailscale. I can SSH into the newly created lxc using the tailscale IP it gives me. But how to setup the tailscale vpn to access the Proxmox UI?
@gabscar1
@gabscar1 7 ай бұрын
Great video. Subscribed!
@cyrilpinto418
@cyrilpinto418 6 ай бұрын
Hi your videos are amazing; could you consider making a video on Wireguard within a Container on a proxmox? Much appreciated.
@ninefox344
@ninefox344 27 күн бұрын
If tailscale is installed this way are you still able to access the proxmox webui remotely? Thanks for your great tutorials and on top of that answering questions you get here. You are a godsend.
@MRPtech
@MRPtech 27 күн бұрын
Thank you for comment ! Yes. I can access proxmox web UI and any device in my local network as long as tailscale is running/online and subnet advertising is setup correctly.
@sp4m3r
@sp4m3r 9 ай бұрын
Great video! thank you very much. What would you say regarding security? I mean opening tailscale to access the whole home network?. Thanks!
@swubutu
@swubutu 11 ай бұрын
thanks for this tutorial ... Its Kungfu Magic !!!
@אדירטראבלסי
@אדירטראבלסי 2 ай бұрын
a big LIKE!
@KorayKüpe
@KorayKüpe 3 ай бұрын
Great tutorial, thanks a lot. I am unable to use Homekit Bridge with this setup. I enter the homekit pair code and it says unable to add accessories. What may be the problem?
@hprompt166
@hprompt166 Ай бұрын
hi there, got this working, how do I get the tailscale lxc to advertise the routes and exit node after a reboot
@petermarin
@petermarin 4 ай бұрын
Do you still needs that change in the proxmox configuration if you’re doing this into a VM?
@ryd3v
@ryd3v 6 ай бұрын
just wondering why allow root ssh login, when you can use ssh authorized key instead?
@theoqueiroz
@theoqueiroz Жыл бұрын
Great video. I just have one question: at 08:16 do we need to add the advertise options everytime the server comes up or just for the first time? I get a warning message saying that UDP GRO forwarding is suboptimally configured on eth0. Thanks for this awesome step-by-step!
@MRPtech
@MRPtech Жыл бұрын
During first initial setup you need to put advertising tag. If you restar lxc container, tailscale automatically will enable advertising on. If you run command "sudo tailscale down" and later you want to turn it on by running command "sudo tailscale up" you will have to add advertising on again as inside your tailscale net this node will be with advertising flag which means you need to initiate advertising again. I hope all this makes sense :)
@theoqueiroz
@theoqueiroz Жыл бұрын
@@MRPtech Got it, thanks! Any info on that warning message?
@GimmeAll
@GimmeAll 7 ай бұрын
@@theoqueiroz Did you ever figure it out, iam getting the same message ?
@netelijah
@netelijah Жыл бұрын
can you make a video on setting jellyfine, with sonarr and radarr on proxmox using truenas as the storage. please thanks
@TheStealthbob
@TheStealthbob Жыл бұрын
Doing the same now...Truecharts while easy at first are a hot mess when they change. Migrating everything off of Truenas
@rodrigobarbosa6381
@rodrigobarbosa6381 4 ай бұрын
thank you a lot!!
@caffeinatedw-w
@caffeinatedw-w Жыл бұрын
I finally was able to follow your video and setup Tailscale. Thanks a lot for this helpful video! I have a quick question btw, is router-advertising for the whole LAN devices a security concern? Let’s say I want to exclude one LXC from being exposed in Tailscale, is there any rule that I can set up? Many thanks!
@MRPtech
@MRPtech Жыл бұрын
Yes. but it is not that easy to tell in words. Basically - setting up Tailscale ACL security and assigning tags to your tailscale NODES. For example TAG_1 can only access TAG_2 and TAG_3 machines. if you LXC container is tagged with TAG_4 that makes it outside allowed list and can't be accessed. I am planning to get that video done over weekend in hope to be live by mid next week.
@caffeinatedw-w
@caffeinatedw-w Жыл бұрын
@@MRPtech Thank you, I ended up setting specific IP being exposed like this, tailscale set --advertise-routes=192.168.68.x/32,192.168.68.x2/32,192.168.68.x3/32
@MRPtech
@MRPtech Жыл бұрын
ok. i didn't know that. You can expose single IP instead of all network o.O? Well ... learn new thing every day. Thank you for sharing that !
@realabzhussain
@realabzhussain 10 ай бұрын
Do you have to enable subnets and exit node for EVERY machine in the network - or only 1 machine? Thanks
@stephenlau3690
@stephenlau3690 8 ай бұрын
Unfortunately, tailscale conflicts to smb in synology nas, the intranet transfer will drop to 0kb once tailscale on in nas.😢 Any way to avoid it?
@mixtereE
@mixtereE 6 ай бұрын
Dear Mr P: Can you provide the order of videos to have the ubuntu lxc template created and other settings needed to complete this tutorial? You mention that the ubuntu template was created in a previous video but I could not find it. Are you using a specific version of ubuntu 22.04, server or reguluar? Am I setting up the datacenter like you advise in your first proxmox video, to just have one pve and not local, local lvm and local network? You provide great content, just sometimes miss things that are crucial for us newbies. on another video I followed your guidance for a zfs cluster until I learned that my random old computer's mix of hardware could not run it- too late. Then I had to uninstall everything. It would be great to have some successes! thanks for doing this !
@MRPtech
@MRPtech 6 ай бұрын
Hi, Setting up LXC Template : kzbin.info/www/bejne/Y3TXhIGimrKBnKssi=tsCuZ-URrQwKndxV If your setup has two drives inside, i suggest to remove Local-LVM and use 2nd drive to store your ISOs, Temaplate, VM Disks. 1st drive - leave that to Proxmox OS.
@mixtereE
@mixtereE 6 ай бұрын
@@MRPtech Thanks. Got it up and running. For those other newbies there is a feature when you create an lxc that allows you to choose a template. I was under the impression that one had to be created, like in mr p's video in the proxmox playlist.
@snailprogrammer7483
@snailprogrammer7483 Жыл бұрын
Will this allow me to login to the PVE panel (port 8006) to view everything away from my house?
@MRPtech
@MRPtech Жыл бұрын
Yes. As long device you are using to login is connected to same tailscale account as PVE tailscale instance
@baileyboy3687
@baileyboy3687 Жыл бұрын
Good video and step by step very informative. So, the video just seemed to finish. How do we actually connect to our different home machines from outside world?
@MRPtech
@MRPtech Жыл бұрын
Because tailscale lxc has subnet advertising on. using any other device with tailscale install and same account used to login you can access your local network devices from anywhere in the world. I have tailscale app on my phone. and used same account to login. now i can access home NAS from anywhere in the world because tailscale lxc has --advertise-routes ON
@baileyboy3687
@baileyboy3687 Жыл бұрын
@@MRPtech ah ok thank you and will give that a try
@mikekane9734
@mikekane9734 Жыл бұрын
Thanks a lot! Question, did I miss the referred video with a remote system Remina/Guacamole? Or it is still in plans?
@MRPtech
@MRPtech Жыл бұрын
Remmina / Guacamole videos to come. as i have to publish couple videos in between to make more sense when you watching Remmina / Guacamole video.
@mikekane9734
@mikekane9734 Жыл бұрын
Thank you so much@@MRPtech ! Looking forward to it.
@mikekane9734
@mikekane9734 6 ай бұрын
@@MRPtech Hi, I just re-watched this video. And still wondering if you shot that videos?
@BobWorrall
@BobWorrall 6 ай бұрын
very clean
@daviduartecarvalho2796
@daviduartecarvalho2796 Жыл бұрын
Thank you!
@SB-qm5wg
@SB-qm5wg 8 ай бұрын
Good video. TY
@gentillidiego
@gentillidiego 5 ай бұрын
incredible
@dude1077
@dude1077 13 күн бұрын
Hi, i followed the steps and set have it all set up, yet i am unable to remote into proxmox remotely from my other devicec(using 5g hotspot to test it, it also has tailscale installed) i am able to ping the tailscale ct and im able to ssh into it, yet i am unable to acces the proxmox VE using the adress it got assigned by tailscale
@MRPtech
@MRPtech 12 күн бұрын
tailscale instant inside your local network - do you have subnet advertising ON ? tailscale.com/kb/1019/subnets
@heromasum
@heromasum 6 ай бұрын
Where's the remotely access proxmox server and container/lxc video?
@wayland2837
@wayland2837 Жыл бұрын
Great video and thanks for making it. I followed you video precisely and I even double checked my work and I cannot access the proxmox admin console remotely. I can access the tailscale lcx container via ssh. What am I missing? Thanks again.
@MRPtech
@MRPtech Жыл бұрын
1. Do you have subnet advertising active on tailscale node? 2. If subnet advertising active, did you approved that via tailscale admin dashboard for that node?
@wayland2837
@wayland2837 Жыл бұрын
Yes I do have subnet advertising active on the tailscale node. I did approve the subnet advertising via the tailscale admin dashboard for the node.
@MRPtech
@MRPtech Жыл бұрын
How you trying to access proxmox dashboard. Via tailsclale IP or using local net IP 192.168.*.*:8006 ?
@swubutu
@swubutu 7 ай бұрын
Hi MRP, i'm wondering if you are going to create a Tutorial Regarding Headscale ;)
@MRPtech
@MRPtech 7 ай бұрын
I have already started to mess around with Headscale ... will see where this will take me ;)
@swubutu
@swubutu 7 ай бұрын
@@MRPtech I'm sure you going to fix this ... i'm messing around aswel but for some ReasonS, every time a new error pops up during setup :D
@iamdiego87
@iamdiego87 5 ай бұрын
With your very food guide I was able to install tailscale in a Proxmox lxc. But how can I access my proxmox VM remotely? Es. In one VM I've installed home assistant and I would like to access It from my phone where I've installed tailscale.
@MRPtech
@MRPtech 5 ай бұрын
You need to switch advertising-routes=A.B.C.0/24 inside that tailscale. And switch that option on in tailscale dashboard. Once you done that you can access all services that are in home network from you phone from anywhere in a world as long as you have tailscale running in your home lab and your phone.
@SpikeCooks
@SpikeCooks 6 ай бұрын
I can access the subroutes, however i cant connect to my truenas smb share? any settings I need to fiddle with in proxmox or the tailscale container to get it to work?
@SpikeCooks
@SpikeCooks 6 ай бұрын
literally just solved it, but in my proxmox host, I went to firewall>add>macro>smb and it worked! hope this can help anyone else :)
@krumelmonstertv2266
@krumelmonstertv2266 Жыл бұрын
Thank you so much
@kvmgz
@kvmgz Жыл бұрын
Hi there. Is there a way or a need to update the tailscale server itself? Or the apt update & upgrade resolves this?
@MRPtech
@MRPtech Жыл бұрын
Hi, apt update // upgrade will do that for you. When you installing tailscale via command line, tailscale repo URLs added to a list of all the repos that apt update/upgrade need to do, tailscale will be one of them.
@rodrigopereira7365
@rodrigopereira7365 8 ай бұрын
TY so much
@DanielPostma-xn2yr
@DanielPostma-xn2yr 6 ай бұрын
Hello, when i tried to ssh into the tailscale vm/ct. I get a erro Permission denied
@MRPtech
@MRPtech 6 ай бұрын
Open your tailscale console via Proxmox and check file /etc/ssh/ssh_config check if line bellow is active (remove # from the start of that line) PasswordAuthentication yes This way you will be able to ssh into Tailscale VM/LXC using username + password.
@vitezism
@vitezism 2 ай бұрын
I thought port forwarding is less secure? What is the port forwarding here doing? The ponit of VPN is to not open ports.
@MRPtech
@MRPtech 2 ай бұрын
There is no need to open a port for tailscale to function. Where in a video am I explaining that we need to "open a port" ?
@vitezism
@vitezism 2 ай бұрын
@@MRPtech At 6:05 you are removing comments from something about forwarding, so I didn't understand that part.
@MRPtech
@MRPtech 2 ай бұрын
that is not port forwarding, that is IP forwarding. By doing that you can use tailscale feature which is call "subner-routing" tailscale.com/kb/1019/subnets Let's say you have a smart fridge with web UI which you can ONLY access while you at home. But what if you want to access that UI when you are not at home? subnet routing allows tailscale nodes to see all local network devices. You can achieve same results with VPN. With Tailscale, you don't need to do any key generation, user creadentials ect. If you have tailcale node inside network and subner-route is configured correctly - all network devices are visible to all tailscale devices. btw - Tailscale allows ACL for better permission control.
@vitezism
@vitezism 24 күн бұрын
@@MRPtech Ok that makes sense, but it is still required if that smart fridge is already connected to homeassistant in proxmox VM? Since everything in proxmox network is shared? Also, when running tailscale up with advertise routes and exit nodes, I get Warning: UDP GRO forwarding is suboptimally configured on eth0, UDP forwarding throughput capability will increase with a configuration change.
@tokk3
@tokk3 14 күн бұрын
how can I start talescale on boot?
@MRPtech
@MRPtech 14 күн бұрын
Tailscale inside LXC container start on boot automatically. It is installed as a service during installation process.
@kiptanoi4422
@kiptanoi4422 9 ай бұрын
Hello, I have a question. I am new to proxmox, container and so on.... I am wondering, If I could run 2 stuff in the same container? I have one container with lxc "turnkey mysql" running And after I watched your video I have one container lxc "Tailscale" running Can I do one single container with both tailscale running and mysql running on it? And how do I do that?
@MRPtech
@MRPtech 9 ай бұрын
If you want to have one LXC container with MySQL and Tailscale - i suggest to start with Ubuntu LXC container and install MySQL and Tailscale inside it. For more easier installation process i would go with Ubuntu Server VM.
@kiptanoi4422
@kiptanoi4422 9 ай бұрын
@@MRPtech Oh, cool thanks, do I win something in resourses and so on to have one single container that manage small stuff like MySQL and Tailscale in the same container, or do I want separate containers for MySQL and Tailscale running?
@Montagic
@Montagic Жыл бұрын
Got this setup and everything connected, but I can't seem to figure out how to get my phone to connect over my data. I think it's working as I'm able to access my VMs from other VLANs like IoT and Guest, but not when I disconnect from wifi. I'm running Arista NG Firewall (untangled) so not sure if maybe that could be blocking things.
@MRPtech
@MRPtech Жыл бұрын
Hi, Have you turned "--advertise-routes" option during initial "tailscale up" setup?
@Montagic
@Montagic Жыл бұрын
@@MRPtech Fixed it! Turns out it doesn't work if you are using it as an exit node on data. Not sure if that is a bug or feature..still new to how all of this works haha
@nadpul
@nadpul Жыл бұрын
How to access proxmox and containers using hostname instead of IP? Thank you.
@MRPtech
@MRPtech Жыл бұрын
I am using tailscale and its feature called "smart dns" which resolves all my local IPs in to hostnames. Alternative would be to use PiHole and its Local DNS option.
@telefoonjoost
@telefoonjoost Жыл бұрын
For some reason after following your guide, when I enable advertise-route from the admin panel of tailsce, my entire home network doesn't have a data connection anymore. When I disable advertise routes the devices on my network can connect to the outside Internet again. Very strange... Do you have any idea?
@MRPtech
@MRPtech Жыл бұрын
1. On which side you do "advertise-routes" Inside LXC? 2. Once you have advertise-routes ON - are you confirming that inside tailscale Admin panel?
@meh8995
@meh8995 Жыл бұрын
i followed the guide step by step but the tailscale doesn't work also kindly did u post the following video for the apps u mentioned at the end (remena guacamole?) 13:35
@MRPtech
@MRPtech Жыл бұрын
Remmina / Quacamole tutorial will be done. What errors do you get when trying to ping Tailscale IP ?
@meh8995
@meh8995 Жыл бұрын
@@MRPtech i wanna ask you what is a good way to access the OS of pve remotely without opening the panel of it
@meh8995
@meh8995 Жыл бұрын
@@MRPtech I fixed the tailscale, i think XD
@edgecrush3r
@edgecrush3r Жыл бұрын
Is there any way to tell my connected devices to us a local DNS server?
@MRPtech
@MRPtech Жыл бұрын
You need to install tailscale client on each device and login with same account to use DNS server. In my case i have local DNS server, this server IP is logged inside tailscale dashboard and any device (with tailscale client installed) hits that DNS server first before going to 1.1.1.1
@wali8976
@wali8976 Жыл бұрын
is there a way to make your proxmox GUI available from anywhere without IPV4 forwarding?
@JesusFranco01
@JesusFranco01 Жыл бұрын
Yes. Cloudflare tunnel is a great way. Use the Applications Access feature to add additional layers of protection.
@meh8995
@meh8995 Жыл бұрын
@@JesusFranco01 any free way?
@JesusFranco01
@JesusFranco01 Жыл бұрын
@@meh8995 cloudflare tunnel has a free tier ;)
@mihleo6391
@mihleo6391 Жыл бұрын
Why dont you just use wireguard?
@MRPtech
@MRPtech Жыл бұрын
1. With Wireguard for some reason i get slower speed connecting to server from outside home network. With tailscale i get close to full speed 2. Tailscale is based on wireguard so technically i am using wireguard.
@bluesquadron593
@bluesquadron593 Жыл бұрын
Hi, I am facing this issue for " tailscale status # Health check: # - Some peers are advertising routes but --accept-routes is false" I cant ping the IPs from the routes IP range given in the LXC tailscale-up command.
@MRPtech
@MRPtech Жыл бұрын
1. Where is your main tailscale setup located? LXC/VM? 2. Which device you are using to try to ping local network IPs ? 3. Have you enabled "--advertise-routes=192.168.X.0/24" during first Tailscale run and turned on "IPV4 Forwarding" ?
@bluesquadron593
@bluesquadron593 Жыл бұрын
@@MRPtech Hi, followed your guide. So I have it in an lxc. I am getting this message from a remote server with tailscale on it. That server still can't ping anything in 192.168.1.0/24.
@bluesquadron593
@bluesquadron593 Жыл бұрын
@@MRPtech Ok, the solution was that on my other tailscale instances I had to spin down tailscale and bring them up with "tailscale up --accept-routes".
@vincentmartin2528
@vincentmartin2528 24 күн бұрын
I did this step by step and advertised 192.168.10.0/24. However, from my laptop on a remote network I can only ping 192.168.10.1 but no other IP's on the network. No idea what the problem is. Same issue when setting up the subnet router on a Windows 10 box and Ubuntu server 24.04 VM. Pulling my hair out at this point. Anyone else have this problem?
@dominick253
@dominick253 Жыл бұрын
I tried it inside an lxc container and it threw kernel header errors. Switched to a vm and it works just fine 🙂
@MRPtech
@MRPtech Жыл бұрын
Error you where getting could be because LXC container was Unprivileged.
@petermarin
@petermarin Жыл бұрын
why did you uncomment the permit root access part?
@MRPtech
@MRPtech Жыл бұрын
Because i want to give SSH access to ROOT user. If i leave that commented, root user can't connect via SSH, only normal users will. This is not recommenced. If someone will guess root password and gain access via SSH, they will have access to entire system. I done it just out of convenience and not necessity
@petermarin
@petermarin Жыл бұрын
@@MRPtech I appreciate the reply!! Can you show us the alternative that’s more secure? (New to this)
@MRPtech
@MRPtech Жыл бұрын
Instead of using root you can login with normal user. If you don't have a user created: first - login as user and type adduser Finish setting this up, next you need to add user to SUDO group, command: usermod -aG sudo On next fresh USER login SUDO will be activated. Now you can SSH with user instead of ROOT. Suggestion - create SSH keys for better security.
@manologitech
@manologitech Жыл бұрын
Great
@sonny8085
@sonny8085 8 ай бұрын
Why don't you just install Tailscale straight onto the Proxmox host?, instead of the need to create an LXC/VM?
@MRPtech
@MRPtech 8 ай бұрын
When i started to mess around with Proxmox, i used to install a lot of stuff directly to Proxmox HOST. And one day Proxmox stopped working. Was it because i installed other stuff on the HOST or something else ... don't know. Now i follow a rule - do not install anything on Proxmox HOST unless o have no other option. For example Zabbix - i had to install Zabbix agent on Proxmox host to monitor each node, for Tailscale - there is no extra benefits to have tailscale inside proxmox host compared to LXC.
@BeNtOoOoOo
@BeNtOoOoOo 5 ай бұрын
Why not just run Wireguard without tailscale, i don't get why would people add an extra layer when wireguard works wonders.
@MRPtech
@MRPtech 5 ай бұрын
wireguard make connection and that is it Tailscale add sooooo much moooore to just making a connection.
@BeNtOoOoOo
@BeNtOoOoOo 5 ай бұрын
@@MRPtech it doesn't make a "connection" it makes a tunnel and a virtual network between the server and one or several clients. It also can route traffic from and to the LAN. So i really don't get what else tailscale can do...
@BeNtOoOoOo
@BeNtOoOoOo 5 ай бұрын
@@MRPtech also, wireguard is 100% private, yours, non internet or outside dependant. Everything i need to my wireguard to work is my own wireguard server... Nothing else. Is it ease of use? I can't see other reason really.
@MRPtech
@MRPtech 5 ай бұрын
Can wireguard: a) allow me to connect to wireguard nodes via SSH using browser? b) allow me to expose service to a public via tunnel? c) give me split DNS feature? d) provide me with custome domain? for example ibis-galaxy.net ? e) provide me an easy way to setup ASL rules?
@BeNtOoOoOo
@BeNtOoOoOo 5 ай бұрын
@@MRPtech I don't think you understand how it works really... Wireguard it's a VPN, same as tailgate. ASL rules, split DNS and all you mentioned are handled by the server at your home. It just routes traffic to the tunnel, what you do with that traffic is up tou you... You want to split DNS? Then you just have to config it as such... You can do anything you want as if the client was in LAN, that's the point. You basicaly deal with wireguard trafic as you would deal with a VLAN. So yes... You can do all that and more, depends on your setup.
@rezenclowd3
@rezenclowd3 4 ай бұрын
Why are you doing a static IP in the dhcp pool? Your DHCP server now may assign the same IP to another computer.... Instead do a DHCP static mapping on your DHCP server and apply your MAC address, or do a static IP in the LXC outside of your DHCP server pool range. IE 192.168.1.1/24 is your LAN. Setup your DHCP pool to be 192.168.1.100-254. That way you have ~99 IPs to use for static IPs depending on where your Gateway is (could be 1.1, could be 1.254 or anywhere in between)
@MRPtech
@MRPtech 4 ай бұрын
Yes, you can do that. I set static IP in LXC config as it is much easier and same for everyone. I can't explain each and every router configurations and how to complete them. Plus - tailscale LXC container is my gateway to home network from outside and it is always running and Proxmox HA setup done. Maximum downtime 5 - 10 min. DHCP server will release IP to another device if Tailscale LXC container will end up offline for 15 days.
@CcnaLife
@CcnaLife 8 ай бұрын
good video but you didn't sht up for 1 second thruout the video... wish you took short breaks
@MRPtech
@MRPtech 8 ай бұрын
Agree. This one was more like speedrun
@petermarin
@petermarin 4 ай бұрын
Do you still needs that change in the proxmox configuration if you’re doing this into a VM?
@MRPtech
@MRPtech 4 ай бұрын
No. With VM you don't need to do that.
#behindthescenes @CrissaJackson
0:11
Happy Kelli
Рет қаралды 27 МЛН
Air Sigma Girl #sigma
0:32
Jin and Hattie
Рет қаралды 45 МЛН
Caleb Pressley Shows TSA How It’s Done
0:28
Barstool Sports
Рет қаралды 60 МЛН
$1 vs $500,000 Plane Ticket!
12:20
MrBeast
Рет қаралды 122 МЛН
The Ultimate Guide to Tailscale on Unraid
1:36:07
The Uncast Show
Рет қаралды 8 М.
Self Host Tailscale with Headscale - How To Setup
21:51
Jim's Garage
Рет қаралды 81 М.
how did I NOT know about this?
23:06
NetworkChuck
Рет қаралды 938 М.
Protect Your Home-Lab using Proxmox SDN and Firewall
38:59
#behindthescenes @CrissaJackson
0:11
Happy Kelli
Рет қаралды 27 МЛН