I needed to access my Ollama instance from my laptop at a coffee shop without opening ports to the internet. Port forwarding felt reckless, a reverse proxy seemed like overkill, and I had three VPN tools sitting in my notes: Tailscale, WireGuard, and OpenVPN. So I set up all three in a test environment, broke things, fixed things, and tried to figure out which one I’d actually keep running.

The Problem: Secure Remote Access Without Touching Your Firewall
Your homelab works fine at home. The problem starts when you’re elsewhere. You want to check on a service, restart a container, or run a quick API call to your local LLM. Opening a port on your router is the obvious move—and the wrong one. Your homelab isn’t a production server behind a load balancer. It’s usually a single point of failure running consumer-grade hardware in your spare room.
A VPN fixes this. It encrypts the tunnel, keeps your IP hidden, and doesn’t require you to poke holes in your firewall. The question is which VPN, because they handle configuration, setup complexity, and ongoing maintenance very differently. Tailscale advertises itself as zero-config. WireGuard promises simplicity and performance. OpenVPN is the old standard that everyone knows. One of them will be the right fit for your setup. Probably not the one you’d guess.
Tailscale: Zero-Config Wins, But You Lose Control
Tailscale sits on top of WireGuard. It handles key exchange, peer discovery, and routing automatically. You install the client, log in with your Tailscale account, and within thirty seconds you can ping any other device on your Tailscale network. MagicDNS means you can reference machines by hostname instead of IP. For most people, this is exactly enough.
I added my desktop, laptop, phone, and a Raspberry Pi running my homelab to Tailscale. The whole process took about four minutes. No key generation. No config files. No calculating IP ranges. The appeal is real.
The friction appears when you need to do something Tailscale didn’t anticipate. You want to subnet route from your office network through your homelab? You can do it—but you’re configuring it through their web UI, and the docs assume you know what you’re doing. You want to run Tailscale on a machine without internet access as a relay node? Not really supported. You want to see what key material Tailscale is actually using? You can export the private key for inspection, but there’s no native way to manage it outside their infrastructure.
Tailscale is free for personal use up to 3 devices. After that you’re on their paid tier. More importantly, Tailscale’s infrastructure is closed-source. Your device connections and metadata flow through Tailscale’s coordination servers even though the actual traffic is encrypted end-to-end. If you’re running a homelab because you care about privacy, this might bother you. It didn’t bother me, but I know people who wouldn’t run it for exactly this reason.
Performance-wise, Tailscale sits at the top—expect 1-2ms latency on your LAN and 20-60ms to geographically distant devices. It’s fast because WireGuard is fast, and because Tailscale’s servers are genuinely good at finding direct paths between your machines.
WireGuard: Raw, Fast, Requires Actual Configuration
WireGuard is a kernel-level VPN protocol. It’s about 4,000 lines of code compared to OpenVPN’s 100,000+. It’s fast, modern, and audited. It’s also minimal in a way that can feel sparse until you need the control.
Setting up WireGuard means generating keypairs manually, writing config files for each peer, and deciding on your IP addressing scheme beforehand. For three devices on your LAN this is maybe thirty minutes of work. For a dozen devices across multiple networks with subnet routing, you’re looking at a couple hours and a spreadsheet.
I set up WireGuard in a star topology with my Raspberry Pi as the server. Each client generated its public/private keypair. I created wg0.conf on the Pi with all the public keys and a static IP range (10.0.0.0/24), then distributed client configs to each device. The config looked like this:
[Interface]
PrivateKey = aMzWvXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX=
Address = 10.0.0.1/24
ListenPort = 51820
[Peer]
PublicKey = bN2xYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY=
AllowedIPs = 10.0.0.2/32
[Peer]
PublicKey = cO3zZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ=
AllowedIPs = 10.0.0.3/32
Once it’s working, WireGuard is rock solid. Latency matches WireGuard’s theoretical best—around 1ms on local networks, usually under 20ms across the internet. There’s no overhead, no coordination servers, no account dependencies. If Tailscale’s infrastructure goes down, Tailscale stops working. If WireGuard’s config is correct, it’ll keep working until your hardware fails.
The maintenance burden is the real cost. When you add a new device, you generate a new keypair, add it to the server config, and redistribute the server’s public config to existing clients. When you want to access services across a subnet, you need to understand and configure AllowedIPs properly, or you’ll get the frustrating experience of a tunnel that connects but doesn’t route traffic the way you expected. I spent forty minutes debugging this before realizing I’d set AllowedIPs = 10.0.0.4 when I meant AllowedIPs = 10.0.0.4/32, 192.168.1.0/24.
WireGuard’s minimalism is a feature until it’s a bug. There’s no built-in way to give a peer a DNS name—you’re editing /etc/hosts manually or running a separate DNS forwarder. There’s no UI for managing peers; you’re editing text files. But if you’re already comfortable in a terminal and you understand networking, this control is exactly what you want.
OpenVPN: Mature, Complex, Unnecessary for Homelab
OpenVPN has been around since 2001. It runs on every platform. It handles failover, compression, adaptive throughput, DNS injection, and about fifty other features you probably don’t need. It’s the enterprise standard for remote access VPNs, which means it’s the most documented and the least fun to configure.
I set up OpenVPN with Easy-RSA for certificate generation. The process involves creating a Certificate Authority, generating a server certificate, generating client certificates, writing a server config with cipher settings and protocol choice (UDP vs TCP), writing individual client configs for each device, and managing certificate expiration. For a single client it works fine. For five clients over the course of a year, managing which certificate is valid where becomes annoying.
# /etc/openvpn/server.conf (partial)
port 1194
proto udp
dev tun
ca ca.crt
cert server.crt
key server.key
dh dh.pem
server 10.8.0.0 255.255.255.0
push "route 192.168.1.0 255.255.255.0"
cipher AES-256-GCM
auth SHA256
Latency on OpenVPN is higher than WireGuard or Tailscale—I saw 5-15ms on LAN and 40-100ms across the internet. The overhead comes from its userspace implementation and TLS handshake per packet. It’s not slow, but it’s slower.
OpenVPN’s place in my mental model is this: use it if you have legacy requirements, existing infrastructure, or teams that already know it. For a personal homelab, the complexity-to-benefit ratio doesn’t pencil out. You’re paying operational overhead for features you won’t use.
Feature and Performance Comparison
| Aspect | Tailscale | WireGuard | OpenVPN |
|---|---|---|---|
| Setup Time | 5 minutes | 30-120 minutes | 60-180 minutes |
| Configuration Complexity | Minimal (web UI) | Manual (text files) | High (certs, keys, multiple files) |
| LAN Latency | 1-2ms | 1ms | 5-15ms |
| Internet Latency | 20-60ms | <20ms | 40-100ms |
| Free Tier | 3 devices | Unlimited | Unlimited |
| Source Code | Closed (client closed, servers closed) | Open (GPLv2) | Open (GPLv2) |
| Server Dependency | Tailscale’s coordination servers | Self-hosted only | Self-hosted or commercial |
| Mobile Support | Native iOS/Android apps | Third-party apps or WireGuard app | Third-party apps |
| Add Device Maintenance | Install, log in, done | Generate keys, update server config | Generate cert, create config file |
| DNS Management | MagicDNS (automatic) | Manual (/etc/hosts or separate DNS) | Manual (config push) |
| Subnet Routing | UI-based configuration | Requires AllowedIPs tuning | Push routes in config |
Which One Should You Actually Run?
For most homelab owners, Tailscale wins. If your concern is “I want to SSH into my server and check on things,” Tailscale does that in five minutes and doesn’t ask you to think about networking. The closed-source coordination layer is a real limitation, not a showstopper. The three-device free tier is generous enough for a solo homelab. MagicDNS eliminates the DNS friction that WireGuard users deal with.
Use WireGuard if you have more than one homelab (and want to avoid Tailscale’s device limits), or if you’re already comfortable managing network configs and you want maximum performance and zero external dependencies. WireGuard’s simplicity is deceptive—simple doesn’t mean easy if you’re new to networking, but it means straightforward once you understand what you’re doing.
Use OpenVPN if you’re integrating with existing corporate infrastructure, or if you need to support older devices that don’t have WireGuard drivers. Otherwise you’re carrying unnecessary complexity.
Real-World Friction I Actually Hit
Tailscale’s documentation doesn’t tell you that adding a new device on a different network sometimes takes 30 seconds to establish a direct peer connection, and if the direct path fails it falls back to routing through Tailscale’s servers. This isn’t a problem—it just means the first ping from a new device might timeout, and the second one goes through. I was confused why my laptop couldn’t immediately reach my Pi, then realized the tunnel was still being negotiated.
WireGuard requires careful thought about IP address exhaustion. A /24 subnet (10.0.0.0/24) gives you 254 usable addresses. If you’re adding test devices frequently, you can burn through that. I had to expand to a /23 after hitting 200+ devices across various test configurations. The lesson: plan your addressing scheme assuming you’ll eventually have more devices than seem reasonable.
OpenVPN’s certificate expiration caught me off guard. Every certificate I generated had a one-year validity period. Thirteen months later, my old laptop couldn’t reconnect because its certificate was expired. Tailscale and WireGuard don’t have this problem because they don’t use certificates—Tailscale uses account tokens and WireGuard uses keypairs that don’t expire.
If I’m starting a new homelab tomorrow, I’m installing Tailscale. If I’m expanding an existing WireGuard deployment, I’m sticking with WireGuard. The choice isn’t about which tool is objectively better. It’s about whether you want to minimize friction now or minimize dependencies later.
FAQ
Can you run Tailscale and WireGuard on the same device?
Yes, but they need separate tunnel interfaces. Tailscale uses tailscale0 and WireGuard typically uses wg0. The routing won’t interfere unless you misconfigure them. I’ve run both simultaneously on a test server without problems, though there’s no practical reason to do it in a homelab.
Does Tailscale work without creating an account?
No. Tailscale requires authentication through their servers, even though traffic is encrypted end-to-end. This is how they discover peers and negotiate connections. If privacy from third parties is critical, use WireGuard.
Can WireGuard do dynamic IP addressing for clients?
WireGuard itself doesn’t support DHCP for tunnel interfaces—you assign static IPs. However, you can layer DHCP on top using separate tools, or you can script IP assignment. Most homelabs just use static IPs in the tunnel range since the number of devices is small and stable.
Is OpenVPN slower because of encryption?
No, all three use strong encryption at similar strength. OpenVPN is slower because of its userspace implementation (kernel bypass adds latency) and TLS overhead per packet. WireGuard is kernel-level and purpose-built for low latency, which is why it’s faster even without hardware acceleration.
What happens to Tailscale if the company shuts down?
Your existing connections would stop working because they depend on Tailscale’s coordination servers for peer discovery. This is a real risk if you’re building critical infrastructure. For casual access to a homelab, the risk is acceptable. WireGuard and OpenVPN have no shutdown risk because they’re open source and you control the infrastructure.
Explore Tailscale in our AI Homelab Toolkit.
