Hey everyone! I've been lurking for a while, learning a ton from this community, so thanks for that. I finally feel like I have something to contribute.
I've been using Tailscale for about six months now, after switching from ZeroTier. My main use case is for a small dev team (5 of us) to access our internal tools, databases, and a couple of on-prem servers. We were on ZeroTier for over a year, and it worked... okay. But we kept running into little stability hiccups and the ACL management started feeling clunky as we grew.
The switch to Tailscale was surprisingly smooth. The biggest immediate win was the integration with our existing Google Workspace accounts. Just having everyone log in with their company email was a huge friction reducer. No more "hey, I need to approve your device" emails. The admin panel feels much more intuitive to me, especially for seeing device connections and setting up simple access policies.
Performance-wise, I haven't noticed a dramatic speed differenceβboth were plenty fast for our needs. But Tailscale *feels* more reliable. We've had far fewer "why can't I see the staging server?" moments. I'm still wrapping my head around the concept of "subnet routers" versus how ZeroTier did it, but so far, it's been solid for our one physical server rack.
My main cautious question for the more experienced folks here is about cost scaling. We're comfortably on the free tier for now, but I'm thinking ahead. If we start adding more servers or need more complex ACLs, how steep does that curve get? Also, I'm still a bit confused about when you'd need Exit Nodes vs. Subnet Routers in more complex setupsβany good real-world examples? 😅
Overall, the migration was definitely worth it for the reduced admin overhead and perceived stability. Just trying to map out the long-term path now.
1. I manage a 12-person revops team at a SaaS company, and our whole sales and support stack connects back to internal tools through a VPN; we've run both ZeroTier and Tailscale in production over the last three years for access to our CRM sandboxes, analytics databases, and a legacy on-prem commission system.
2.
* **Price creep for headless devices**: Tailscale starts free but charges $5/user/month once you need SSO or device groups. ZeroTier's free tier is more permissive for networks, but their "Central" management console is $50/month flat for the first 100 nodes. The real hidden cost is in "users" vs "machines": if you have 5 engineers but 20 servers, Tailscale billing is friendlier; if you have 50 IoT devices and 2 admins, ZeroTier's model wins.
* **ACL management vs. "it just works"**: ZeroTier's JSON ACLs are powerful for complex rules (think segmenting dev/staging/prod networks) but become a configuration nightmare around rule precedence. Tailscale's tags and auto-approval based on SSO groups took us 2 hours to replicate what required a 150-line JSON file and weekly tweaks in ZeroTier. For a simple policy like "sales can only access the CRM tool," Tailscale is a 3-click setup.
* **Reliability on spotty connections**: In my last shop, we had field sales on terrible conference wifi. ZeroTier would occasionally take 30+ seconds to re-establish a relay, dropping SSH sessions. Tailscale's DERP servers seem to handle flaky connections better; we saw reconnection times under 5 seconds. This isn't about throughput - both held ~100 Mbps per node easily - but about session persistence.
* **The on-prem exit strategy**: ZeroTier feels built for a pure mesh. Tailscale subtly guides you toward their "Exit Nodes" or "Subnet Routers." If you need a specific device to act as a gateway to a physical subnet (like a legacy lab network), ZeroTier's bridge functionality is more transparent. With Tailscale, we had to run a Linux box as a subnet router, which added a single point of failure we didn't have with ZeroTier.
3. I'd pick Tailscale for any team under 50 people already using Google or Okta, because the user management friction disappears. Pick ZeroTier if you're wiring up industrial gear or have a highly segmented network topology you need to mirror in code. To decide, tell us how many service accounts/machines versus human users you have, and whether your access policies change weekly or yearly.