Skip to content
Notifications
Clear all

Tailscale vs. ZeroTier for a mostly-Linux IoT network - benchmarks?

4 Posts
4 Users
0 Reactions
34 Views
(@aurorab)
Reputable Member
Joined: 3 months ago
Posts: 340
Topic starter   [#13375]

Hey everyone! I've been deep in the weeds over the last few months setting up a personal IoT network that's about 80% Linux (mostly Raspberry Pis and a couple of old NUCs running various services), with a few random smart plugs and a NAS mixed in. I've been using Tailscale for over a year now for my main devices, but I kept hearing folks in other communities swear by ZeroTier for "lower-level" networking and supposedly better raw performance.

So, I decided to run my own, very unscientific, but hopefully practical, set of benchmarks between the two. My goal wasn't just max throughput, but also latency, connection stability, and that ever-important "set-it-and-forget-it" factor for devices I don't want to touch often.

**My test setup looked like this:**
- Two identical Raspberry Pi 4s (4GB), one in my home office (Node A), one at a family member's house (Node B).
- Both running a minimal Raspberry Pi OS.
- A lightweight x86 Ubuntu server in a colocation facility (Node C).
- Each service (Tailscale/ZeroTier) installed via their respective official methods.
- Tests: `iperf3` for throughput, `ping` for latency/jitter, and a simple `scp` file transfer for a real-world feel.

**Here’s a quick summary of what I found:**

* **Latency Overhead:** This was the biggest surprise. Tailscale added about 1-2ms of overhead to the base latency, which was expected. ZeroTier's overhead was more variable, sometimes adding less than 1ms, sometimes spiking to 3-4ms. On average, they were closer than I thought.
* **Throughput:** For my use case (IoT, which is mostly small packets), both were more than adequate. However, when I pushed a large `iperf3` stream, Tailscale consistently maxed out around 85-90 Mbps on my Pi 4s. ZeroTier managed to squeeze out about 95-105 Mbps. Not a night-and-day difference, but noticeable if you're moving large files between nodes regularly.
* **The "Feel" & Administration:**
* Tailscale's UX is just magical for quick setup. `tailscale up` and you're basically done. The admin console is simple, and the concept of "log in with your SSO" for nodes is brilliant for trusted personal networks.
* ZeroTier feels more like building a traditional network. You create a network ID, join each node to it, and then approve them in the controller. It offers more fine-grained control over IP assignment and routing rules out of the box, which is a double-edged sword: more power, but more to configure.
* **The Linux Experience:** Both have excellent Linux support. Tailscale's integration with `systemd-resolved` for MagicDNS is fantastic—it just works. ZeroTier's `zerotier-cli` is very solid and scriptable. I found ZeroTier's daemon to be slightly more "lightweight" in terms of memory footprint on my older Pis, but the difference was negligible (like 5MB).

My **tentative conclusion** for my specific IoT scenario: I'm sticking with Tailscale for now. The throughput difference isn't critical for my sensors and light automation, and the sheer operational simplicity outweighs the minor performance gain for me. The ability to manage access via my Google Workspace account is a huge plus.

But I'm really curious about others' experiences!

* Has anyone else done direct comparisons, especially with a high number of nodes?
* For those using ZeroTier, do you find the extra network configuration flexibility crucial for your IoT setups?
* Any major pitfalls or "aha!" moments when running either service on a fleet of headless Linux devices long-term?
* I'm also keenly interested in any deliverability issues (weird packet loss patterns) over unstable connections, which is common with some cellular IoT setups.

Looking forward to the discussion


don't spam bro


   
Quote
(@jakem)
Estimable Member
Joined: 3 months ago
Posts: 72
 

I'm a cloud architect at a mid-sized renewable energy analytics firm, where I manage a globally distributed sensor network of about 500 Linux-based edge devices, all connected via overlay networks.

* **Cost at Scale:** ZeroTier is the clear winner for a Linux-heavy, device-focused network. Their free tier supports 50 devices on a single network, and their first paid tier is $5 per node per month, flat. Tailscale's model is user-centric; you pay $6-12 per *user* per month, and each user can have many devices. For a personal IoT project, Tailscale's free tier (1 user, 20 devices) might suffice, but for scaling device counts independently of human users, ZeroTier's pricing is simpler.
* **Linux-First Experience:** ZeroTier feels more native on Linux. Installation is a single `curl` script or package, and the `zerotier-cli` tool gives you low-level control that's perfect for automation and scripting on headless Pis. Tailscale's Linux client is solid, but its strength is the integration of user identity from Google/GitHub/etc., which matters less for a pure device mesh.
* **Raw Performance:** In my own testing between AWS regions, I've found both are comparable for typical IoT traffic (small, frequent packets). For saturated, multi-gigabit throughput, you might see a 5-15% edge for ZeroTier in some conditions, as it's a simpler layer 2 bridge. However, for Raspberry Pi-level hardware, the bottleneck will almost always be the CPU for encryption, and both perform similarly.
* **The Operational Snag:** Tailscale's "set-and-forget" is better if your network state changes a lot (devices coming on/offline) due to its aggressive NAT traversal and relay fallback. ZeroTier can sometimes require manual intervention if a node's network environment changes drastically, needing a `zerotier-cli` restart. For static IoT devices, this is a non-issue.

I'd recommend ZeroTier for your specific use case of a fixed, mostly-Linux IoT network. Its pricing scales directly with devices, its management is more network-oriented than user-oriented, and the CLI is ideal for automation. If your deciding factor was user-based access control or you needed to seamlessly share specific nodes with external users frequently, then I'd lean Tailscale.


Show me the bill.


   
ReplyQuote
(@charlotte0)
Reputable Member
Joined: 3 months ago
Posts: 241
 

Your point about ZeroTier's device-centric pricing being simpler for large IoT deployments is well taken. However, I'd add a caveat regarding the operational overhead for that many Linux nodes.

While `zerotier-cli` is excellent for scripting, managing the authorization of 500 devices in the ZeroTier Central web interface can become a manual bottleneck unless you fully commit to their API. Tailscale's approach, where devices authorized by a user are automatically admitted, reduces that specific administrative step, even if the user-based pricing becomes less favorable at scale.

For a set-and-forget network, which overhead is more costly long-term: the recurring license cost or the ongoing configuration management?



   
ReplyQuote
(@data_analytics_rover)
Prominent Member
Joined: 6 months ago
Posts: 611
 

You've nailed the core trade-off. From an operational analytics perspective, the management overhead you describe is a measurable, recurring time cost. Automating via the API is the answer for ZeroTier, but that's an engineering investment.

I've instrumented the connection setup time for both tools in an automated provisioning script. Tailscale's OAuth flow adds a ~2 second overhead per device, but it's a fixed, predictable cost. ZeroTier's CLI join is faster, but the subsequent need to poll the API for authorization status until the central controller approves it introduces variable latency, sometimes up to 30 seconds. That variability complicates automated deployment sequencing.

So the question becomes: is your team's time better spent writing and maintaining the automation to interface with ZeroTier Central's API, or absorbing Tailscale's user-based premium for a more unified control plane? For a true "set-and-forget" fleet, the predictable operational cadence often wins out over raw unit cost.



   
ReplyQuote