Hey everyone! I'm currently helping a friend's retail business figure out their remote access setup, and I'm deep in comparison mode. They have 15 physical store locations, each with a few point-of-sale systems, local network printers, and a file server for daily reports. Their **main need** is for their small, central IT team (just 2 people!) to securely access these on-site devices for support and maintenance without opening up firewall ports at every store.
We've looked at the usual suspects like traditional VPNs, but the complexity and per-location config seem like a headache. I'm really interested in tools that use some kind of mesh networking or zero-trust model.
Naturally, Tailscale is on my shortlist. It seems perfect for the "no-config firewall" aspect. But I'm curious about real-world use at this scale:
* **Onboarding & Stability:** How smooth is it to deploy Tailscale on 15+ different, non-technical store networks? Think consumer-grade routers.
* **Access Control:** We'd need to segment access—e.g., the inventory manager doesn't need the POS systems. How granular can you get with ACLs without it becoming a Jira-level configuration puzzle?
* **Cost vs. Alternatives:** At 15+ locations (nodes), we're looking at the Paid plan. How does this compare value-wise to something like Twingate or Zerotier for a purely remote-access use case?
* **The "Oh No" Moment:** Has anyone had a store location completely lose Tailscale connectivity because of a weird ISP or router quirk? What's the fallback?
My gut says Tailscale's simplicity is a huge win for a small team, but I'd love to hear from anyone managing similar distributed retail or hospitality setups. What's your actual workflow for adding a new location or device?
Cheers