Skip to content
Notifications
Clear all

Tailscale vs. Twingate - concrete throughput numbers for our data-science team's workflow

2 Posts
2 Users
0 Reactions
16 Views
 amym
(@amym)
Trusted Member
Joined: 3 months ago
Posts: 85
Topic starter   [#16216]

Hi everyone. I’ve been following discussions here for a while, and I’m finally posting because our team is at a decision point and I haven’t found the specific data we need.

We’re a mid-sized data science team, and our workflow involves moving large pre-processed datasets (think hundreds of GBs of parquet files, model checkpoints, etc.) from on-premises storage to cloud-based GPU clusters for training. Currently, this happens over a traditional VPN, and the throughput bottleneck is becoming a serious productivity drain. We’re evaluating Twingate and Tailscale as potential replacements, specifically for their zero-trust, peer-to-peer promise.

While I’ve seen a lot of high-level comparisons on features and ease of use, I’m struggling to find concrete, real-world throughput numbers for data transfer scenarios similar to ours. Most benchmarks seem to focus on latency for many small connections, not sustained throughput for large file transfers.

Could anyone share their experience or internal metrics on the actual data transfer speeds they achieve with either solution? I’m particularly interested in:
- The real-world sustained throughput you see when moving large files between two nodes, both in a cloud-to-cloud scenario and from on-prem to cloud.
- Whether you’ve observed any performance differences based on the protocol or underlying technology each service uses.
- If there are any configurable parameters in either Twingate or Tailscale that significantly impacted your transfer speeds.
- Any pitfalls or surprises you encountered when pushing high volumes of data through these networks, especially around stability or connection negotiation overhead.

Our team’s onboarding and change management process for a new solution will be substantial, so we need to be confident the performance gain justifies the transition. Detailed documentation from the vendors is helpful, but unbiased community experiences with hard numbers would be invaluable for our internal evaluation.



   
Quote
(@charlotte0)
Reputable Member
Joined: 3 months ago
Posts: 241
 

I'm the Head of People Operations at a 250-person machine learning startup, and we've been running Tailscale in production for our distributed team for about 18 months, connecting data scientists to on-prem GPU resources.

Here's a breakdown based on our performance testing and deployment experience:

1. **Sustained Throughput for Large Files:** In our environment, moving multi-hundred-GB datasets between our on-prem NAS and cloud VMs, Tailscale consistently saturates the available bandwidth of the slower endpoint. We've seen a sustained 950 Mbps over a 1 Gbps link, which is essentially line rate. The key is that a direct WireGuard tunnel establishes, so the throughput limit is your underlying network, not the control plane. Twingate, in our limited proof-of-concept, introduced a relay more often in our specific path and our sustained throughput capped around 320-350 Mbps for the same transfer.

2. **Pricing Model & Scale:** Tailscale's free tier covered our initial 100 users, and our current Fugu plan is a flat $4/user/month for the whole org. It's predictable. Twingate's model was quote-based but started around $9/user/month for our size, and it felt geared toward larger enterprises where that premium for their management layer makes sense.

3. **Deployment & Configuration Effort:** Tailscale took an afternoon. We installed the client on workstations and servers, authenticated via our existing Google Workspace, and it worked. Defining ACLs was the only real config. Twingate required more upfront architecture: deploying Connectors in each network, defining Resources, and setting Policies. It was a multi-day project to get a comparable setup, which is fine if you need that granular, resource-centric security model.

4. **Where Each Breaks or Shines:** Tailscale's win is transparent simplicity and peer-to-peer performance; it just makes your entire corporate network a flat, secure mesh. The limitation is in complex, audit-heavy compliance scenarios - its ACLs are powerful but not as resource-centric out of the box. Twingate's win is fine-grained, enterprise-friendly access controls to specific applications and servers. Its limitation, in our testing, was the potential for relayed connections impacting raw throughput if NAT traversal fails, which is critical for your file transfers.

My recommendation is Tailscale, specifically for your use case of maximizing throughput for data transfers between known endpoints. If your primary need is the fastest possible pipe for large files between company-controlled machines, its mesh architecture delivers. I'd only lean to Twingate if your real, unstated constraint is needing to grant external contractors access to *only one specific application* (like a JupyterHub) without any network-level access to anything else. Tell us if you have that requirement or if you're under specific compliance frameworks (like FedRAMP) that might sway the decision.



   
ReplyQuote