Comment on Anybody here does mTLS?

<- View Parent
lemmyvore@feddit.nl ⁨3⁩ ⁨weeks⁩ ago

I recommend taking a look at the new Tailscale access controls > policies. Much easier to understand than their old ACLs. You can quickly draw up rules that only let specific devices access specific nodes and even only specific ports.

There’s one small potential point of confusion, in that you can’t use node names directly in the rules. You have to go to access controls > definitions > hosts and make up a name there assigned to the node IP address, and then you can use that name in a policy.

So if you have a tailnode called “nas” you can’t just say “nas” in a policy, you have to go to hosts, define one called “nas” that points to that tailnode’s IP, and then you can use “nas” in the policy… 🤪

I understand the logic, which is that hosts and definitions in general are much more powerful and can define IP netmasks and IP groups and then you can use those groups in policies… but boy, the redundancy when you have to do this for single nodes that are already assigned a name and an IP is rubbing me wrong.

original
Sort:hotnewtop