‹ BackHN Continuity

Thread

Making Tailscale Faster

250 points · 112 comments · yarapavan

  1. iscoelho · · focus · HN ↗
    In my opinion, this is Tailscale's largest issue.

    It is slow. It cannot achieve speeds of greater than 1Gbps on clients systems (Windows & Mac), where you'd normally see it being used. On Linux, it struggles to achieve 10Gbps even when using a synthetic large packet benchmark [1]. With an IMIX benchmark, it would not be competitive whatsoever.

    This problem is fixable. WireGuard achieves higher performance (Kernel vs Userspace implementation) and IPsec implementations can achieve 100Gbps/400Gbps (DPDK/XDP). Zero-copy networking.

    From this blog post, I can say Tailscale still seems to not have the appetite for that, which is a shame.

    [1] <a href="https:&#x2F;&#x2F;tailscale.com&#x2F;blog&#x2F;more-throughput" rel="nofollow">https:&#x2F;&#x2F;tailscale.com&#x2F;blog&#x2F;more-throughput

    1. boomer_joe · · focus · HN ↗
      Yes. Just fucking stop doing userspace wireguard on linux <a href="https:&#x2F;&#x2F;github.com&#x2F;tailscale&#x2F;tailscale&#x2F;issues&#x2F;426" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;tailscale&#x2F;tailscale&#x2F;issues&#x2F;426 - issue has been open for 6 years (and is locked now, lol), btw.

      And if any tailscale employees are reading this - <a href="https:&#x2F;&#x2F;github.com&#x2F;tailscale&#x2F;tailscale&#x2F;issues&#x2F;15724" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;tailscale&#x2F;tailscale&#x2F;issues&#x2F;15724 please fix this too. Regular users not using some sort of enterprise saas DNS (whatever their thing is?) deserve DNS privacy too.

      1. TZubiri · · focus · HN ↗
        &gt; Just fucking stop doing userspace wireguard on linux - issue has been open for 6 years

        If they would have taken that advice, tailscale instances would have been pwned by copy.fail

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.