Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How does it compare with cloudflare's tunnels? [0]

I have been using Cloudflare's cloudflared tunnels. It was great for tunneling ssh traffic behind firewalls. And it starts free.

[0] https://developers.cloudflare.com/cloudflare-one/connections...



Clouflare Tunnels are generally used for http(s) traffic more so than SSH, this is just Tailscale's SSH offering.

The equivalent http(s) side of things from Tailscale would be Tailscale Funnel [0], although it's incomplete since you can't BYO domain to TS Funnel.

In essence, CF Tunnel = Tailscale Funnel w/ BYOD + Tailscale SSH

[0] https://tailscale.com/kb/1223/funnel


Cloudflare Tunnel can absolutely be used for more than HTTP(S): https://blog.cloudflare.com/ssh-raspberry-pi-400-cloudflare-...


Where exactly did I say it can't be used for more than http(s)? I just said it's generally used for that, and

> In essence, CF Tunnel = Tailscale Funnel w/ BYOD + _Tailscale SSH_

> CF Tunnel = ... Tailscale SSH


It's very different, CF tunnel is a reverse proxy to your service, Tailscale SSH manages authentication to machines inside your VPN. I can't see any resemblance, personally.


First of all, for CF, it manages the authentication part of ssh with SSO support (personally I used github)

Secondly, it has clients (on iOS it is called Cloudflare One) which can act as a VPN service as well. You can access any IP addresses (if you setup the vpc correctly [0]) directly accessible to cloudflared daemons.

[0] https://developers.cloudflare.com/cloudflare-one/connections...


My understanding is that only Tailscale is end-to-end-encrypted, though both ensure that all traffic is encrypted on the wire. I don’t claim this as fact because, unlike the Cloudflare docs, Tailscale’s claim (yell) that there is no way for them to decrypt.

I’d be pleased to be proven wrong (and jgrahamc is def ITT) as I use a bunch of CF services already and it would be great to have one less PaaS in my life.


You are right. Tunnel and TLS both end on Cloudflare. It’s not end to end. In fact CF scans the traffic supposedly for malware.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: