Tailscale vs WireGuard vs Cloudflare Tunnel for Homelabs
Tailscale, WireGuard, or Cloudflare Tunnel? Compare the three ways to reach your homelab remotely without port forwarding, and pick the right one.
You’ve got a Raspberry Pi running Pi-hole, a password manager, maybe a media server. Now you want to reach all of it from a coffee shop, a hotel, or your phone on cellular, without punching holes in your router.
Three tools come up in almost every answer: Tailscale, WireGuard, and Cloudflare Tunnel. They sound interchangeable, but they solve two different problems. This guide explains the difference, compares them side by side, and shows how to get the most common setup running in a few commands.
The Short Answer
- Only you (and a few people you trust) need access: use Tailscale. It is the lowest-effort path to a private network.
- You want full control and no third-party coordination server: use plain WireGuard.
- You want to publish a service at a public URL (for family, a webhook, a demo): use Cloudflare Tunnel.
Many homelabs end up running two of the three: a private VPN for admin access and a tunnel for the one or two services that need a public address.
Private Network vs Public Exposure
This is the distinction most comparisons skip, and it decides everything else.
Tailscale and WireGuard build a private network. Only devices you enroll can reach your services. Nothing is visible to the public internet, so there is nothing to scan or brute-force.
Cloudflare Tunnel publishes a service. It gives a service a public HTTPS hostname through Cloudflare’s edge, with no inbound port open on your router. You are still exposing the app to the internet, so the app’s own authentication has to be solid.
If you are only trying to SSH into your Pi or open an admin dashboard, you almost certainly want a private network rather than a public hostname.
Tailscale: The Easy Mesh VPN
Tailscale is a managed mesh VPN built on WireGuard. You install it on each device, sign in, and the devices can reach each other by stable private addresses. NAT traversal, key exchange, and DNS are handled for you.
Good fit when:
- Your ISP uses CGNAT, so you can’t forward ports even if you wanted to
- You have phones and laptops that roam between networks
- You want to reach a whole LAN through one device (a subnet router) without installing anything on every machine
Trade-offs:
- A third-party coordination service manages authentication and key distribution (your traffic itself is encrypted between devices)
- Free-tier limits and terms can change, so check the current plan before you rely on it
- You can self-host the control server with the open-source Headscale project, at the cost of doing more work yourself
Quick Start on a Raspberry Pi
Install Tailscale and bring the node up:
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up
To reach other devices on your home network through the Pi, enable IP forwarding and advertise your subnet:
echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.d/99-tailscale.conf
sudo sysctl -p /etc/sysctl.d/99-tailscale.conf
sudo tailscale up --advertise-routes=192.168.1.0/24
Then approve the route in the Tailscale admin console. The full walkthrough, including ACLs and troubleshooting, is in my Tailscale subnet routing note.
For a deeper reference, see the official Tailscale subnet router documentation and the exit node guide.
WireGuard: Maximum Control
WireGuard is the protocol underneath Tailscale. Running it yourself means a small, fast, auditable VPN with no outside service involved.
Good fit when:
- You want everything self-hosted and self-managed
- You have a public IP or a dynamic DNS name and can forward one UDP port
- You only have a handful of devices
Trade-offs:
- You generate and distribute keys by hand
- You configure each peer, its
AllowedIPs, DNS, and firewall rules yourself - It needs one reachable endpoint, which is a problem behind CGNAT unless you rent a small VPS to act as the hub
A minimal server config looks like this:
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = <server-private-key>
[Peer]
# Laptop
PublicKey = <laptop-public-key>
AllowedIPs = 10.8.0.2/32
Open the port and bring it up:
sudo ufw allow 51820/udp
sudo wg-quick up wg0
If you go this route, lock the host down first. My UFW rules guide covers a sensible baseline.
Cloudflare Tunnel: Publish Without Opening Ports
Cloudflare Tunnel runs a small daemon, cloudflared, on your server. It makes an outbound connection to Cloudflare, which then routes public requests for your hostname back through it. Your router never needs an open inbound port.
Good fit when:
- You want a real HTTPS URL for a service, such as a status page or a shared app
- You already manage your domain’s DNS in Cloudflare
- You want Cloudflare’s edge in front of the service
Trade-offs:
- The service is reachable from the public internet, so it needs strong authentication (Cloudflare Access can add a login in front)
- Traffic passes through Cloudflare’s network
- Cloudflare’s terms limit some uses, such as proxying large media streams, so read the current terms before putting a media server behind it
The setup flow is: install cloudflared, authenticate it, create a named tunnel, and map a hostname to a local service. The Cloudflare Tunnel documentation walks through each step.
Side-by-Side Comparison
| Tailscale | WireGuard | Cloudflare Tunnel | |
|---|---|---|---|
| Model | Private mesh VPN | Private VPN (DIY) | Public hostname via Cloudflare |
| Setup effort | Low | Medium to high | Medium |
| Works behind CGNAT | Yes | Only with a public relay | Yes |
| Needs open router port | No | Yes (one UDP port) | No |
| Third-party dependency | Coordination server | None | Cloudflare edge |
| Exposed to the internet | No | No (one UDP port) | Yes, by design |
| Best for | Admin access, roaming devices | Full control, small setups | Sharing a service publicly |
Which One Should You Pick?
Work through these questions in order:
- Does anyone outside your own devices need access? If yes, and they shouldn’t install anything, Cloudflare Tunnel (with Access in front) is the practical choice.
- Are you behind CGNAT or without a static IP? If yes, skip plain WireGuard unless you are willing to run a relay. Choose Tailscale.
- Do you want zero third-party involvement? Choose WireGuard, or Tailscale with Headscale if you want the convenience layer.
- Everything else: start with Tailscale. You can add the others later.
Whichever you choose, pair it with a solid backup plan for the services you are reaching. If you host your own password vault, see my write-up on self-hosting Vaultwarden with a disaster-recovery fallback.
FAQ
Is Tailscale just WireGuard?
Tailscale uses WireGuard for the encrypted tunnels, then adds the parts that are tedious to do by hand: key distribution, NAT traversal, device identity, and DNS. You get WireGuard’s performance without managing configs for every peer.
Do I need to forward ports for Tailscale?
No. Tailscale devices connect outbound and negotiate a direct path when possible, falling back to a relay when a direct connection can’t be made. That is why it works behind CGNAT and strict routers.
Is Cloudflare Tunnel safer than opening a port?
It removes the open inbound port, which cuts down on scanning and direct attacks against your router. But the service is still public, so a weak login page is still a weak login page. Add authentication such as Cloudflare Access, and keep the app updated.
Can I use Tailscale and Cloudflare Tunnel together?
Yes, and it is a common pattern. Use Tailscale for private admin access (SSH, dashboards, Pi-hole) and Cloudflare Tunnel for the small number of services that need a public URL.
Which is fastest?
Raw throughput is close, since Tailscale runs WireGuard underneath. When Tailscale establishes a direct peer-to-peer connection, performance is comparable to hand-configured WireGuard. Relayed connections are slower, so a CPU-limited Pi or a distant relay will matter more than the tool you choose.
Conclusion
For most homelabs, Tailscale is the right starting point: private by default, no port forwarding, and working in minutes. Reach for WireGuard when you want to own every piece, and add Cloudflare Tunnel only for services that truly need a public address.
If you’re setting up your first remote-access path, follow the Tailscale subnet routing note and then read through my homelab page to see how the pieces fit together.
Comments