Routing to Tailscale clients from a local network with OPNSense

Overview Effectively, what we’re trying to accomplish here today is the opposite of a Tailscale Subnet Router. As in, allowing clients on our local network to talk to devices via their Tailscale subnet IP addresses. When I started looking into how to do this, I could not find a complete guide on the topic. I’ll do my best to do this start to finish so that anyone else can follow along with me. ...

August 15, 2026 · 4 min

Fluxer Over Tailscale

This weekend I’ve been playing with setting up a self-hosted Fluxer instance. In my traditional fashion, I made things much harder by myself by refusing to use their provided Caddy setup, and instead using Traefik. And for an additional challenge - I wanted this to be completely inaccessible from the public Internet, instead using my Tailscale mesh network. The setup required some heavy modifications to the Docker Compose file provided by Fluxer’s team, and a few tweaks to livekit.yaml. ...

June 20, 2026 · 2 min

Wireguard configuration concepts

Wireguard concepts The point of this post This is intended as a high level starting point for someone who is new to using Wireguard. If you spot any errors or inaccuracies, feel free to open a pull request in the Github repo, or leave a comment. Overview Wireguard is a modern VPN protocol. Instead of using a traditional client server model, Wireguard uses a peer-to-peer mechanism. Authentication is handled with private and public key pairs, and optionally a pre-shared key. ...

October 26, 2025 · 4 min

PSA: Unifi IPSec site-to-site tunnels and DHCP

Bit of a PSA of sorts, as this is the second time that I have run into this particular issue. Scenario: You had a Unifi gateway such as a UDM Pro with a static IP address. You switched your WAN IP from static to dynamic, for whatever reason. (In my case it was a different ISP that doesn’t hand out actual static IPs, only DHCP reservations.) You may find that the router holds onto that old IP, and if you’re like me, you’ll be confused as hell. ...

April 1, 2025 · 1 min

Adventures in DNS (But it's actually DHCP this time.)

So, story time. Boss has a friend who does IT for an electrical contractor 30 mins or so away from our primary office, and he brings us in because he’s having DNS issues he can’t figure out Get onsite there and go over his setup – typical mess of a network closet with no brand consistency and mismatched patch cables, whatever. Otherwise looks good from a network perspective. However, he mentions that he has no access to the firewall since it’s owned by the ISP. ...

December 2, 2024 · 4 min