ZEROTIER-TAILSCALE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
VPN mesh networking tools for creating secure overlay networks. Useful for lab connectivity, red team infrastructure, and remote access.
ZEROTIER#
INSTALLATION#
# Linux curl -s https://install.zerotier.com | sudo bash # macOS brew install zerotier-one # Windows # Download from https://www.zerotier.com/download/ # Docker docker run -d --name zerotier --device=/dev/net/tun \ --cap-add=NET_ADMIN zerotier/zerotier
BASIC COMMANDS#
# Service management
sudo systemctl start zerotier-one
sudo systemctl enable zerotier-one
sudo systemctl status zerotier-one
# Join a network
sudo zerotier-cli join NETWORK_ID
# Leave a network
sudo zerotier-cli leave NETWORK_ID
# List joined networks
sudo zerotier-cli listnetworks
# Show node info
sudo zerotier-cli info
# List peers
sudo zerotier-cli listpeers
# Get node address (10-char hex)
sudo zerotier-cli info | awk '{print $3}'
NETWORK MANAGEMENT#
# Via web UI: https://my.zerotier.com # Or self-hosted controller # Create network: my.zerotier.com > Create Network # Authorize members: check "Auth" box for each node # Assign IP ranges: Managed Routes section # Set access rules: Flow Rules # Self-hosted controller # https://github.com/key-networks/ztncui (web UI) # Or use the API directly
FLOW RULES (FIREWALL)#
# Allow all traffic (default) accept; # Drop all, allow specific drop; accept ipprotocol tcp dport 22; # Allow SSH accept ipprotocol tcp dport 80; # Allow HTTP accept ipprotocol tcp dport 443; # Allow HTTPS # Tag-based rules tag admin id 1 default 0; accept tand admin 1; # Only admin-tagged nodes drop;
API#
# Base: https://api.zerotier.com/api/v1
# Auth: Bearer token from my.zerotier.com > Account
# List networks
curl -H "Authorization: Bearer TOKEN" \
https://api.zerotier.com/api/v1/network
# Get network details
curl -H "Authorization: Bearer TOKEN" \
https://api.zerotier.com/api/v1/network/NETWORK_ID
# List members
curl -H "Authorization: Bearer TOKEN" \
https://api.zerotier.com/api/v1/network/NETWORK_ID/member
# Authorize member
curl -X POST -H "Authorization: Bearer TOKEN" \
-d '{"config":{"authorized":true}}' \
https://api.zerotier.com/api/v1/network/NETWORK_ID/member/NODE_ID
========================================================================
TAILSCALE#
INSTALLATION#
# Linux curl -fsSL https://tailscale.com/install.sh | sh # macOS brew install tailscale # Docker docker run -d --name tailscale --cap-add=NET_ADMIN \ -v /dev/net/tun:/dev/net/tun \ tailscale/tailscale
BASIC COMMANDS#
# Start and authenticate sudo tailscale up # Start with specific options sudo tailscale up --advertise-exit-node # Act as exit node sudo tailscale up --accept-routes # Accept subnet routes sudo tailscale up --ssh # Enable Tailscale SSH sudo tailscale up --authkey=tskey-xxx # Pre-authenticated # Check status tailscale status # Show IP addresses tailscale ip tailscale ip -4 # IPv4 only tailscale ip -6 # IPv6 only # Ping another node tailscale ping HOSTNAME_OR_IP # List network nodes tailscale status # Disconnect sudo tailscale down # Logout sudo tailscale logout
SUBNET ROUTING#
# Advertise local subnet (make local network accessible) sudo tailscale up --advertise-routes=10.10.10.0/24,192.168.1.0/24 # Accept routes from other nodes sudo tailscale up --accept-routes # Enable IP forwarding (required for routing) echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.conf sudo sysctl -p
EXIT NODES#
# Advertise as exit node (route all traffic through) sudo tailscale up --advertise-exit-node # Use an exit node sudo tailscale up --exit-node=EXIT_NODE_IP sudo tailscale up --exit-node=hostname # Clear exit node sudo tailscale up --exit-node=
TAILSCALE SSH#
# Enable Tailscale SSH (replaces OpenSSH for Tailscale connections) sudo tailscale up --ssh # Connect ssh user@hostname # Uses Tailscale auth tailscale ssh user@hostname # Explicit Tailscale SSH # No SSH keys needed — uses Tailscale identity
FILE SHARING#
# Send file tailscale file cp myfile.txt hostname: # Receive files (check default receive directory) tailscale file get .
TAILSCALE FUNNEL & SERVE#
# Serve local service to internet (no port forwarding needed) tailscale serve https / http://localhost:3000 # Funnel (public internet access) tailscale funnel 443 # List active serves tailscale serve status
ACL (ACCESS CONTROL)#
# Managed via admin console: https://login.tailscale.com/admin/acls
# JSON-based ACL policy
{
"acls": [
{"action": "accept", "src": ["group:admin"], "dst": ["*:*"]},
{"action": "accept", "src": ["tag:server"], "dst": ["tag:server:22"]},
],
"groups": {
"group:admin": ["user@example.com"]
},
"tagOwners": {
"tag:server": ["group:admin"]
}
}
API#
# Base: https://api.tailscale.com/api/v2 # Auth: API key from admin console # List devices curl -u "API_KEY:" \ https://api.tailscale.com/api/v2/tailnet/TAILNET/devices # Get device info curl -u "API_KEY:" \ https://api.tailscale.com/api/v2/device/DEVICE_ID ========================================================================
RED TEAM / LAB USE CASES#
# 1. C2 infrastructure mesh # Connect all redirectors, team servers, and operators # via ZeroTier/Tailscale overlay network # 2. Lab connectivity # Access home lab from anywhere without port forwarding # Subnet routing exposes entire lab network # 3. Pivot network # Install on compromised host → instant VPN back to attack infra # (OPSEC: consider detection risk) # 4. Multi-cloud lab # Connect VMs across AWS, Azure, GCP, and local machines # 5. Team collaboration # All operators on same overlay network # Direct access to shared tools and infrastructure
COMPARISON#
Feature ZeroTier Tailscale ------- -------- --------- Protocol Custom P2P WireGuard Self-hosted Yes (controller) Headscale (OSS) Free tier 25 devices 100 devices NAT traversal Yes Yes (DERP relays) Subnet routing Yes Yes Exit nodes Yes Yes SSH No Tailscale SSH File sharing No tailscale file ACLs Flow rules JSON ACLs Speed Good Excellent (WG) Mobile Yes Yes
TIPS#
- Tailscale uses WireGuard → generally faster - ZeroTier is more self-hostable (own controller) - Both punch through most NATs automatically - Subnet routing = instant access to entire networks - Pre-auth keys enable automated deployment - Tag-based ACLs for segmenting lab environments - Both have ephemeral node support for temporary access - Headscale is the open-source Tailscale control server - For red team infra: ZeroTier is harder to fingerprint - For labs: Tailscale is easier to set up