← All cheat sheets

ZEROTIER-TAILSCALE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

VPN mesh networking tools for creating secure overlay networks.
Useful for lab connectivity, red team infrastructure, and remote access.

ZEROTIER#


    

INSTALLATION#

# Linux
curl -s https://install.zerotier.com | sudo bash

# macOS
brew install zerotier-one

# Windows
# Download from https://www.zerotier.com/download/

# Docker
docker run -d --name zerotier --device=/dev/net/tun \
  --cap-add=NET_ADMIN zerotier/zerotier

BASIC COMMANDS#

# Service management
sudo systemctl start zerotier-one
sudo systemctl enable zerotier-one
sudo systemctl status zerotier-one

# Join a network
sudo zerotier-cli join NETWORK_ID

# Leave a network
sudo zerotier-cli leave NETWORK_ID

# List joined networks
sudo zerotier-cli listnetworks

# Show node info
sudo zerotier-cli info

# List peers
sudo zerotier-cli listpeers

# Get node address (10-char hex)
sudo zerotier-cli info | awk '{print $3}'

NETWORK MANAGEMENT#

# Via web UI: https://my.zerotier.com
# Or self-hosted controller

# Create network: my.zerotier.com > Create Network
# Authorize members: check "Auth" box for each node
# Assign IP ranges: Managed Routes section
# Set access rules: Flow Rules

# Self-hosted controller
# https://github.com/key-networks/ztncui (web UI)
# Or use the API directly

FLOW RULES (FIREWALL)#

# Allow all traffic (default)
accept;

# Drop all, allow specific
drop;
accept ipprotocol tcp dport 22;             # Allow SSH
accept ipprotocol tcp dport 80;             # Allow HTTP
accept ipprotocol tcp dport 443;            # Allow HTTPS

# Tag-based rules
tag admin id 1 default 0;
accept tand admin 1;                        # Only admin-tagged nodes
drop;

API#

# Base: https://api.zerotier.com/api/v1
# Auth: Bearer token from my.zerotier.com > Account

# List networks
curl -H "Authorization: Bearer TOKEN" \
  https://api.zerotier.com/api/v1/network

# Get network details
curl -H "Authorization: Bearer TOKEN" \
  https://api.zerotier.com/api/v1/network/NETWORK_ID

# List members
curl -H "Authorization: Bearer TOKEN" \
  https://api.zerotier.com/api/v1/network/NETWORK_ID/member

# Authorize member
curl -X POST -H "Authorization: Bearer TOKEN" \
  -d '{"config":{"authorized":true}}' \
  https://api.zerotier.com/api/v1/network/NETWORK_ID/member/NODE_ID

========================================================================

TAILSCALE#


    

INSTALLATION#

# Linux
curl -fsSL https://tailscale.com/install.sh | sh

# macOS
brew install tailscale

# Docker
docker run -d --name tailscale --cap-add=NET_ADMIN \
  -v /dev/net/tun:/dev/net/tun \
  tailscale/tailscale

BASIC COMMANDS#

# Start and authenticate
sudo tailscale up

# Start with specific options
sudo tailscale up --advertise-exit-node     # Act as exit node
sudo tailscale up --accept-routes           # Accept subnet routes
sudo tailscale up --ssh                     # Enable Tailscale SSH
sudo tailscale up --authkey=tskey-xxx       # Pre-authenticated

# Check status
tailscale status

# Show IP addresses
tailscale ip
tailscale ip -4                             # IPv4 only
tailscale ip -6                             # IPv6 only

# Ping another node
tailscale ping HOSTNAME_OR_IP

# List network nodes
tailscale status

# Disconnect
sudo tailscale down

# Logout
sudo tailscale logout

SUBNET ROUTING#

# Advertise local subnet (make local network accessible)
sudo tailscale up --advertise-routes=10.10.10.0/24,192.168.1.0/24

# Accept routes from other nodes
sudo tailscale up --accept-routes

# Enable IP forwarding (required for routing)
echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.conf
sudo sysctl -p

EXIT NODES#

# Advertise as exit node (route all traffic through)
sudo tailscale up --advertise-exit-node

# Use an exit node
sudo tailscale up --exit-node=EXIT_NODE_IP
sudo tailscale up --exit-node=hostname

# Clear exit node
sudo tailscale up --exit-node=

TAILSCALE SSH#

# Enable Tailscale SSH (replaces OpenSSH for Tailscale connections)
sudo tailscale up --ssh

# Connect
ssh user@hostname                           # Uses Tailscale auth
tailscale ssh user@hostname                 # Explicit Tailscale SSH

# No SSH keys needed — uses Tailscale identity

FILE SHARING#

# Send file
tailscale file cp myfile.txt hostname:

# Receive files (check default receive directory)
tailscale file get .

TAILSCALE FUNNEL & SERVE#

# Serve local service to internet (no port forwarding needed)
tailscale serve https / http://localhost:3000

# Funnel (public internet access)
tailscale funnel 443

# List active serves
tailscale serve status

ACL (ACCESS CONTROL)#

# Managed via admin console: https://login.tailscale.com/admin/acls
# JSON-based ACL policy

{
  "acls": [
    {"action": "accept", "src": ["group:admin"], "dst": ["*:*"]},
    {"action": "accept", "src": ["tag:server"], "dst": ["tag:server:22"]},
  ],
  "groups": {
    "group:admin": ["user@example.com"]
  },
  "tagOwners": {
    "tag:server": ["group:admin"]
  }
}

API#

# Base: https://api.tailscale.com/api/v2
# Auth: API key from admin console

# List devices
curl -u "API_KEY:" \
  https://api.tailscale.com/api/v2/tailnet/TAILNET/devices

# Get device info
curl -u "API_KEY:" \
  https://api.tailscale.com/api/v2/device/DEVICE_ID

========================================================================

RED TEAM / LAB USE CASES#

# 1. C2 infrastructure mesh
#    Connect all redirectors, team servers, and operators
#    via ZeroTier/Tailscale overlay network

# 2. Lab connectivity
#    Access home lab from anywhere without port forwarding
#    Subnet routing exposes entire lab network

# 3. Pivot network
#    Install on compromised host → instant VPN back to attack infra
#    (OPSEC: consider detection risk)

# 4. Multi-cloud lab
#    Connect VMs across AWS, Azure, GCP, and local machines

# 5. Team collaboration
#    All operators on same overlay network
#    Direct access to shared tools and infrastructure

COMPARISON#

Feature          ZeroTier          Tailscale
-------          --------          ---------
Protocol         Custom P2P        WireGuard
Self-hosted      Yes (controller)  Headscale (OSS)
Free tier        25 devices        100 devices
NAT traversal    Yes               Yes (DERP relays)
Subnet routing   Yes               Yes
Exit nodes       Yes               Yes
SSH              No                Tailscale SSH
File sharing     No                tailscale file
ACLs             Flow rules        JSON ACLs
Speed            Good              Excellent (WG)
Mobile           Yes               Yes

TIPS#

  - Tailscale uses WireGuard → generally faster
  - ZeroTier is more self-hostable (own controller)
  - Both punch through most NATs automatically
  - Subnet routing = instant access to entire networks
  - Pre-auth keys enable automated deployment
  - Tag-based ACLs for segmenting lab environments
  - Both have ephemeral node support for temporary access
  - Headscale is the open-source Tailscale control server
  - For red team infra: ZeroTier is harder to fingerprint
  - For labs: Tailscale is easier to set up