←back to thread

655 points louis-paul | 1 comments | | HN request time: 0s | source
Show context
briHass ◴[] No.43627559[source]
I'm a fan of TS and have been a paying customer for work infra for almost a year now. It really is well put together and easy to use, but I do run up against some issues/complaints when diving deep that I hope they can work out:

* The pricing tiers and included features by tier penalizes you in frustrating ways. The base plan is a reasonable $6/user/m, but if you want to use ACLs to control anything in a workable way, it jumps 3x to $18/u/m. Better solutions are available for that kind of money, and I shudder to imagine what the next tier ('call us') costs.

* Subnet routing broke on Ubuntu (maybe other distros) recently, and there were no alerts, communication from TS, or TS tools to pinpoint/figure out what was going on. I stumbled on a solution (install subnet router on a Windows box), and from there I searched and found others with that issue. Lost half a day in emergency mode over that!

* Better tooling to determine why it's falling back to DERP instead of direct for remote clients. DERP relays should be an absolute last resort to provide connectivity for Business-plan-level customers (very slow), and the way TS works just assumes any connectivity is fine.

Overall, the simplicity and abstraction of complex VPN networking is wonderful, but if you have issues or advanced needs, you are immediately thrust into the low-level UDP/NAT/STUN world you were trying to avoid. At that point, you're better off using a traditional VPN (WG, OpenVPN, or heaven forbid, IPSec), because it ends up being more straightforward (not easier) without the abstractions and easy-button stuff.

replies(10): >>43628638 #>>43628773 #>>43629221 #>>43629247 #>>43629638 #>>43630250 #>>43630297 #>>43630660 #>>43631345 #>>43674964 #
atomicnumber3 ◴[] No.43628773[source]
>$6/user/m, but if you want to use ACLs to control anything in a workable way, it jumps 3x to $18/u/m.

It's market segmentation, needing ACLs is a sign you're at least an SMB, and to a business of nearly any actual size, the difference between $6/user and $18/user is 0.

replies(5): >>43628801 #>>43629300 #>>43630261 #>>43632383 #>>43674980 #
wkat4242 ◴[] No.43629300[source]
Uh I work for an enterprise of tens of thousands of users and $18 a month is not nothing for us. In fact considering the discounts we get at our size that would be so high we'd never consider it.

We don't even use windows enterprise for the same reason, we have legacy office 365 plans and lifetime windows licenses without the M365 addons because it saves is a few bucks per head. At our size, a few bucks a head quickly add up to millions per year. Microsoft keeps trying to dissuade us and they even pretend office 365 plans don't exist anymore ("office 365 is now microsoft 365") but they do: https://www.microsoft.com/en-us/microsoft-365/enterprise/off... . The same with their Copilot stuff. 30$ is a non starter. Our users want it but nope (and we did a trial in one big team and only 10% actually bothered to use it after the first month so I think it's more the idea of it that want rather than the actual product)

We don't use Tailscale but $6 would be feasible where $18 would be a complete nonstarter.

In fact our company is a lot more cost conscious than I am as a consumer.

replies(4): >>43629785 #>>43629818 #>>43630316 #>>43639814 #
lmeyerov ◴[] No.43630316[source]
Enterprise math is interesting --

For a global all-you-can-eat enterprise-wide rollout:

* base: 20K users x $200/yr

* 50% discount: volume + multi-year + ...

=> enterprise: $1M/yr

=> 200 person division in the enterprise: $10K/yr

It's not cheap, but averaging out a global rollout, not terrible afaict

(This is super rough. Ex: Add in BYO hardware, internal staffing, pro serv, and who knows the real discounting!)

replies(1): >>43630736 #
1. wkat4242 ◴[] No.43630736[source]
Yeah no idea of the discounts there nor of how much we spend on our current VPN provider (I don't work in that team). I guess for a VPN they might have higher spending limits as a VPN is always required to be on on all of our endpoints.