I've installed the latest OpenWrt 25.12.5 on a AR750S Slate to test prior to buying a new Beryl 7 from GL.iNet. The AR750S with the latest OpenWrt works fine but a little slow to setup and respond to changes. I figure the Beryl 7 will solve the performance issues.
After everything was working I installed Tailscale and got it working so I could remotely access my NAS at home. However, starting Tailscale and configuring it on the Slate was painfully slow.
I assume that this was too much for the old Slate.
So it got me thinking. If I'm remote and connect my laptop to the AR750S in repeater mode and the router is connected to a public non trusted WiFi, I'm behind a NAT and Firewall so safe, but not connected to my home NAS. I can install Taliscale on the laptop and connect it to the NAS quick and easily.
So for this use case, I'd say that it works fine and has equally good protection as running Tailscale on the AR750S Slate and not the laptop.
I'm hoping the much newer Beryl 7 will have no issues with performance, but the use case of Tailscale on the router or just on the laptop is still puzzling to me.
Can someone explain when to use Tailscale on the router?
You use things like Tailscale ( or Netbird or Zerotier etc.)
When you cannot directly connect to your router from outside.
If you can then using WireGuard is easier and faster to setup and does not involve a third party.
I have used Tailscale in R7800 ARM7 dual core @ 1.7ghz and EX5700 (ARM8 quad core @ 2ghz) directly inside router. Works fine in both cases although EX5700 will do significantly higher speeds.
In my experience, should have a router with at least 512MB ram. But maybe you can get away with 256MB. As the Slate has 128MB I’m surprised it’s even running without locking up.
As the router is «always on», I find it very convenient to have it running on the router. I also have it running on my NAS, just in case.
I run tailscale on my NTP server a raspberry pi4B that runs 24/7 anyways, that is configured as exit node, so I can access my home network, my router's config interface and the internet that way.
I also try to not run too much on my router, but that is a subjective preference.
In my current test, Tailscale have been removed from the AR750S Slate. I have my PC connected via Ethernet to the Slate and the Slate using Repeater mode to connect to my Home network main AP. This isn't completely remote because my PC in on 192.168.8.0/24 which in this case is a subnet of 192.168.68.0/24, my home net. But using .local doesn't work but actual IP address do work. Using the 10.*.* addressing of tailscale works or the MagicDNS names work.
Anyway it provides a convenient test bed.
I added all my key PCs and servers and NASs to my Tailnet. So I can ssh or browse into any device on my home network via Tailscale MagicDNS names and my Dolphin file manager can connect via smb://MagicNDS name to the Synology NAS which has the Tailscale package installed.
So in this case I have full access to everything on my home network remotely using Tailscale on each of those devices and I have NOT installed Tailscale on the travel router.
I'm now trying to figure out if exit nodes are of any use for me, but I don't understand them beyond the case of using a PC on my home network to access a bank website remotely using Tailscale. But if I have a fully updated OpenWrt travel router between my laptop and the public wifi, I'm not sure I'm at risk going straight to the Banking website from the laptop.