Tailscale's DERP (Designated Encrypted Relay for Packets) protocol solves NAT traversal failures caused by symmetric NAT, carrier-grade NAT, and restrictive firewalls. DERP relays forward WireGuard-encrypted packets over HTTPS port 443 without ever decrypting them, acting as a fallback when direct peer-to-peer connections fail.

18m read time From sitepoint.com
Post cover image
Table of contents
What Are Tailscale Peer Relays (DERP)?Table of ContentsThe "Hard" NAT Problem: Why Hole Punching FailsHow Tailscale's DERP Protocol Actually WorksWhen and Why You Need a Self-Hosted DERP RelayDeploying a Self-Hosted DERP Relay: Step by StepTroubleshooting and Performance TuningDERP vs. the Alternatives: Where It Fits in the EcosystemDirect When Possible, Relayed When Necessary

Sort: