Why Tailscale is slow: relay vs direct
Relayed Tailscale is slow, direct is close to line rate. Two commands tell you which you have, plus the blocked UDP and hard NAT fixes for a VPS.
Filtering by topic #nat · clear
Relayed Tailscale is slow, direct is close to line rate. Two commands tell you which you have, plus the blocked UDP and hard NAT fixes for a VPS.
CGNAT leaves you with no public IP. Put frp on a cheap VPS, dial the tunnel out from home, and terminate HTTPS on the public end with a real certificate.
On Ubuntu the iptables command already writes nftables rules. Prove it on your box, read the native ruleset, and see where ufw and Docker collide.