Finding the Right VPN for Our Team
Key point
Inflab shares its technical experience and comparison of going through AWS Client VPN and Firezone before settling on Tailscale.
Details
Inflab has reviewed and adopted various VPN solutions to manage access to internal resources on its private network. Initially, the company used the managed service AWS Client VPN, but it had a limitation in that its mobile client did not support SAML authentication.
Inflab then switched to Firezone, an open-source solution based on WireGuard. Firezone offered advantages such as excellent performance and mobile SSO support, but issues arose including the open-source project's shift to a paid model, the inability to configure detailed permissions, and traffic costs from having to include the entire CloudFront IP range when implementing Split tunnel.
Ultimately, Inflab evaluated Tailscale and Netbird. Both solutions have the following characteristics:
- Excellent performance based on WireGuard
- Detailed permission settings available at the tag and group level
- Support for domain-based Split tunnel using a DNS proxy
In particular, domain-based Split tunnel allows only the necessary domains to be routed through the VPN, effectively reducing unnecessary traffic and costs.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.