Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Homelab

SoftEther vs. Tailscale: Which Is Better for Remote Access and Site-to-Site Networking?

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For most new homelab, personal, and small-team setups, Tailscale is the easier default: it connects authenticated devices through a WireGuard-based mesh and usually avoids port forwarding. Choose SoftEther when you need to run the VPN server yourself, support traditional VPN clients, or bridge networks at Layer 2. These products solve related but different problems: SoftEther is self-hosted VPN server software; Tailscale is a managed, identity-based networking platform.

SoftEther and Tailscale at a glance

Question SoftEther Tailscale
What is it? Self-hosted VPN server software with virtual hubs, bridging, and routing. A managed coordination and networking platform that connects devices in an encrypted mesh.
Typical topology Clients connect to a VPN server; the server connects them to hubs, networks, or routes. Devices connect directly where possible; relays can carry encrypted traffic when a direct path fails.
Protocols and clients Native SoftEther protocol, plus compatibility options including OpenVPN, L2TP/IPsec, SSTP, L2TPv3, and EtherIP/IPsec. Compatibility depends on the client and configuration. Tailscale clients use WireGuard-based connectivity and integrate with identity and policy features.
Network reach Layer-2 bridging and Layer-3 routing. Mesh access between enrolled devices, plus subnet routers for devices on private networks.
Administration You operate the server, operating system, authentication, certificates, firewall, updates, backups, and availability. Tailscale operates the standard coordination service; you manage identity, devices, policy, and any gateways you deploy.
DNS and naming DNS generally needs to be configured through your existing network or a separate DNS service. MagicDNS can provide device names within a tailnet.
Cost model The software is free and open source; hosting and operating it may cost money. A Personal plan is available for non-commercial use; business plans are seat-based.

SoftEther advertises limits of up to 4,096 concurrent VPN sessions, 4,096 virtual hubs, and clusters of up to 64 members. Those are published product limits, not guarantees of capacity or performance in a particular deployment. See the SoftEther specifications.

How the architectures differ

SoftEther: a VPN server you operate

A typical SoftEther deployment has a VPN Server hosting one or more virtual hubs, with clients or VPN bridges connecting to them. From there, the server can use Layer-2 bridging, Layer-3 routing, SecureNAT, or a combination to reach other networks. This traditional server-centered design offers considerable control, but you are responsible for making the server reachable, secure, patched, backed up, and available. The SoftEther project overview and specifications describe its architecture and capabilities.

Tailscale: a coordinated device mesh

Tailscale enrolls devices into a private network called a tailnet. Its coordination service distributes keys and policy information; the devices normally send encrypted traffic directly to one another. If NAT or firewall conditions prevent a direct connection, Tailscale can fall back to a DERP relay. Relaying keeps traffic encrypted but can add latency or reduce throughput. See How Tailscale works and Tailscale’s firewall guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

The standard Tailscale service is not a fully self-hosted control plane. Running a subnet router, exit node, or peer relay on your own hardware does not change who operates the standard coordination service.

Which one fits your use case?

Scenario Better starting point Why
Two-person homelab or family access to a NAS, desktop, or server Tailscale Device-based enrollment, identity controls, and MagicDNS reduce setup work. For devices without a client, add a subnet router.
Developer access to machines across cloud providers and home networks Tailscale A mesh can connect enrolled devices without routing every connection through one VPN server.
Small team that wants identity-aware access and managed coordination Tailscale It combines device enrollment with policy controls; administrators still need to define access rules and manage identity.
Existing equipment needs OpenVPN, L2TP/IPsec, or SSTP compatibility SoftEther Its server offers multiple protocol and client compatibility options. Check the specific client and protocol requirements rather than assuming every device is supported.
Applications need Ethernet broadcasts, Layer-2 discovery, or bridging SoftEther It supports Layer-2 bridging as well as Layer-3 routing. Bridging also extends broadcast traffic and can complicate segmentation.
Connect two or more private networks Either, depending on the routing requirement Tailscale subnet routers advertise selected network routes. SoftEther can use Layer-3 routing or Layer-2 bridging; choose bridging only when the application genuinely requires it.
Must keep the VPN server and its operation under your control SoftEther You can host the server yourself, at the cost of owning its security, maintenance, and availability.
Consumer anonymity or streaming-location changes Neither by default These are private-network connectivity tools, not anonymity guarantees or consumer privacy VPN services.

Remote access, subnet routers, and exit nodes

For direct access to enrolled computers, Tailscale is usually simpler: install the client, authenticate, apply the required policy, and connect using the device’s tailnet address or MagicDNS name. For equipment that cannot run a client—such as some printers, appliances, or older servers—place a subnet router on the local network and advertise the relevant routes. Those other devices remain ordinary network devices; the router provides the path into their subnet.

A subnet router and an exit node do different jobs. A subnet router provides access to selected private network ranges. An exit node routes a device’s general internet traffic through a chosen node. Tailscale documents route advertisement, approval, and default SNAT behavior in its subnet-router guide, and exit-node setup separately in its exit-node guide. For site-to-site designs and overlapping IPv4 ranges, consult the current site-to-site networking documentation.

Rank #2
GL.iNet GL-SFT1200 Opal Travel Router, AC1200 Dual-Band Wi-Fi
  • 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
  • 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
  • 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
  • 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.

SoftEther can also reach devices without individual VPN clients by bridging or routing their LAN through a VPN Server or VPN Bridge. The choice is about network behavior: Layer 2 can carry Ethernet-level discovery, while Layer 3 connects IP networks without extending the same broadcast domain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Setup and ongoing administration

Getting a basic Tailscale network running

  1. Create an account or organization and install the client using the current Tailscale installation instructions for each platform.
  2. Authenticate each device, then review device approval and identity settings for your account.
  3. Enable MagicDNS if you want readable device names, and set ACLs or grants before exposing sensitive services.
  4. For LAN access, configure a subnet router, advertise only the required routes, and approve them in the administration console.
  5. For full-tunnel internet routing, configure and authorize an exit node separately from any subnet router.
  6. Test access to the intended devices and networks. If performance or reachability differs between peers, check whether traffic is direct or relayed and review firewall requirements.

Low-configuration does not mean no administration. Identity-provider settings, device lifecycle, access policy, key expiry, DNS, route approval, exit-node permissions, and restrictive firewalls can all require attention.

Building a basic SoftEther deployment

  1. Download the server software from the official SoftEther download page and install it on an environment supported by the project.
  2. Create a virtual hub and decide how users will authenticate: for example, local users, RADIUS, certificates, or an existing directory integration.
  3. Choose the required network design: Layer-2 bridge, Layer-3 routes, SecureNAT, or a suitable combination.
  4. Configure certificates, listener ports, client access, and host and network firewall rules. The specifications list default TCP listeners on 443, 992, and 5555 and describe NAT traversal; neither removes the need to review exposure and firewall policy.
  5. Restrict administrative access and select compatible client protocols deliberately, avoiding weak or obsolete options where possible.
  6. Set up logging, monitoring, backups, upgrades, and recovery procedures. Test routing, DNS, MTU, reconnects, and failure recovery using the SoftEther reference manual.

SoftEther also documents operation through HTTP or SOCKS proxies and specialized restricted-firewall techniques, including VPN over ICMP or DNS. Treat these as specialized compatibility features, not default production designs; their use may conflict with network policy and complicate security and troubleshooting.

Rank #3
Sale
ASUS RT-AX1800S Dual Band WiFi 6 Extendable Router, Subscription-Free Network Security, Parental Control, Built-in VPN, AiMesh Compatible, Gaming & Streaming, Smart Home
  • New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
  • Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
  • Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
  • 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
  • Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.

Security, privacy, and control

Encryption is only one part of the decision

Tailscale uses WireGuard to encrypt traffic between nodes. Identity-provider authentication, device approval, ACLs or grants, tags, Tailnet Lock, and supported posture or SSH features add access-management controls. The data plane and control plane are different: WireGuard protects traffic between devices, while the coordination service supplies keys and policy information for the standard service. Relays forward encrypted traffic rather than decrypting it.

SoftEther supports TLS-based encryption for its native protocol, along with authentication and policy options such as passwords, RADIUS, directory integration, X.509 certificates, per-user or per-group policies, source-IP controls, and security logging. Its compatibility with older protocols and algorithms is useful for legacy clients, but compatibility does not make every available configuration equally appropriate. Select modern settings, maintain certificates, and restrict management and network exposure. The specifications list the supported mechanisms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Neither is a complete perimeter or anonymity service

A VPN connection does not secure a compromised endpoint, replace a firewall, or guarantee that no one logs activity. An exit node or VPN server changes where traffic exits the network, but it does not itself provide anonymity or prevent logging by the endpoint, network operator, or destination. Tailscale’s access policies govern tailnet connectivity; they are not a substitute for every host or application security control.

Rank #4
Sale
GL.iNet GL-BE3600 Slate 7 Wi-Fi 7 Travel Router Touchscreen 2.5G
  • 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
  • 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
  • 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
  • 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Performance depends on the path and design

There is no evidence-based universal speed winner without testing the same endpoints, hardware, protocols, and network conditions. A direct Tailscale peer connection avoids sending traffic through a central VPN server and may reduce latency or bottlenecks. If it must use DERP, the relay path may be slower. SoftEther throughput depends on server CPU, encryption and protocol choices, topology, and network conditions; TCP-based tunneling can perform poorly under packet loss, especially when layered over other TCP-heavy traffic. SoftEther’s project overview advertises “1Gbps-class” performance, a vendor claim rather than an independently verified result.

For a meaningful comparison, test the paths you would actually deploy: direct Tailscale, relayed Tailscale, SoftEther’s native protocol, and any SoftEther compatibility protocol you plan to use. Keep endpoint hardware, network path, payload, and test duration consistent, and record latency as well as throughput.

Costs and operational ownership

SoftEther software is free and open source, but the operator still pays—in money, time, or both—for hosting, administration, monitoring, backups, certificates, and support arrangements. A self-hosted server may have no vendor seat subscription while still carrying real lifecycle and availability costs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
TP-Link Dual-Band AX3000 Wi-Fi 6 Wireless Gigabit Internet Router for Home
  • Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
  • A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
  • Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
  • Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
  • Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.

Tailscale’s pricing page lists a Personal plan at $0 for non-commercial use and paid, seat-based plans for business use; plans, limits, and prices can change. Check the current pricing page before choosing a plan. The convenience of managed coordination reduces control-plane operations, but you remain responsible for endpoint security, identity-provider security, access policy, device lifecycle, and any routers or exit nodes you run.

Common failure modes to plan for

Tailscale

  • Slow connection: a peer may be using a DERP relay because direct connectivity failed. Review firewall requirements and the connection path.
  • Route does not work: a subnet route may be advertised but not approved, or the destination network may lack a return route. Default SNAT can also mean devices see the subnet router’s address rather than the original client.
  • Internet traffic takes the wrong path: confirm whether the device is using an exit node; it is not interchangeable with a subnet router.
  • Unexpected access or DNS behavior: check policy scope and whether local DNS or security software overrides MagicDNS. Broad access rules can expose more services than intended.
  • Enrollment or device lifecycle problems: identity-provider availability can affect new authentication or enrollment, while expired keys or stale devices can interrupt access.

SoftEther

  • Server compromise or outage: an exposed management interface, missed updates, weak credentials, or a single-server design can put the whole deployment at risk.
  • One-way or missing connectivity: check routes in both directions, overlapping subnets, firewall rules, and DNS.
  • Intermittent or poor performance: review protocol choice, packet loss, server resources, MTU, and whether TCP is being tunneled over TCP.
  • Client trust errors: verify certificate names, trust chains, and the hostname clients use.
  • Unexpected network noise or segmentation: Layer-2 bridging can extend broadcasts. Use it only where the application requires Ethernet-level behavior.
  • Configuration drift: manually maintained users, hubs, routes, ports, certificates, and policies need documented review and backups.

Final recommendation

Start with Tailscale when the goal is straightforward, identity-aware access among people and devices, especially across homes and cloud networks. Choose SoftEther when self-hosted control, traditional client compatibility, or Layer-2 bridging is a real requirement and you can operate the server securely. If your priority is centrally inspecting all traffic, a certified firewall appliance, or application-level access controls, neither should be selected automatically: evaluate the network-security architecture that requirement calls for.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.