cross-posted from: https://discuss.online/post/34942012
I find everyone using different services, so unsure how to best manage (and balance) concurrent access in Ubuntu/Debian to:
- Local network services
- Tailscale services from userA
- Tailscale services from userB
- Wireguard (OpenVPN also option) from userC
- Twingate from userD
Each user is wanting to share different services via VPN, and pressuring any to change their production setups to a different style of VPN is not going to happen.
- Management via software
- Possibly up a routing device along the lines of OpenWrt or OpnSense.
- Could even distribute such devices between these friends.
Thanks for all thoughts!
Assuming all the networks are on independent subnets, the kernel’s routing tables should mostly send IP traffic in the right direction. For instance, if your LAN is on
192.168.0.0/24, Network A is192.168.32.0/24, and Network B is10.0.16.0/16, then on a machine directly connected to all the networks, packets will basically just go to the right place. However:- If you want devices on your LAN to be able to reach those other networks without directly connecting, you’ll need to set up a routing table for those devices. That’s where an OpenWrt (or similar) device comes in.
- If the networks’ subnets overlap, it’ll be a rough time. Let’s say that Network C is on the same range as your LAN; now you can’t directly route to it because your computer doesn’t know which instance of
192.168.0.13you actually wanted to connect to. There are ways around this, but they get more complicated. It’s better (if possible) to just have everyone pick non-overlapping subnets. - This is just the IP layer. If you want to access services through a domain name, you’ll probably want a DNS server (e.g.
dnsmasq) that forwards requests to the appropriate name servers for each network. If you have service names or auto-discovery through multicast DNS, you’ll need an mDNS reflector to forward the traffic across network boundaries.
This is just basic network routing and subnetting.
Okay, although it certainly doesn’t seem basic.
You didn’t really include any details about your current VPN setups, your subnets, your routing rules, etc for anyone to give you a useful answer.
I’m not sure what you’d like here. You didn’t give much info.
Did you want someone to literally work out a full config for you in here? We don’t know what you’re even running.
Example setup:
- Jellyfin user access from TailscaleA
- Nextcloud user access from TailscaleB
- Jellyfin user access from Wireguard
- Jellyfin user access from Twingate
- Jellyfin user access from local services
How would you manage this in a somewhat seamless manner?

