Skip to main content

ZTXGate vs Tailscale

ZTXGate and Tailscale both use WireGuard-based secure connectivity, but they build different products and operating models around that transport.

Tailscale combines its peer-networking platform with increasingly application-aware access capabilities. Its Tailscale PAM product is currently in beta and materially expands the comparison by adding browser access, application proxies, request-based policy, credential handling, and session recording.

ZTXGate is a customer- or MSP-operated ZTNA platform designed around explicit resource access, optional licensed clientless HTTP/HTTPS access, and standalone or fully air-gapped operation.

Product-status note: Tailscale PAM is currently documented as beta. Its capabilities may change quickly, so this page should be rechecked more frequently than mature-product comparisons.

At a Glance

AreaZTXGateTailscale
Secure transportWireGuard-based managed accessWireGuard-based tailnet connectivity
Standard control modelCustomer- or MSP-operated ZTXGate deploymentTailscale coordination/control service
Custom control serverZTXGate itself is customer/MSP operatedOfficial clients can point to a custom control server such as Headscale
Resource/application policyZTXGate resource policyTailscale Grants plus Tailscale PAM application policy
Clientless/browser accessLicensed HTTP/HTTPS proxy capabilityTailscale PAM browser client; HTTP, SSH, databases, RDP, and other services documented
Device postureIntune, Defender for Endpoint, SentinelOne, CrowdStrike, JamfCrowdStrike, SentinelOne, Jamf Pro, Intune and other documented integrations
MFALicensed integrated ZTXBAS phishing-resistant biometric authentication; external options where reachableUser authentication and MFA delegated to configured identity provider
Fully air-gapped ZTNA with integrated MFASupportedNot established for the standard Tailscale service or current PAM architecture in the documentation reviewed
PAM capabilitiesZTXGate is not positioned as a full PAM platformPAM beta includes credential injection, protocol-aware access, session recording, and broader service coverage
Resilience modelPeriodic backup and restore to a fresh deployment; no conventional HA clusteringExisting tailnet traffic can largely continue during coordination-server outage; PAM has its own connector/service architecture

A useful comparison must distinguish standard Tailscale, Tailscale PAM, and Tailscale clients using a custom control server such as Headscale rather than treating all three as one identical operating model.

WireGuard in Each Architecture

WireGuard is secure transport in both products, but it is not the whole access-control system.

ZTXGate adds user/device/resource policy, posture inputs, request-and-approve workflows, continuous enforcement, clientless HTTP/HTTPS access, audit, and optional integrated ZTXBAS authentication around WireGuard-based managed connectivity.

Standard Tailscale creates an identity-aware private network and distributes connectivity and policy information through its coordination system. Tailscale Grants support network- and application-layer permissions, while Tailscale PAM adds a more application-aware proxy and privileged-session model.

Explore WireGuard & ZTNA

Standard Tailscale Control Model

Tailscale documents its coordination server as the centralized component that distributes public keys and firewall rules to devices. Traffic normally flows directly between endpoints where possible rather than through the coordination server.

If the Tailscale coordination service is unavailable, current documentation states that existing devices can largely continue communicating while cached keys and firewall rules remain valid. However:

  • new users and devices cannot be added
  • keys cannot be refreshed or exchanged
  • firewall rules cannot be updated
  • existing users cannot have keys revoked through the unavailable control service

This is outage tolerance, not the same thing as a permanently disconnected lifecycle model.

Custom Control Servers and Headscale

Tailscale's official clients support configuration of a custom control-server URL, including a self-managed Headscale deployment.

That is important because it means “Tailscale always requires the hosted Tailscale coordination server” would be inaccurate.

However, a custom Headscale control server should not automatically be assumed to provide every hosted Tailscale or Tailscale PAM capability. Those are separate products and architectures.

The current Tailscale PAM documentation, for example, requires a PAM-enabled tailnet and Tailscale admin-console workflow, and the connector installation documentation requires Internet egress to Tailscale PAM APIs and proxies.

So this comparison distinguishes:

Tailscale hosted service
vs
Tailscale clients + custom control server
vs
Tailscale PAM beta

rather than labeling all of them simply “self-hosted Tailscale.”

Tailscale PAM Changes the Comparison

Tailscale PAM is much broader than a conventional mesh-VPN comparison.

Current beta documentation describes support for:

  • HTTP/HTTPS
  • SSH
  • databases
  • Kubernetes
  • RDP
  • VNC
  • arbitrary TCP services
  • browser-based clientless access
  • credential injection
  • session recording/playback for supported services
  • request-based policies

These capabilities exceed what ZTXGate currently claims in areas such as protocol-aware privileged access, credential injection, and session recording.

ZTXGate should therefore not position itself as “Tailscale plus application policy.” The two products now overlap in access use cases while retaining different operating and deployment models.

Clientless and Browser Access

ZTXGate provides a licensed clientless proxy for supported HTTP and HTTPS applications.

Tailscale PAM's browser client provides a broader current clientless portfolio, including documented browser access to SSH, databases, RDP, and other services. Its HTTP service flow also provides identity-based access to internal web applications through the PAM connector.

That broader protocol coverage is a Tailscale PAM strength.

The ZTXGate distinction is its ability to keep the ZTNA access platform and licensed HTTP/HTTPS clientless path inside a customer- or MSP-operated deployment, including environments that cannot depend on Tailscale PAM cloud services.

Explore Clientless ZTNA

Identity and Device Posture

Tailscale explicitly states that it is not an identity provider. User authentication is delegated to native or custom OIDC identity providers, and the IdP's MFA policies apply to Tailscale.

ZTXGate supports OIDC and SCIM in connected deployments and also supports licensed integrated ZTXBAS for phishing-resistant biometric authentication.

Both products have meaningful device-posture integrations.

ZTXGate supports:

  • Microsoft Intune
  • Microsoft Defender for Endpoint
  • SentinelOne Singularity
  • CrowdStrike
  • Jamf

Current Tailscale documentation lists integrations including:

  • CrowdStrike Falcon
  • SentinelOne
  • Jamf Pro
  • Microsoft Intune
  • additional EDR/MDM providers

Device posture itself is therefore shared territory rather than a unique differentiator.

Authentication When the Cloud Is Unreachable

ZTXGate

A standalone ZTXGate deployment can be intentionally and permanently air-gapped. When licensed, integrated ZTXBAS provides phishing-resistant biometric authentication inside that isolated deployment without requiring a separate ZTXBAS server or external cloud MFA service.

Licensing and software updates can be handled manually when the optional CoreZT-operated ZTXHub service is not used.

Standard Tailscale

Tailscale delegates user authentication and MFA to the configured identity provider. If the coordination server is unavailable, existing connectivity can continue for a period because keys and policy are cached, but current documentation states that new users/devices cannot be added and keys/policies cannot be refreshed or updated.

That is meaningful continuity for an existing tailnet, but it is not a documented permanently disconnected authentication lifecycle.

Tailscale PAM

Current Tailscale PAM documentation requires a PAM-enabled tailnet and a connector that can reach Tailscale PAM APIs and proxies through the Internet. Users authenticate with their Tailscale identity.

The documentation reviewed does not establish a Headscale-only or permanently air-gapped mode for the current Tailscale PAM beta.

The comparison is therefore not “Tailscale lacks MFA.” Tailscale can inherit strong MFA from its IdP. The distinction is that ZTXGate can keep its licensed phishing-resistant biometric authentication path inside a fully air-gapped access deployment.

Explore Air-Gapped ZTNA

Audit and Privileged Sessions

Tailscale PAM currently documents session context and recording/playback for supported service types, along with credential and secrets capabilities.

ZTXGate records access, authentication, and policy activity and can export relevant events to SIEM environments. It is not currently positioned as a full privileged-session recording or credential-vaulting platform.

Organizations specifically seeking PAM functions such as credential injection or full session recording should account for that difference directly.

Operational Ownership

Tailscale may fit well when:

  • peer-oriented private networking is a primary requirement
  • the hosted Tailscale coordination model is acceptable
  • broad Tailscale PAM capabilities are attractive despite the product currently being beta
  • session recording, credential injection, database-aware access, or broader browser protocol coverage are required
  • an organization's existing IdP and MFA strategy should remain the authentication authority

ZTXGate may fit well when:

  • the ZTNA platform should be customer- or MSP-operated
  • permanent standalone or air-gapped operation is required
  • phishing-resistant biometric authentication must remain available inside that air-gapped deployment
  • a mandatory hosted coordination/control service is undesirable
  • the access requirement is focused on ZTNA rather than a broader emerging PAM platform
  • WireGuard-based managed access and licensed HTTP/HTTPS clientless access cover the required protocols

This is not an overall ranking. The products now overlap in some access scenarios but remain architecturally and operationally different.

Official Sources Used

Tailscale facts on this page were verified against current first-party documentation:

Explore ZTXGate · Start Free Trial