ZTXGate vs Tailscale
ZTXGate and Tailscale both use WireGuard-based secure connectivity, but they build different products and operating models around that transport.
Tailscale combines its peer-networking platform with increasingly application-aware access capabilities. Its Tailscale PAM product is currently in beta and materially expands the comparison by adding browser access, application proxies, request-based policy, credential handling, and session recording.
ZTXGate is a customer- or MSP-operated ZTNA platform designed around explicit resource access, optional licensed clientless HTTP/HTTPS access, and standalone or fully air-gapped operation.
Product-status note: Tailscale PAM is currently documented as beta. Its capabilities may change quickly, so this page should be rechecked more frequently than mature-product comparisons.
At a Glance
| Area | ZTXGate | Tailscale |
|---|---|---|
| Secure transport | WireGuard-based managed access | WireGuard-based tailnet connectivity |
| Standard control model | Customer- or MSP-operated ZTXGate deployment | Tailscale coordination/control service |
| Custom control server | ZTXGate itself is customer/MSP operated | Official clients can point to a custom control server such as Headscale |
| Resource/application policy | ZTXGate resource policy | Tailscale Grants plus Tailscale PAM application policy |
| Clientless/browser access | Licensed HTTP/HTTPS proxy capability | Tailscale PAM browser client; HTTP, SSH, databases, RDP, and other services documented |
| Device posture | Intune, Defender for Endpoint, SentinelOne, CrowdStrike, Jamf | CrowdStrike, SentinelOne, Jamf Pro, Intune and other documented integrations |
| MFA | Licensed integrated ZTXBAS phishing-resistant biometric authentication; external options where reachable | User authentication and MFA delegated to configured identity provider |
| Fully air-gapped ZTNA with integrated MFA | Supported | Not established for the standard Tailscale service or current PAM architecture in the documentation reviewed |
| PAM capabilities | ZTXGate is not positioned as a full PAM platform | PAM beta includes credential injection, protocol-aware access, session recording, and broader service coverage |
| Resilience model | Periodic backup and restore to a fresh deployment; no conventional HA clustering | Existing tailnet traffic can largely continue during coordination-server outage; PAM has its own connector/service architecture |
A useful comparison must distinguish standard Tailscale, Tailscale PAM, and Tailscale clients using a custom control server such as Headscale rather than treating all three as one identical operating model.
WireGuard in Each Architecture
WireGuard is secure transport in both products, but it is not the whole access-control system.
ZTXGate adds user/device/resource policy, posture inputs, request-and-approve workflows, continuous enforcement, clientless HTTP/HTTPS access, audit, and optional integrated ZTXBAS authentication around WireGuard-based managed connectivity.
Standard Tailscale creates an identity-aware private network and distributes connectivity and policy information through its coordination system. Tailscale Grants support network- and application-layer permissions, while Tailscale PAM adds a more application-aware proxy and privileged-session model.
Standard Tailscale Control Model
Tailscale documents its coordination server as the centralized component that distributes public keys and firewall rules to devices. Traffic normally flows directly between endpoints where possible rather than through the coordination server.
If the Tailscale coordination service is unavailable, current documentation states that existing devices can largely continue communicating while cached keys and firewall rules remain valid. However:
- new users and devices cannot be added
- keys cannot be refreshed or exchanged
- firewall rules cannot be updated
- existing users cannot have keys revoked through the unavailable control service
This is outage tolerance, not the same thing as a permanently disconnected lifecycle model.
Custom Control Servers and Headscale
Tailscale's official clients support configuration of a custom control-server URL, including a self-managed Headscale deployment.
That is important because it means “Tailscale always requires the hosted Tailscale coordination server” would be inaccurate.
However, a custom Headscale control server should not automatically be assumed to provide every hosted Tailscale or Tailscale PAM capability. Those are separate products and architectures.
The current Tailscale PAM documentation, for example, requires a PAM-enabled tailnet and Tailscale admin-console workflow, and the connector installation documentation requires Internet egress to Tailscale PAM APIs and proxies.
So this comparison distinguishes:
Tailscale hosted service
vs
Tailscale clients + custom control server
vs
Tailscale PAM beta
rather than labeling all of them simply “self-hosted Tailscale.”
Tailscale PAM Changes the Comparison
Tailscale PAM is much broader than a conventional mesh-VPN comparison.
Current beta documentation describes support for:
- HTTP/HTTPS
- SSH
- databases
- Kubernetes
- RDP
- VNC
- arbitrary TCP services
- browser-based clientless access
- credential injection
- session recording/playback for supported services
- request-based policies
These capabilities exceed what ZTXGate currently claims in areas such as protocol-aware privileged access, credential injection, and session recording.
ZTXGate should therefore not position itself as “Tailscale plus application policy.” The two products now overlap in access use cases while retaining different operating and deployment models.
Clientless and Browser Access
ZTXGate provides a licensed clientless proxy for supported HTTP and HTTPS applications.
Tailscale PAM's browser client provides a broader current clientless portfolio, including documented browser access to SSH, databases, RDP, and other services. Its HTTP service flow also provides identity-based access to internal web applications through the PAM connector.
That broader protocol coverage is a Tailscale PAM strength.
The ZTXGate distinction is its ability to keep the ZTNA access platform and licensed HTTP/HTTPS clientless path inside a customer- or MSP-operated deployment, including environments that cannot depend on Tailscale PAM cloud services.
Identity and Device Posture
Tailscale explicitly states that it is not an identity provider. User authentication is delegated to native or custom OIDC identity providers, and the IdP's MFA policies apply to Tailscale.
ZTXGate supports OIDC and SCIM in connected deployments and also supports licensed integrated ZTXBAS for phishing-resistant biometric authentication.
Both products have meaningful device-posture integrations.
ZTXGate supports:
- Microsoft Intune
- Microsoft Defender for Endpoint
- SentinelOne Singularity
- CrowdStrike
- Jamf
Current Tailscale documentation lists integrations including:
- CrowdStrike Falcon
- SentinelOne
- Jamf Pro
- Microsoft Intune
- additional EDR/MDM providers
Device posture itself is therefore shared territory rather than a unique differentiator.
Authentication When the Cloud Is Unreachable
ZTXGate
A standalone ZTXGate deployment can be intentionally and permanently air-gapped. When licensed, integrated ZTXBAS provides phishing-resistant biometric authentication inside that isolated deployment without requiring a separate ZTXBAS server or external cloud MFA service.
Licensing and software updates can be handled manually when the optional CoreZT-operated ZTXHub service is not used.
Standard Tailscale
Tailscale delegates user authentication and MFA to the configured identity provider. If the coordination server is unavailable, existing connectivity can continue for a period because keys and policy are cached, but current documentation states that new users/devices cannot be added and keys/policies cannot be refreshed or updated.
That is meaningful continuity for an existing tailnet, but it is not a documented permanently disconnected authentication lifecycle.
Tailscale PAM
Current Tailscale PAM documentation requires a PAM-enabled tailnet and a connector that can reach Tailscale PAM APIs and proxies through the Internet. Users authenticate with their Tailscale identity.
The documentation reviewed does not establish a Headscale-only or permanently air-gapped mode for the current Tailscale PAM beta.
The comparison is therefore not “Tailscale lacks MFA.” Tailscale can inherit strong MFA from its IdP. The distinction is that ZTXGate can keep its licensed phishing-resistant biometric authentication path inside a fully air-gapped access deployment.
Audit and Privileged Sessions
Tailscale PAM currently documents session context and recording/playback for supported service types, along with credential and secrets capabilities.
ZTXGate records access, authentication, and policy activity and can export relevant events to SIEM environments. It is not currently positioned as a full privileged-session recording or credential-vaulting platform.
Organizations specifically seeking PAM functions such as credential injection or full session recording should account for that difference directly.
Operational Ownership
Tailscale may fit well when:
- peer-oriented private networking is a primary requirement
- the hosted Tailscale coordination model is acceptable
- broad Tailscale PAM capabilities are attractive despite the product currently being beta
- session recording, credential injection, database-aware access, or broader browser protocol coverage are required
- an organization's existing IdP and MFA strategy should remain the authentication authority
ZTXGate may fit well when:
- the ZTNA platform should be customer- or MSP-operated
- permanent standalone or air-gapped operation is required
- phishing-resistant biometric authentication must remain available inside that air-gapped deployment
- a mandatory hosted coordination/control service is undesirable
- the access requirement is focused on ZTNA rather than a broader emerging PAM platform
- WireGuard-based managed access and licensed HTTP/HTTPS clientless access cover the required protocols
This is not an overall ranking. The products now overlap in some access scenarios but remain architecturally and operationally different.
Official Sources Used
Tailscale facts on this page were verified against current first-party documentation:
- What happens if the coordination server is down?
- Configure clients to use a custom control server
- Supported SSO identity providers
- Device posture management
- Tailscale PAM
- Tailscale PAM architecture and core concepts
- Get started with Tailscale PAM
- Install a Tailscale PAM connector
- Access an HTTP service using Tailscale PAM