@chiefgyk3d · ChiefGyk3D
Saved 2026-07-02 · Posted 2026-06-19 · Status: New
Ditch the VPN! TwinGate on Raspberry Pis offers secure remote access without inbound ports. It's SASE in action, a concept rarely taught. Home lab it! #TwinGate #HomeLab #SASE #Cybersecurity #RaspberryPi #NetworkSecurity #TechTips #RemoteAccess
Content ideas (0)
No ideas generated yet. Run /instagram-sync ideate from Claude Code to create some.
Comments (15)
You moved the attack surface from your control to a 3rd party.
Hot take: too many people in cybersecurity hear SASE or ZTNA and immediately reduce it to, “You just moved your VPN trust to a vendor.”
That is not an informed critique. It is a lazy oversimplification.
WireGuard and OpenVPN are great technologies. I use WireGuard-based tools myself. But a traditional VPN is generally built around extending network access: connect a user or device to a network, then control what it can reach with firewall rules, ACLs, VLANs, and segmentation.
SASE and ZTNA are about changing that access model. Instead of broadly placing someone on a network, access can be identity-aware, policy-driven, segmented, and scoped to the specific application, resource, or subnet someone actually needs.
That does not mean traditional VPNs are automatically bad. It does not mean every SASE vendor is perfect. It does not mean there are no trust tradeoffs.
It means “VPN but cloud” is not a serious explanation of the architecture.
And the “you have to trust a vendor” argument is not even universally true. NetBird can be fully self-hosted. Twingate, Zscaler, Cloudflare Zero Trust, Tailscale, NetBird, and Headscale all take different approaches to identity-aware remote access, overlay networking, and zero-trust access.
They are not all interchangeable, and they are not all full SASE platforms. Some are primarily ZTNA solutions. Some are WireGuard-based mesh or overlay networks. Some offer broader SASE or SSE capabilities. That distinction matters.
You do not have to deploy SASE. You do not have to like a particular vendor. You do not have to replace every VPN tomorrow.
But if you do not understand what SASE is, stop arguing about it and start studying it.
But now you’re relying on 3rd party servers?
"i used to own home and random stranger used to knock on my door. now i live in an apartment building with doorman and pay rent for the rest of my life."
Noob question, can’t you just use a IP changer as well as a MAC changer instead of using a VPN.
So instead of securing your own vpn endpoint, you trust a corporation to do it?
Second twingate ad in 5 mins. Why are all these homelabbers wanting me to route my traffic through 3rd party servers?
This is cool but I just decided to airgap my entire home network instead. I’m a lifelong penetration tester and the internet scares me now lmao
Wireguard doesn't respond to a knock attempt when there is no keys to handshake.
It’s like I always say in Canyoneering, more gear is more points to f failure. Tie the tope to you, not the carabiner.. Less points of failure for anything in life, the better.
Twingate since homeland day 1 it's the IMO the simplest and best method
Holy LARP, SASE is literally taught in Sec+ as of 2023 dude
As a guy who works in an enterprise telco, this is way more impressive than people are giving credit, this kinda stuff is used all the time and its very reliable, its like using a nuclear bunker to stop a bullet, like yes it could be over kill but its better to be over prepared than under cus if someone does rock up with a nuke then your still fine
A good vpn end point is attached to a good security appliance. Plus good luck gaining access to a vpn end point
you can do the same thing with wireguard vpn seems redundant