Tailscale-Based Overlay Network Architecture for Proxmox VE

Authors

  • Fiqih Akbari Politeknik Negeri Sambas

DOI:

10.33395/sinkron.v10i3.16296

Keywords:

Edge computing testbed; firewall hardening; overlay network; Proxmox VE; remote management; sovereign edge computing; Tailscale

Abstract

Remote management of virtualized infrastructure introduces security risk when management services are exposed directly to the public internet. This risk is amplified when testbeds are intended to support sovereign edge computing workloads that require secure, isolated infrastructure. This study designs and evaluates a secure remote management architecture for a Proxmox VE node using a Tailscale overlay network and interface-specific firewall hardening, establishing a foundational infrastructure baseline for sovereign edge computing. The research follows Design Science Research supported by a network engineering evaluation procedure. The artefact was developed through problem identification, topology design, implementation, measurement, and evaluation. Data were collected from Tailscale status checks, Proxmox VE observation, ping latency testing, relay netcheck output, iptables verification, and external port scanning before and after firewall hardening. The Tailscale path achieved an average round-trip time of 0.434 milliseconds with zero packet loss, comparable to the public Internet Protocol path at 0.540 milliseconds with zero packet loss. Before hardening, public scanning detected management ports 22, 2222, and 8006. After applying interface-specific firewall rules, the external scan reported no open ports among the top 1000 ports, while private access to Proxmox VE through the Tailscale interface remained available. The proposed architecture demonstrates that overlay networking must be combined with firewall hardening to remove public management exposure without disrupting authorized remote administration. The result establishes a replicable foundational infrastructure baseline for sovereign edge computing, providing the first stage toward deployment of secure edge computing systems in resource-limited environments.

GS Cited Analysis

Downloads

Download data is not yet available.

References

Anyam, J., Singh, R. R., Larijani, H., & Philip, A. (2025). Empirical performance analysis of WireGuard vs. OpenVPN in cloud and virtualised environments under simulated network conditions. Computers, 14(8), 326. https://doi.org/10.3390/computers14080326

Bonawitz, K., et al. (2019). Towards federated learning at scale: System design. Proceedings of Machine Learning and Systems, 1, 374–388.

Deutschmann, J., Jahandar, S., Hielscher, K.-S., & German, R. (2023). Internet via satellite: GEO vs. LEO, OpenVPN vs. WireGuard, and CUBIC vs. BBR. Proceedings of the 1st ACM MobiCom Workshop on Satellite Networking and Computing. https://doi.org/10.1145/3614454.3622998

Donenfeld, J. A. (2017). WireGuard: Next generation kernel network tunnel. Proceedings of the Network and Distributed System Security Symposium (NDSS).

Kjorveziroski, V., Filiposka, S., Kocarev, L., & Prodan, R. (2025). Federated architecture for serverless platforms aimed at transparent execution in the edge-cloud continuum. International Journal of Cloud Computing, 14(2), 145–166. https://doi.org/10.1504/IJCC.2025.145664

Kondoj, M., Langi, H., & Putung, Y. (2022). Performance analysis of cloud computing based e-commerce server using Proxmox virtual environment. Proceedings of the 5th International Conference on Applied Science and Technology on Engineering Science (iCAST-ES). https://doi.org/10.5220/0011876000003575

Mackey, S., Mihov, I., Nosenko, A., Vega, F., & Cheng, Y. (2020). A performance comparison of WireGuard and OpenVPN. Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy, 162–164. https://doi.org/10.1145/3374664.3379532

Mell, P., & Grance, T. (2011). The NIST definition of cloud computing. National Institute of Standards and Technology, Special Publication 800-145.

Pepito, R., & Dutta, A. (2021). Open source 5G security testbed for edge computing. 2021 IEEE 4th 5G World Forum (5GWF). https://doi.org/10.1109/5GWF52925.2021.00075

Proxmox Server Solutions GmbH. (2025). Proxmox Virtual Environment documentation. https://pve.proxmox.com/pve-docs/

Qiao, Y., Xiong, J., & Zhao, Y. (2025). Network-aware container scheduling in edge computing. Cluster Computing, 28(3), 477–492. https://doi.org/10.1007/s10586-024-04733-8

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture. National Institute of Standards and Technology, Special Publication 800-207. https://doi.org/10.6028/NIST.SP.800-207

Ruhault, S., Lafourcade, P., & Mahmoud, D. (2024). A unified symbolic analysis of WireGuard. Proceedings of the Network and Distributed System Security Symposium (NDSS). https://doi.org/10.14722/ndss.2024.24364

Satyanarayanan, M. (2017). The emergence of edge computing. Computer, 50(1), 30–39. https://doi.org/10.1109/MC.2017.9

Shi, W., Cao, J., Zhang, Q., Li, Y., & Xu, L. (2016). Edge computing: Vision and challenges. IEEE Internet of Things Journal, 3(5), 637–646. https://doi.org/10.1109/JIOT.2016.2579198

Tailscale Inc. (2025). Tailscale documentation. https://tailscale.com/kb/

Varghese, B., Wang, N., Barbhuiya, S., Kilpatrick, P., & Nikolopoulos, D. S. (2016). Challenges and opportunities in edge computing. Proceedings of the IEEE International Conference on Smart Cloud, 20–26.

Yang, N., Chen, C., & Yuan, T. (2022). Security hardening solution for Docker container. 2022 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC), 44–49. https://doi.org/10.1109/cyberc55534.2022.00049

Yang, Q., Liu, Y., Chen, T., & Tong, Y. (2019). Federated machine learning: Concept and applications. ACM Transactions on Intelligent Systems and Technology, 10(2), Article 12. https://doi.org/10.1145/3298981

Downloads


Crossmark Updates

How to Cite

Akbari, F. (2026). Tailscale-Based Overlay Network Architecture for Proxmox VE. Sinkron : Jurnal Dan Penelitian Teknik Informatika, 10(3), 1832-1839. https://doi.org/10.33395/sinkron.v10i3.16296