Tailscale-Based Overlay Network Architecture for Proxmox VE
DOI:
10.33395/sinkron.v10i3.16296Keywords:
Edge computing testbed; firewall hardening; overlay network; Proxmox VE; remote management; sovereign edge computing; TailscaleAbstract
Remote management of virtualized infrastructure introduces security risk when management services are exposed directly to the public internet. This risk is amplified when testbeds are intended to support sovereign edge computing workloads that require secure, isolated infrastructure. This study designs and evaluates a secure remote management architecture for a Proxmox VE node using a Tailscale overlay network and interface-specific firewall hardening, establishing a foundational infrastructure baseline for sovereign edge computing. The research follows Design Science Research supported by a network engineering evaluation procedure. The artefact was developed through problem identification, topology design, implementation, measurement, and evaluation. Data were collected from Tailscale status checks, Proxmox VE observation, ping latency testing, relay netcheck output, iptables verification, and external port scanning before and after firewall hardening. The Tailscale path achieved an average round-trip time of 0.434 milliseconds with zero packet loss, comparable to the public Internet Protocol path at 0.540 milliseconds with zero packet loss. Before hardening, public scanning detected management ports 22, 2222, and 8006. After applying interface-specific firewall rules, the external scan reported no open ports among the top 1000 ports, while private access to Proxmox VE through the Tailscale interface remained available. The proposed architecture demonstrates that overlay networking must be combined with firewall hardening to remove public management exposure without disrupting authorized remote administration. The result establishes a replicable foundational infrastructure baseline for sovereign edge computing, providing the first stage toward deployment of secure edge computing systems in resource-limited environments.
Downloads
References
Anyam, J., Singh, R. R., Larijani, H., & Philip, A. (2025). Empirical performance analysis of WireGuard vs. OpenVPN in cloud and virtualised environments under simulated network conditions. Computers, 14(8), 326. https://doi.org/10.3390/computers14080326
Bonawitz, K., et al. (2019). Towards federated learning at scale: System design. Proceedings of Machine Learning and Systems, 1, 374–388.
Deutschmann, J., Jahandar, S., Hielscher, K.-S., & German, R. (2023). Internet via satellite: GEO vs. LEO, OpenVPN vs. WireGuard, and CUBIC vs. BBR. Proceedings of the 1st ACM MobiCom Workshop on Satellite Networking and Computing. https://doi.org/10.1145/3614454.3622998
Donenfeld, J. A. (2017). WireGuard: Next generation kernel network tunnel. Proceedings of the Network and Distributed System Security Symposium (NDSS).
Kjorveziroski, V., Filiposka, S., Kocarev, L., & Prodan, R. (2025). Federated architecture for serverless platforms aimed at transparent execution in the edge-cloud continuum. International Journal of Cloud Computing, 14(2), 145–166. https://doi.org/10.1504/IJCC.2025.145664
Kondoj, M., Langi, H., & Putung, Y. (2022). Performance analysis of cloud computing based e-commerce server using Proxmox virtual environment. Proceedings of the 5th International Conference on Applied Science and Technology on Engineering Science (iCAST-ES). https://doi.org/10.5220/0011876000003575
Mackey, S., Mihov, I., Nosenko, A., Vega, F., & Cheng, Y. (2020). A performance comparison of WireGuard and OpenVPN. Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy, 162–164. https://doi.org/10.1145/3374664.3379532
Mell, P., & Grance, T. (2011). The NIST definition of cloud computing. National Institute of Standards and Technology, Special Publication 800-145.
Pepito, R., & Dutta, A. (2021). Open source 5G security testbed for edge computing. 2021 IEEE 4th 5G World Forum (5GWF). https://doi.org/10.1109/5GWF52925.2021.00075
Proxmox Server Solutions GmbH. (2025). Proxmox Virtual Environment documentation. https://pve.proxmox.com/pve-docs/
Qiao, Y., Xiong, J., & Zhao, Y. (2025). Network-aware container scheduling in edge computing. Cluster Computing, 28(3), 477–492. https://doi.org/10.1007/s10586-024-04733-8
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture. National Institute of Standards and Technology, Special Publication 800-207. https://doi.org/10.6028/NIST.SP.800-207
Ruhault, S., Lafourcade, P., & Mahmoud, D. (2024). A unified symbolic analysis of WireGuard. Proceedings of the Network and Distributed System Security Symposium (NDSS). https://doi.org/10.14722/ndss.2024.24364
Satyanarayanan, M. (2017). The emergence of edge computing. Computer, 50(1), 30–39. https://doi.org/10.1109/MC.2017.9
Shi, W., Cao, J., Zhang, Q., Li, Y., & Xu, L. (2016). Edge computing: Vision and challenges. IEEE Internet of Things Journal, 3(5), 637–646. https://doi.org/10.1109/JIOT.2016.2579198
Tailscale Inc. (2025). Tailscale documentation. https://tailscale.com/kb/
Varghese, B., Wang, N., Barbhuiya, S., Kilpatrick, P., & Nikolopoulos, D. S. (2016). Challenges and opportunities in edge computing. Proceedings of the IEEE International Conference on Smart Cloud, 20–26.
Yang, N., Chen, C., & Yuan, T. (2022). Security hardening solution for Docker container. 2022 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC), 44–49. https://doi.org/10.1109/cyberc55534.2022.00049
Yang, Q., Liu, Y., Chen, T., & Tong, Y. (2019). Federated machine learning: Concept and applications. ACM Transactions on Intelligent Systems and Technology, 10(2), Article 12. https://doi.org/10.1145/3298981
Downloads
How to Cite
Issue
Section
License
Copyright (c) 2026 Fiqih Akbari

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.






















Moraref
PKP Index
Indonesia OneSearch
OCLC Worldcat
Index Copernicus
Scilit
