I’m been doing some interesting testing with on-prem cnMaestro with multi remote site cambium migration.
Problem: On-Prem cnMaestro running either locally or on AWS, Azure etc and securely connect to multiple customer sites without dealing with firewall or ACL rules.
Test Solution: Tailscale VPN
- Local cnMaestro On-Prem
- Running on Proxmox VM
- Install Tailscale Client from the cnMaestro CLI
- ex: curl -fsSL https://tailscale.com/install.sh | sh && sudo tailscale up --auth-key=“yourkey”
*** In Tailscale, add a Linux server and generate an install script to paste into the CLI
- ex: curl -fsSL https://tailscale.com/install.sh | sh && sudo tailscale up --auth-key=“yourkey”
- Install Tailscale Client on remote customer Router
- In this case, I used NSE 3000 with 2.5-b2 version
- Turned on full GUI features
- Turned on Tailscale Remote access with appropriate tailscale key *** In Tailscale, add a Linux server and generate the script. You, however, only need the Key part for the NSE 3000
- Use the tailscale cnMaestro IP or URL address for the server address.
- Point your Cambium device cnMaestro URL to the new Tailscale cnMaestro IP or URL
- Push template, AP Group Override etc, or manual
- Onboard and then delete device from the Cloud.
I tested this for Tailscale which is a very easy deployment of Wireguard. It should work with any customer router that supports Tailscale. pfSense, OPNsense and a bunch more. Total time test setup was < 2 hrs.
It should also work with any Wireguard or for that matter, any other VPN deployment.
Comments?