ZSoftly Cloud Platform
Professional Services

Zero Trust VPN with Headscale

Retire the VPN concentrator and the per-user ZTNA bill. A WireGuard mesh your team controls, with the coordination server on your infrastructure.

Overview

Remote access today is either an aging VPN concentrator with a renewal quote and a CVE history, or a zero trust SaaS priced per user per month. Both put a third party between your people and your network: one as a choke point, the other as a control plane you cannot inspect.

Headscale is an open-source, self-hosted implementation of the control server behind the Tailscale WireGuard mesh. Devices connect directly to each other with modern encryption, users keep the familiar official Tailscale apps, and the server deciding who reaches what runs on ZCP in Canada or inside your own environment. ZSoftly designs, implements, and operates it.

What this service covers

  • Cost and risk assessment against your current appliance or ZTNA spend
  • Headscale deployment on ZCP or your infrastructure, with self-hosted relays
  • Migration from legacy VPN concentrators or per-user subscriptions
  • SSO and MFA integration, including self-hosted Authentik
  • Access policies, audit logging, and managed operations
$0
Per-User License Fees
flat infrastructure cost
Direct
Device-to-Device Traffic
no concentrator backhaul
Yours
Network Metadata
no third-party control plane
WireGuard
Modern Encryption
on every connection

Sound Familiar?

The remote-access problems that end up on a CISO or CTO desk.

Appliance Renewal Season

The concentrator quote arrived: hardware refresh, per-seat licenses, and support. And it is still the single box every remote packet hairpins through.

VPN CVE in the News

Another emergency patch for an edge appliance. The VPN is your front door, and its CVE history keeps landing on your risk register.

ZTNA Pricing That Scales Wrong

The zero trust SaaS solved access, but the per-user bill grows with every hire and contractor, and your network map lives in a console you do not control.

The Business Case

What changes for your budget, your privacy posture, and your attack surface.

Cost Reduction

One flat infrastructure cost replaces appliance refreshes, per-seat VPN licenses, and per-user ZTNA subscriptions. Contractors, service accounts, and CI runners stop being line items.

Privacy and Sovereignty

The control plane holding your device inventory, users, access rules, and connection logs runs where you decide. No vendor sees your network topology, and residency requirements are met by design.

Smaller Attack Surface

No internet-facing concentrator to exploit. Devices authenticate through your SSO with MFA, connect peer to peer over WireGuard, and reach only what policy allows: least privilege instead of full network access.

How the Options Compare

The three ways to deliver remote access, weighed the way a budget owner weighs them.

What you are weighing Legacy VPN appliance ZTNA SaaS (Tailscale, Twingate, Cloudflare) Self-hosted Headscale
Cost model Hardware refresh plus per-seat licenses Per user, per month, growing with headcount Flat infrastructure cost, no per-user fees
Traffic path Everything hairpins through one box Mesh or vendor edge, depending on product Direct device-to-device WireGuard mesh
Who holds your network map You The vendor control plane You
Access granularity Full network once connected Per-app or per-resource policies Per-resource ACLs tied to SSO identity
Exposed attack surface Internet-facing appliance with a CVE history Vendor-operated edge No inbound ports on user devices; one control server you patch on your schedule
Data residency On premise Vendor jurisdiction Your jurisdiction, on ZCP in Canada or your own site
User experience Connect, wait, disconnect Always-on client apps The same official Tailscale apps, always on

Headscale is the open-source implementation of the Tailscale coordination server and works with the official Tailscale client apps. Tailscale Inc. does not sell support for it; ZSoftly provides the implementation and operations.

Where Headscale Fits, and Where It Does Not

The same honest scope line we draw on every platform recommendation. We tell you which tool wins before you commit.

Headscale can replace

  • Legacy VPN concentrators for workforce remote access
  • Per-user ZTNA and mesh VPN subscriptions
  • Site-to-site tunnels between offices, clouds, and data centers
  • Jump hosts and bastion VPNs for engineering access
  • Per-seat licensing for contractors and service accounts

Keep a dedicated tool for

  • Managed SaaS with a vendor SLA and zero operations (Tailscale)
  • Full SASE requirements such as web filtering and CASB
  • Carrier-grade site-to-site routing at BGP scale
  • Tailscale-only extras such as Funnel public sharing

How the Engagement Runs

The old VPN stays up as a fallback until the last wave lands. No cliff-edge cutover.

1

Assess

Phase 1

We map remote access as it stands: appliances, licenses, and who connects to what. You get a cost and risk comparison against the renewal you are trying to avoid.

2

Pilot

Phase 2

Headscale deploys alongside the current VPN. A pilot group connects with the standard Tailscale apps through your SSO. Nothing cuts over yet.

3

Migrate

Phase 3

Teams and sites move in waves, with access policies applied as they land. The old VPN stays as fallback until the final wave, then retires.

4

Operate

Ongoing

We patch, monitor, and support the mesh, or hand your team the runbooks. Access reviews come from the policy file, not a spreadsheet.

Questions Your Board Will Ask

Is Headscale production-ready?

Headscale is mature open source under active development, used in production by teams that want a self-hosted control plane, and it speaks the same protocol as the official Tailscale apps your users install. ZSoftly hardens the deployment, keeps it patched, and stands behind it operationally.

How is this different from buying Tailscale?

Same client apps, same WireGuard mesh. The difference is where the control plane lives and how it is billed. Tailscale runs it as SaaS priced per user; Headscale runs on your infrastructure at a flat cost, and your device inventory, access rules, and connection logs never leave it.

What do employees experience?

They install the standard Tailscale app, sign in through your SSO with MFA, and their tools work. No connect button, no split-tunnel tickets, and access follows their role.

What happens if the control server goes down?

Existing connections keep working; devices talk directly to each other and cached policies stay enforced. New device sign-ins wait until it returns. We deploy with backups, monitoring, and a documented recovery path sized to your tolerance.

Can it use our existing identity provider?

Yes. Headscale delegates login to any OIDC provider, so access rides on your existing SSO and MFA. Pair it with self-hosted Authentik and the whole access stack, identity and network, runs on infrastructure you own.

Put a Number on Retiring Your VPN

Bring your appliance renewal or ZTNA invoice. The assessment shows the flat-cost alternative and the migration path.