I spent the last few hours trying to setup a new ZeroTier net and it seems they have taken a few steps backwards in sub-net routing with FreeBSD/OPNSense. The new portal doesn't even expose the options for subnet routing with FreeBSD nodes. CoPilot had me hacking the ZeroTier local.conf to advertise the subnets / routes but I couldn't get any of that to allow packets across the OPNSense instances. The new portal doesn't seem to allow you to get an API token for the ZeroTier config panel so I couldn't use that. I did notice that on the public side I wasn't playing the IP address lottery so ZeroTier's keep awake signalling must have improved somewhere along the way.
Feels like TailScale with a standalone Linux VM doing subnet routing as the only option left that seems viable.
Feels like TailScale with a standalone Linux VM doing subnet routing as the only option left that seems viable.
"