Answers to the questions people actually ask, grouped the way people actually ask them.
Most "it doesn't work" tickets end at openvlan status. It prints your peers, whether each path is direct or relayed, and what the ACL engine did with your last connection attempt — the three facts that resolve the majority of issues below.
When an article doesn't solve it, the next rung depends on what's on fire. Production down and enterprise plan? That's a ticket, not a forum post. A weird NAT edge case at 2am? The forum has night owls on every timezone.
Each user can enroll up to 100 devices on every plan, including the free tier.
Yes. The mesh establishes connections through NAT without port-forwarding, and falls back through relays when direct paths are blocked. Café wifi, LTE, plane wifi — all workable.
A self-hosted coordinator is available on Enterprise agreements for teams with data-residency requirements.
None inbound. Outbound 443 for coordination is enough for connectivity; UDP 41641 improves direct-path success but is optional.
Run openvlan status on both. Check (1) both show "connected", (2) your ACLs allow this src→dst pair, (3) the service on the far side binds to the tailnet interface, not just localhost.
Make sure MagicDNS is enabled in the DNS settings and your OS is using the tailnet resolver. On Linux, set --accept-dns=true when running openvlan up.
openvlan status shows "direct" or "relayed". Relayed paths add latency — usually fixable by allowing UDP 41641 outbound on the relevant firewalls.
Enable the system service so it reconnects at boot: systemctl enable --now openvland.
No. Traffic is encrypted end-to-end between your devices with AmneziaWG; the coordination layer only distributes public keys and ACL decisions, never payload.
Private keys are generated and stored on each device only. They are never transmitted, not even to your tailnet's coordination server.
Disable the user in your identity provider (with SCIM) or from the admin console. Their sessions and keys stop working within seconds.
MFA is enforced by your identity provider during login. Because OpenVLAN authenticates against it, your IdP's MFA policy applies to network access automatically.
Your tailnet stays on; only paid features (SCIM, session recording, long audit retention) pause until you pick a plan.
Plans apply to the whole tailnet. For a mixed setup, keep a free personal tailnet and a separate team tailnet.
Admin console → Settings → Delete tailnet. Node metadata is purged within 30 days; device-held keys are destroyed immediately.