iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Yes, Linux can use Tailscale, WireGuard, and network namespaces as building blocks for selective routing, but their documented features do not amount to a ready-made, end-to-end recipe for combining them. Decide which traffic belongs on Tailscale, which belongs on WireGuard, and which should use the ordinary network; then design and validate the routes, namespace boundaries, permissions, DNS behavior, and failure handling for your particular setup.
Decide which traffic should use each path
“Split tunneling” can mean different things. Before configuring anything, define traffic by destination or by the process that generates it. Those are different routing policies, and the tools involved do not automatically combine them.
- Tailscale: traffic to tailnet devices, and possibly internet traffic sent through a selected exit node.
- WireGuard: traffic assigned to a WireGuard interface or routing policy. Linux namespaces can help isolate the routes and processes that use that interface.
- Ordinary network: traffic that should continue through the host’s usual network connection.
Write down the intended destinations or processes for each class, including DNS requests and IPv4 and IPv6 traffic. Also decide whether local-network devices should remain reachable. Without these decisions, a “split tunnel” description is too vague to translate safely into routes.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteUnderstand what an exit node does—and does not do
A Tailscale exit node is a tailnet device through which another tailnet device can route internet traffic. On Linux, setting one up requires enabling IPv4 and IPv6 forwarding, advertising the device with tailscale set --advertise-exit-node, and having an administrator approve it in the admin console. A client must then select the exit node. See Tailscale’s Linux exit-node setup and exit-node overview.
#1 Best Overall
- 12th Intel Alder Lake N95 Processor – The GMKtec G3 S Mini PC is powered by the 12th Gen Intel N95 processor with 4 cores, 4 threads, 6MB cache and a burst frequency up to 3.4GHz. Compared with N100/N5105/N5100/N5095, the N95 delivers up to 36% overall performance improvement. Perfect for routine tasks, office work, and home entertainment, this compact mini desktop is more convenient than traditional bulky PCs.
- 8GB RAM & 256GB SSD Storage – Pre-installed with 8GB DDR4 memory and a fast 256GB M.2 2242 SSD, the G3 S mini desktop offers quicker startup, smoother multitasking, and faster file transfers. Enjoy seamless performance whether you’re working on multiple applications, browsing, or streaming content.
- Rich Interfaces & Connectivity – The G3 S mini computer comes equipped with USB 3.2 (up to 10Gbps), dual HDMI 2.0 (4K@60Hz), and a 3.5mm audio jack. With support for WiFi 5, Bluetooth 5.0, and Gigabit Ethernet (RJ45 1000MbE), it connects easily with monitors, projectors, printers, office equipment, and other peripherals, making it versatile for both home and business use.
- Dual 4K Display Support – Featuring upgraded Intel UHD Graphics (up to 1000MHz), the G3 S supports 4K video playback and AV1 decoding for a smooth viewing experience. With dual HDMI outputs, you can connect two 4K@60Hz displays simultaneously, enabling efficient multitasking for work and entertainment.
- GMKtec WARRANTY - GMKtec offers a 1-year limited GMKtec's warranty for each mini PC, starting from the date of the purchase. All defects due to design and workmanship are covered. With a professional after sales team always ready to attend to your needs, you can simply relax and enjoy your mini PC.
By default, an exit node captures non-Tailscale traffic, except traffic already directed to a subnet router or app connector. Tailscale documents an option to allow access to the local network while an exit node is in use; local-network access is otherwise disabled by default. Its overview identifies app-based split tunneling on Android, but does not document an equivalent integrated per-application Linux control for the combined Tailscale, WireGuard, and namespace arrangement described here.
Exit-node routing is also distinct from permission to use it. A customized tailnet policy may need a grant or ACL permitting autogroup:internet. Permission to connect to the exit-node device itself does not, by itself, grant permission to route internet traffic through it.
Rank #2
- 【Powerful AMD Core Running Performance】Adopt AMD Ryzen 5 7430U processor with 6 cores 12 threads, clock speed reach up to 4.3GHz. This mini computer delivers steady running performance to match daily office operation, daily home entertainment and light gaming usage demands, stable output without frequent stutter, fit for long time daily use.
- 【Smooth 4K Multi-screen Display Output】Built-in AMD Radeon graphics card with 1800MHz working frequency, this mini gaming pc supports 4K 60Hz video output. Equipped with HDMI, DP 1.2 and Type-C three display interfaces, users can freely combine connection ways to realize triple screen linkage, convenient for multi-task work split screen operation and high-definition video playback, improve daily operation efficiency effectively.
- 【Rich Interfaces & Stable Dual LAN Transmission】This mini pc comes with complete daily mainstream ports, including multiple USB 3.2/USB2.0 ports, audio jack, DC power port and other common interfaces. Equipped with 2.5G dual RJ45 wired network port, support fast and stable data transmission, can stably connect with monitor, projector, office equipment and household audio-visual devices, meet diversified external connection needs.
- 【Dual High-speed Wireless Connection Mode】Equipped with WiFi6 wireless network module and upgraded Bluetooth 5.3 version on this micro pc. WiFi6 brings faster network access speed and smoother network signal transmission; Bluetooth 5.3 realizes low-delay stable connection with wireless keyboard, mouse, headset, printer and other peripheral devices, optimize daily wireless using experience.
- 【Large Expandable Memory & Reliable Heat Dissipation】Configured with 16GB 3200MHz DDR4 RAM and 512GB built-in SSD, users can expand memory up to 64GB and solid state storage up to 4TB through reserved expansion slots. Compact body structure adopts aluminum alloy shell and honeycomb heat dissipation holes, speed up internal air circulation, lower operating temperature, maintain long-term stable operation and extend service life.
Separate destination routing, access policy, and namespace placement
These mechanisms answer different questions. A route determines which IP destinations are sent through an interface; a tailnet grant or ACL determines whether a connection is allowed. Both route selection and permission must allow traffic for the connection to succeed. Tailscale explains this distinction in its route-injection reference.
Recommended Free Tools
Linux network namespaces provide separate network stacks and routing tables, among other isolated resources. They can help keep a process or set of routes separate from the host’s normal networking. WireGuard’s documentation explains that, like other Linux network interfaces, WireGuard integrates with network namespaces. It gives an example pattern in which the physical interface is placed in a physical namespace while WireGuard remains in the initial namespace. That demonstrates a WireGuard capability; it is not a Tailscale configuration recipe. See WireGuard’s Routing & Network Namespaces documentation and the Linux network_namespaces(7) manual.
Rank #3
- 【AMD Ryzen 3 5300U CPU: Outperforms N150 & 3500U】 BOSGAME E5 mini PC is powered by the TSMC 7nm FinFET architecture AMD Ryzen 3 5300U processor (4 Cores, 8 Threads, up to 3.8GHz boost, 6MB total cache). Compared to low-end Intel N150 or 3500U chips which only have 4 single threads and throttle under load, the 5300U delivers over 30% faster multi-core speed. Run 30+ browser tabs, large Excel sheets, and Zoom meetings simultaneously without system lag.
- 【8GB DDR4 RAM & 256GB NVMe SSD Storage】 Installed with high-speed 8GB DDR4 dual-channel memory and a fast 256GB M.2 2280 SSD, eliminating slow boot times and application loading delays. To accommodate growing data requirements, the upgradeable hardware design features dual SODIMM slots that allow you to expand memory up to 64GB RAM, ensuring smooth operation during heavy multitasking.
- 【High-Capacity Dual M.2 SSD Storage Expansion】 Never worry about running out of space for your business files. In addition to the pre-installed 256GB system drive, the motherboard houses an extra empty internal M.2 2280 NVMe PCIe 3.0 slot. This allows you to easily add a second solid-state drive for up to an additional 2TB of storage capacity (upgrades not included) without needing to remove or reinstall the original operating system.
- 【Radeon 6-Core Graphics & Triple 4K Displays】 Integrated with official AMD Radeon Graphics (6 Graphics Cores, 1500 MHz frequency) for casual gaming, photo editing, and crisp 4K media decoding. Featuring 1x HDMI 2.0 port, 1x DisplayPort, and 1x Full-Function Type-C port, the E5 outputs true 4K@60Hz resolution to three monitors at once. This multi-screen setup eliminates constant window-switching for traders, programmers, and office workers.
- 【Dual 2.5GbE LAN Ports for Advanced Networking】 Experience fast wired network transmission speeds up to 2500Mbps without lagging or buffering. The integration of dual 2.5 Gigabit Ethernet ports (powered by Realtek RTL8125 controller) makes this compact computer an exceptional hardware choice for tech enthusiasts. Easily configure it into software routers, hardware firewalls (pfSense, OpnSense), home NAS servers, or local homelabs.
For a combined setup, the operator must establish which namespace owns each interface and how packets are supposed to cross between namespaces. The sources do not verify a particular forwarding topology among a host, Tailscale, and WireGuard, so there is no safe universal diagram or command sequence to apply without adapting and testing it for the target system.
Choose an approach by the traffic you need to select
| Approach | Traffic scope | Where selection happens | What to account for |
|---|---|---|---|
| Tailscale exit node | By default, non-Tailscale internet traffic from a client, with exceptions for traffic already directed to a subnet router or app connector. | Exit-node advertisement and approval, then client selection. | Tailnet permission for internet routing, local-network access, and the default broad scope. Sources: Tailscale exit-node overview and Linux setup. |
| Tailscale subnet router or app connector | Selected network destinations, rather than the exit node’s default handling of non-Tailscale internet traffic. | Tailnet route selection for the applicable destinations. | Do not treat destination-specific routing as integrated per-process WireGuard split tunneling. Source: Tailscale exit-node overview. |
| WireGuard with namespace separation | Traffic associated with the routes and processes arranged for that namespace design. | Linux namespace placement and routing policy. | Interface ownership and packet forwarding must be designed for the actual topology. WireGuard documents namespace integration, not a combined Tailscale recipe. Source: WireGuard Routing & Network Namespaces. |
The wg-quick manual describes policy-routing controls including Table, PostUp, and PreDown. These are available configuration mechanisms, not evidence that a particular policy will coexist safely with Tailscale’s routes. Review the wg-quick(8) manual alongside the routing behavior of your actual system.
Rank #4
- 【Powerful & Efficient Performance】Powered by the Intel Celeron J3355 Processor (up to 2.5GHz), this Mini PC delivers a 25% performance boost over previous generations. Pre-installed with Windows 11 Home and supporting Linux/Ubuntu, it’s the ideal micro desktop for seamless web browsing, document editing, and efficient daily office tasks.
- 【Massive Storage & Unique Expansion】Equipped with 6GB LPDDR3 RAM and 128GB onboard storage for fast boot-ups. Stand out with our dual M.2 SSD slot design (1x SATA + 1x NVMe), allowing you to easily expand storage up to 2TB without replacing the original drive. Perfect for managing large digital libraries and intensive multitasking.
- 【Stunning 4K Dual HDMI Display】Boost your productivity with Intel HD Graphics 500 and dual HDMI ports, supporting 4K @60Hz high-definition visuals. Connect two monitors simultaneously to streamline your workflow—ideal for home office setups, stock trading, or enjoying a theater-like 4K media experience.
- 【Ultra-Compact & Space-Saving Design】Measuring only 4.2x4.1x1.4 inches and weighing just 0.49 lbs, this palm-sized mini computer fits anywhere. Use the included VESA bracket to mount it behind your monitor for a zero-clutter workspace. Features a smart silent fan and heat sink system for quiet, reliable 24/7 operation.
- 【Stable Connectivity & Smart Recovery】Stay connected with Dual-Band WiFi (2.4G/5G), Bluetooth 5.0, and Gigabit Ethernet. Exclusive One-Click Restore feature (via F9 key) allows for quick system recovery in minutes. Backed by Bmax's 12-month warranty and lifetime technical support for a worry-free purchase.
Build and validate a design without assuming the tunnels cooperate
- Document the traffic policy. List the destinations or processes assigned to Tailscale, WireGuard, and the ordinary connection. Include DNS, IPv4, IPv6, and local-LAN needs.
- Choose where each decision belongs. Identify whether selection is made by the Tailscale client, host routing, or a namespace. Keep route selection separate from tailnet authorization.
- Set up and approve the exit node if needed. Follow Tailscale’s Linux setup for forwarding, advertisement, and administrator approval; select the exit node on the client that should use it.
- Map namespace ownership and forwarding. For every interface and relevant process, record its namespace and intended packet path. Do not assume that moving or isolating a WireGuard interface automatically makes Tailscale traffic traverse it.
- Inspect the effective routes and permissions. Check the routing state in each relevant namespace and confirm that tailnet policy allows the intended connections. A permitted connection can still fail if its route is wrong, and a route alone does not override policy.
- Test each traffic class independently. Confirm the externally visible IP for traffic meant to use the exit node, as Tailscale recommends, and verify the expected path for traffic assigned to WireGuard or the ordinary network. Treat these as checks to perform, not as results established here.
- Test failure and edge cases before relying on the setup. Check behavior when either tunnel or its endpoint is unavailable, whether traffic falls back outside the intended path, DNS resolution, IPv4 and IPv6 separately, and local-network reachability. The outcome depends on the configuration and must be verified on the target host.
What is established—and what must be tested locally
The documented components support exit-node routing, WireGuard’s integration with Linux network namespaces, and route-policy controls. They do not establish a best combined architecture, a universal command sequence, or measured performance, security, or failover results for this specific arrangement. Distribution, Tailscale version, WireGuard tooling, firewall backend, policy, and namespace layout can all affect behavior.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
A dedicated Linux device is not required by the documented exit-node setup; any Linux host that meets the relevant setup requirements may be used. The important requirement for a selective-routing design is not special hardware, but a clearly specified and tested packet path for every traffic class.
Quick Recap
Best Value
- WHY CHOOSE G3 ULTRA MINI PC PENTIUM GOLD 7505 - Choose the Intel Pentium Gold 7505 for snappier everyday responsiveness: It delivers up to 30% faster single-core performance than the Ryzen 5 3500U, making office apps and web browsing feel noticeably quicker, while its Intel UHD Graphics (48 EUs) provides 2.4x the GPU performance of the N100 & N150's 24-EU graphics, ensuring smoother 4K streaming and light photo editing.
- 16GB RAM MEMORY & 512GB STORAGE - GMKtec Nucbox G3 Ultra mini computer is prebuilt with 16GB LPDDR4 RAM at 3200 MT/s, you will enjoy a speedier experience with Built-in 512GB M.2 SATA Hard Drive. Our mini desktop pc boots up in seconds, work on multiple browser tabs, software applications and quickly transfers files. There is a primary slot and secondary expansion storage. Primary slot is M.2 2280 PCIE and secondary slot is M.2 2280 SATA.
- RICH INTERFACE - Nucbox pentium mini computer is equipped with 3* USB 3.2 Gen2 ports, up to 10Gbps/S, 1*USB 2.0, HDMI(4K@60Hz)*2, 3.5mm Audio Jack. Supports WiFi 6, and Gigabit Ethernet RJ45 2.5GbE network connectivity, Bluetooth 5.2. This Mini PC supports multiple device connection and can be used with servers, monitoring equipment, office equipment, displays, projectors, televisions, etc.
- 4K DUAL SCREEN DISPLAY - Mini desktop computer is equipped with upgraded Intel Graphics(max 1000MHz), supports 4K video playback and AV1 decoding, connect the pc with a projector as a home theatre, enjoy a variety of entertainments. Two HDMI 2.0 ports allows you to multi-task efficiently on two 4K@60Hz displays.
- UPGRADED COOLING FAN - The G3 Ultra has upgraded the cooling fan to reduce fan noise and thermals. We are using an upgraded thermal paste as well to help reduce heat on the CPU.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

