In my country, residential fiber has CGNAT and no static IP. I run a small consultancy. One year ago I moved my entire operation—three VPS, home NAS, two client site routers—into a single ZeroTier mesh. Layer 2 over UDP. Worked beautifully for eleven months.
Cost: $0. Routing: direct when possible, relay via OVHcloud Hillsboro when symmetric NAT blocked. Latency to my Contabo VPS in Singapore: 34ms direct, 78ms relayed.
What failed: June 3, critical client presentation. ZeroTier root servers unreachable from my region for six hours. My mesh thought it was online. It was not. I had no out-of-band. Embarrassment: total.
Lesson: mesh VPN is not primary connectivity. It is convenience. In my country, we have saying: one rope is no rope.
I now keep a WireGuard tunnel to Hetzner Singapore as backup. Separate credentials, separate path. Test failover weekly.
Anyone else learned this hard way?