WG by itself requires open ports at your edge firewall, while Tailscale (which is a layer on top of WG) will traverse NAT and Dynamic IPs. I set up Tailscale between two pfSense sites in 30 minutes. It’s works automagically!
Yes, 100 devices, up to 3 users. You can check their tiered pricing levels vs features.
Yes, from what I have read there will be a performance hit with Tailscale in it’s current implementation on pfSense.
You will have to weigh the ease of authenticating, configuring, maintaining, and compliance Tailscale offers vs a raw DIY WG implementation. Why not set it up in labs between the two sites and take it for a spin? Then compare to your results using OpenVPN
I deployed recently Headscale which is a self-hosted, open source alternative to the Tailscale coordination server. You can track my progress here. The cool thing is that NAT problems are almost solved automatically with Headscale/Tailscale. You might want to jump on my journey.
Check out Christian McDonald’s video which I have linked in my post.