I feel like this might be a long shot but wanted to see if anyone else was running the tailscale plugin for Opnsense. I have everything set up when my opnsense acts as an exit node. The clients connect up to the exit node just fine but I wanted to redirect traffic to a different gateway instead of my ISP gateway. I tried setting up tailscale net as the source on the tailscale interface to route traffic to a specific gateway but it doesn’t seem to work. It seems like tailscale ignores all of opnsense firewall rules which is a lot different than what I am use to working with the wireguard interface on opnsense.

  • @BobsAccountant
    link
    English
    12 days ago

    You said you added the Tailscale network, but how wide did you go? By default when you load the plugin and activate the interface, it just gives its own IP as the network (/32). If you added that, then only traffic with that specific origin will hit your route. It’s crazy, but for my firewall rules (not routing) to work, I had to define the network as a 100.0.0.0/8, which is gigantic. You may have to do that with the route as you can’t otherwise set the gateway on the interface as it’s not hosting the DHCP server.