• ACLs and/or Firewall rules

    2
    0 Votes
    2 Posts
    532 Views
    S

    bump

    Nobody uses ACLs ?

  • 0 Votes
    2 Posts
    780 Views
    bthovenB

    @bthoven I found that using Virtual IP for my home.mydomain.com was the issue. Instead, using LAN interface IP (for my pfSense setup--> 192.168.1.1) has solved the problem.

  • Tailscale not found in available packages

    1
    0 Votes
    1 Posts
    358 Views
    No one has replied
  • Headscale on pfS?

    9
    1 Votes
    9 Posts
    2k Views
    rcfaR

    @chudak Yes, it's likely possible.

    But such "extra installs" won't be backed up with a configuration backup.

    So one must document and keep track of all the small manual changes and twists one makes to the system and redo everything from scratch when setting up a new box or when a hw failure forces one to restore from backup.
    So a supported HS-server module, which stores all relevant parameters in the configuration one backs up regularly, would significantly increase peace of mind...

    ...also, since the people writing pfSense are a lot more familiar with security related issues, whenever I modify the standard setup with tweaks, I run an increased risk of introducing security holes. Thus someone familiar with the full system architecture and security model is much less likely to make mistakes in that regard.

  • Tailscale and Snort

    3
    0 Votes
    3 Posts
    867 Views
    mooncaptainM

    @mooncaptain
    more urls to add to your pass list
    I found these are necessary after running snort for a while these url's started to get blocked.
    There may be more.

  • Subnet Routes - is it limited to two subnets?

    2
    0 Votes
    2 Posts
    311 Views
    johnpozJ

    @munson not sure what your routing too.. If the networks are directly attached to pfsense, routes would be there.

    If you have some downstream router, you could route however many routes you have that are downstream.. But if you have some other router on your network this should be connected to pfsense via transit network, or sometimes called a connector network.

    Here is how you would setup up routes to downstream networks.

    pfsense-layer-3-switch.png

    Not exactly sure what your trying to do, but if your routing to other networks over a network you have devices on, like your lan - your going to run into issues if devices on this lan network and any of your downstream networks talk to each other.. Unless your downstream network is being natted, or your portfowarding to get to them on the downstream router. or you have put host routing on the devices in your "transit" network with hosts on it.

  • Why do I need TS installed on pfsense router?

    33
    0 Votes
    33 Posts
    4k Views
    johnpozJ

    @michmoor said in Why do I need TS installed on pfsense router?:

    If i try to access my pfsense tailscale IP

    Exactly - which is what he was trying to do, use his tailscale IP.

  • TS is dead after reboot

    3
    0 Votes
    3 Posts
    480 Views
    johnpozJ

    @chudak I can't say I have noticed any such issue, but then again really the only time I ever reboot my pfsense is on an upgrade. Or an extended power outage where it lasts longer than my ups can keep pfsense up. But those are far and few between.

    I will make sure to take a look next time I reboot my pfsense.. but most likey that will not be until 24.03 comes out.

  • Talescale geolocation change?

    7
    0 Votes
    7 Posts
    3k Views
    K

    @jonsed Yes this works great! There even is a TS app for AppleTV so you can actually virtually be "at home" even when you travel abroad with your AppleTV and are dependent on potentially dodgy hotel or ABnB routers. I use it all the time using my pfsense as an exit-node.

  • As exit node, failed to access internet from time to time

    1
    0 Votes
    1 Posts
    377 Views
    No one has replied
  • Use other Tailscale exit nodes

    5
    1 Votes
    5 Posts
    3k Views
    N

    The only way I've been able to route pfsense to an exit node is to first create an interface bound to the tailscale service, add the tailscale IP address tied to your device as static, and add the exit node you want in the upstream gateway field. Then, head over to the System->Routing->Gateways settings and edit the new gateway. Disable gateway monitoring and gateway monitoring action. Lastly, go into your firewall rules for your LAN that you want going into the tailscale vpn and set the gateway for each rule to the new gateway. Your devices should be routing to the exit node now.

    This is not ideal, as your device IP could change at some point, but it's the only thing I got to work. I even tried pushing 0.0.0.0/1 and 128.0.0.0/1 as a subnet from the exit node to override the default route, and that worked at first, but as soon as the tailscale service itself needs to talk, it sends traffic within its own VPN and things fall apart.

  • PLEASE!! Cannot access WebGUI via Tailscale

    1
    0 Votes
    1 Posts
    408 Views
    No one has replied
  • Tailscale dashboard widget?

    3
    0 Votes
    3 Posts
    744 Views
    chudakC

    @mfld said in Tailscale dashboard widget?:

    /status_tailscale.php

    Maybe do some filtering? Or set limits, like e.g. show 5 nodes?

  • 0 Votes
    1 Posts
    664 Views
    No one has replied
  • Multicast via Tailnet

    1
    0 Votes
    1 Posts
    448 Views
    No one has replied
  • 1 Votes
    1 Posts
    370 Views
    No one has replied
  • Let Tailscale use other interface, not WAN

    2
    3 Votes
    2 Posts
    774 Views
    NeoDudeN

    Would love to figure this out too. When I was using Wireguard it was as simple as adding a Firewall rule, the "Tailscale" tab within the firewall section doesn't appear to work the same way unfortunately.

  • High CPU and temperature hit when key expires?

    2
    0 Votes
    2 Posts
    461 Views
    K

    @Klaus2314 I had another case today. My appliance as hot as a frying pan when I came in this morning and Tailscale was hung. Logs show the temp went up at 3AM to almost 100°C. 3AM is usually the time when my ISP does a short dis/reconnect. Any idea how to fix this other than disabling Tailscale?

  • Routing Tailscale Traffic via NordVPN Gateway

    1
    0 Votes
    1 Posts
    815 Views
    No one has replied
  • Can pfSense route to a Tailscale subnet without NAT?

    3
    0 Votes
    3 Posts
    2k Views
    C

    @jonsed, very sorry I can not help with this but I'm running into the exact same issue. I would also like to get to the Tailscale 100. addresses from machines behind my pfsense router, pfsense can get to them from a shell just fine but none of the edge clients.

    Good luck.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.