Shaping a Tailscale client's IP traffic
-
Hello
I have Tailscale installed on my 2100 and it works very well.
I publish 1 route to an internal server for clients.The internal server does NOT have Tailscale installed on it. I rely on the route being in place.
I have also seen that all traffic from these Tailscale clients, to this internal server, appears to come from the router(PfSense's) ip address. This is expected.My question is :
How do I limit/shape traffic for a tailscale client ?I thought of using limiters and the 100.x.x.x Tailscale IP address that the client has but the 100.x.x.x IP is not "visible/available" to be processed by the firewall. I assume this is because of the src ip being the router (above).
Any advice ?
I hope my question makes sense.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.