Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Tailscale not online

    Scheduled Pinned Locked Moved Tailscale
    14 Posts 5 Posters 2.4k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mcury Rebel Alliance @IanMcLeish
      last edited by mcury

      @IanMcLeish said in Tailscale not online:

      Can you get your's back online though?

      I have uninstalled everything and reinstalled. Deleted the instance in the Tailscale admin page and made a new key. But I am still offline and no further forward.

      Yeap, you need to delete the device in the tailnet, generate a new key, paste it to pfsense and save.
      This alone will make it go online again.

      Then, check the tailnet IP your device got and changed the virtual IP for the NAT to match it.
      Accept the advertised routes if any, and that is it.

      Did you have any joy with the --unattended option?

      I didn't do anything yet besides of reporting the problem.

      dead on arrival, nowhere to be found.

      I 1 Reply Last reply Reply Quote 0
      • I Offline
        IanMcLeish @mcury
        last edited by IanMcLeish

        @mcury said in Tailscale not online:

        @IanMcLeish said in Tailscale not online:

        Can you get your's back online though?

        I have uninstalled everything and reinstalled. Deleted the instance in the Tailscale admin page and made a new key. But I am still offline and no further forward.

        Yeap, you need to delete the device in the tailnet, generate a new key, paste it to pfsense and save.
        This alone will make it go online again.

        Then, check the tailnet IP your device got and changed the virtual IP for the NAT to match it.
        Accept the advertised routes if any, and that is it.

        Did you have any joy with the --unattended option?

        I didn't do anything yet besides of reporting the problem.

        Aargh.

        This is not working for me, it isn't going online again!

        Ill try removing the packages again and starting over - i would rather not remove the entire pfsense and start again!! I was following Tom Lawrence's Youtube video. it worked for me before.

        M 1 Reply Last reply Reply Quote 0
        • M Offline
          mcury Rebel Alliance @IanMcLeish
          last edited by mcury

          @IanMcLeish said in Tailscale not online:

          Ill try removing the packages again and starting over - i would rather not remove the entire pfsense and start again!!

          Did you generate a new key ?
          Go to the tailnet, click add device, choose linux server, set the expiry to 90 days and click generate install script.
          Then, you will see a code being generated at the bottom of the page, copy from the tskey onwards and paste in pfsense tailscale authentication tab.
          After that, just follow the instructions in my last post.

          dead on arrival, nowhere to be found.

          I 1 Reply Last reply Reply Quote 0
          • I Offline
            IanMcLeish @mcury
            last edited by

            @mcury

            I was generating a key in the tailscail admin domain. I did try your method as well, but still no luck.
            Thanks for your help.

            I wonder what went wrong on Feb 3 to cause this?

            I tried restoring an older backup as well from before Feb 3 and that too made not a jot of a difference.

            I think I will give up.

            Personally, I know a router can be complicated, as networks and firewall are complicated, but tailscale is so simple on most every product, except this one.

            M 1 Reply Last reply Reply Quote 0
            • M Offline
              mcury Rebel Alliance @IanMcLeish
              last edited by

              @IanMcLeish said in Tailscale not online:

              I think I will give up.

              Weird, those exactly steps worked for me yesterday..

              dead on arrival, nowhere to be found.

              I 1 Reply Last reply Reply Quote 0
              • I Offline
                IanMcLeish @mcury
                last edited by

                @mcury
                I got it!

                I had to go to the command prompt and run the command tailscale up which then gave me a link to the tailscale web admin page to authenticate. I kinda thought that the whole point of the key was to avoid that, but it is back up and running anyway.

                Thanks for your help - was nice at least to know i wasn't doing anything stupid, but maybe missing that last part was me doing something stupid!?

                M 1 Reply Last reply Reply Quote 1
                • M Offline
                  mcury Rebel Alliance @IanMcLeish
                  last edited by

                  @IanMcLeish said in Tailscale not online:

                  I got it!

                  great 👍

                  dead on arrival, nowhere to be found.

                  1 Reply Last reply Reply Quote 0
                  • T Offline
                    totalimpact
                    last edited by totalimpact

                    This still seems to be an issue, and makes the Tailscale client unreliable. I have 4 nodes down now with expiry disabled, after some unknown time, and then a router reboot they can no longer authenticate.

                    Error executing command (/usr/local/bin/tailscale status)
                    # Health check:
                    #     - not logged in, last login error=invalid key: API key does not exist
                    
                    unexpected state: NoState
                    

                    From the CLI I can run tailscale login, and it re-authenticates the same node, I can tailscale down + up and it connects fine, status on the webpage looks good, but if I reboot or restart the Tailscale service in the webpage it can no longer connect again with the same error needing to login again. The only way to make it work reliably is to clear the config, delete the node and reconnect as a new node.

                    Pfsense 2.7.2, Tailscale package 0.1.4

                    E 1 Reply Last reply Reply Quote 0
                    • E Offline
                      elvisimprsntr @totalimpact
                      last edited by elvisimprsntr

                      @totalimpact

                      Tailscale 1.54.0 is 2+ years out of date. Tailscale has made quite a number of changes since Tailscale 1.54.0, likely rendering it incompatible with their servers.

                      I would consider manually updating the Tailscale FreeBSD package.

                      FreshPorts does not maintain an archive of all the releases, only the latest compiled by the volunteer maintainers.

                      The key to manually upgrading is knowing which FreeBSD version your pfSense release is running, i.e. 14 or 15.

                      You can following along here.

                      1 Reply Last reply Reply Quote 0
                      • ryan.goodfellowR Offline
                        ryan.goodfellow
                        last edited by

                        Upgraded 25.07 and Tailscale is broken in the way users here describe. I can manually log in using sudo /usr/local/bin/tailscale login, but the tailscale service in pfSense does not pick this up and restarting the service clobbers the login state. Given 16004 was logged 7 months ago with zero activity, this is an indication that Netgate devices no longer support Tailscale.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.