Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Tailscale & HAProxy

    Scheduled Pinned Locked Moved Tailscale
    1 Posts 1 Posters 314 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      TravisH
      last edited by

      Hi All,

      I use HAProxy to redirect to a range of https internal resources, this works really well at the moment through the WAN where I have source limits set up, and I can connect to the internal resources from limited external IP Addresses. Given I have tailscale I would like to basically be able to put custom dns entries in to point these hostnames to my pfsense tailscale IP4 address (100.89.148.118) but I am not having any luck getting this working.

      At the moment, I am just trying to connect to HAProxy using https://100.89.148.118 but it is getting blocked by the firewall.

      Sep 11 11:55:58 	tailscale0 	Default deny rule IPv4 (1000000103) 	100.89.148.10:53148		100.89.148.118:443		TCP:S
      

      I have tried with and without NAT redirecting internally to 127.0.0.1, and I also have rules set up to allow any traffic to and from my tailnets (defined in an alias) but I still keep getting these connections from my other tailscale machines being blocked on the pfsense machine. Can someone give me some pointers on what I am missing because I can see the requests are coming through to the pfsense machine, and in theory the rules should allow it through but I cant see why they don't. I do have tailscale ACL in place, but clearly that is not an issue as the requests are making it through to the firewall.

      0/0 B
         IPv4+6 TCP/UDP 	TailNets 	* 	TailNets 	* 	* 	none 	  	Allow across Tailnets 	
         	0/0 B
         IPv4+6 TCP/UDP 	* 	* 	* 	443 (HTTPS) 	* 	none 	  	Allow Tailscale IP4
      

      I also tried adding a EasyRule but because the tailscale0 interface doesn't exist in pfsense it throws an error and won't let me add that rule.

      Appreciate any help or tips,

      Cheers.

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.