Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Using pfSense as Tailscale exit node only partially works

    Tailscale
    2
    6
    1.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JPedroT
      last edited by

      When setting my tailscale client to use the pfSense at a remote location as the exit node. Some websites works others do not, I am not sure why, any ideas or is it a known issue?

      Sites that work:
      facebook.com
      slashdot.org

      Sites that do not work:
      test-ipv6.com
      netgate.com

      The error starts of with site unexpected closed connection and then ends up with connection was reset according the browser error page.

      I tested with Brave and Google Chrome

      1 Reply Last reply Reply Quote 0
      • J
        JPedroT
        last edited by

        Did some more tests and it works fine with Firefox and Safari, which is weird.
        I disabled extensions in Chrome and it still did not work, anybody got any ideas?

        M 1 Reply Last reply Reply Quote 0
        • M
          mhache @JPedroT
          last edited by mhache

          @jpedrot Chrome based browsers had a change a while back that break Tailscale exit nodes if the exit node does not have IPv6 support. This is why it works with Safari and Firefox. IPv4 only website works but IPv6 supported website doesn't has Chrome based browsers tries first to connect with IPv6. As the Exit node does not have IPv6, the request get dropped. (Short explanation)

          https://redmine.pfsense.org/issues/13489

          Looks like there are no fix from Netgate at this point. 1.30 fixed the issue but the version for pfSense is still 1.26.2.

          J 1 Reply Last reply Reply Quote 2
          • J
            JPedroT @mhache
            last edited by

            Thanks @mhache, then I have temp workaround until pfSense updates its Tailscale package.

            M 1 Reply Last reply Reply Quote 0
            • M
              mhache @JPedroT
              last edited by

              @jpedrot You can try this:
              https://www.reddit.com/r/PFSENSE/comments/yw82cq/guide_manually_install_a_newer_version_of/

              J 1 Reply Last reply Reply Quote 1
              • J
                JPedroT @mhache
                last edited by

                @mhache I am lazy, so I will wait for Netgate to update the package. I just enabled IPv6 for the WAN interface and that worked like a charm.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.