<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Tailscale subnet routes, exit nodes &amp; pfSense firewall rules]]></title><description><![CDATA[<p dir="auto">Figured out what's going on with respects to [pfSense hosted] Tailscale subnet routes &amp; exit nodes along with pfSense firewall rule behaviour:</p>
<p dir="auto">EG: Firewall/Rules/Tailscale:</p>
<ol>
<li>
<p dir="auto">Subnet Routes <em>are not subject</em> to pfSense Tailscale interface rules whatsoever - While subnet routes can use /32 cidr host scope TailScale ACLs would respectively be necessary for filtering to source, protocol, port, etc</p>
</li>
<li>
<p dir="auto">Exit node traffic <em>is subject</em> to pfSense Tailscale interface rules</p>
</li>
<li>
<p dir="auto">Exit node traffic destined to approved subnet routes will bypass pfSense Tailscale interface rules (as per #1)..</p>
</li>
<li>
<p dir="auto">Interesting one: Exit node traffic destined to <em>unapproved subnet routes</em> will bypass pfSense Tailscale interface rules (this one threw me off for the past 24 hours)<br />
EG: in an exit node scenario all approved <em>and unapproved</em> subnet routes essentially become overlapping, rules bypass/overrides</p>
</li>
<li>
<p dir="auto">The auto-generated network group/object "Tailscale networks" is unusable at this time resulting in errors. As all Tailscale traffic originates from the pfSense interface(s) using SNAT I don't see anything other than Tailscale ACLs for source-based policies but I'm curious as to what the future plans are for this group/object.</p>
</li>
</ol>
<p dir="auto">PfSense 2.7.2 (RELEASE)<br />
TailScale 0.1.4 (Package)</p>
<p dir="auto">Hope this helps,<br />
Josh</p>
]]></description><link>https://forum.netgate.com/topic/190879/tailscale-subnet-routes-exit-nodes-pfsense-firewall-rules</link><generator>RSS for Node</generator><lastBuildDate>Fri, 06 Mar 2026 06:21:19 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/190879.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 10 Nov 2024 13:12:08 GMT</pubDate><ttl>60</ttl></channel></rss>