OPNsense Forum

English Forums => Virtual private networks => Topic started by: Kieeps on July 23, 2022, 12:21:05 pm

Title: Tailscale site-to-site setup
Post by: Kieeps on July 23, 2022, 12:21:05 pm
I'w reacently started looking in to Tailscale, it solves most of the problems i had with wireguard and i'd like to try it as my site-to-site solution, i understand that it's using wireguard-go and it will perform a bit worse then the kmod we have all gotten used to by now (it's not default but seems to be very common anyway)

I'w currently installed Tailscale from mimugmail''s repo and got it working fine by using the tailscale IP to reach the remote site, but whenever i try to add subnet routing i get stuck...
Subnets are properly advertised on both sites but i cant figure out how to route the corresponding subnet to the right interface.

I understand that it's not possible to route traffic to a specific interface, but setting up a gateway for that interface and route traffic to that gateway should work right? well i couldn't make it work...

I also tried to set up outbound-nat to translate the remote subnet to tailscale net but couldn't get that to work either.

I noticed that pfsense had some guides for this since they also got a tailscale plugin now, not sure it that plugin does stuff differently behind the curtains, but i could not get any closer to success with any of those guides.

Basically i'd like to solve this and create a Guide for it since i am positive this will be helpful for many people when more people realize the pros of this system.

Is subneting/exit node working on this package? what could i be doing wrong? and most importantly what would be a good way to troubleshoot the problem? i'w watched the "Live View" and the traffic actually leaves LAN network and goes in to the Tailscale network... but the remote site never gets any traffic.
Title: Re: Tailscale site-to-site setup
Post by: Kieeps on August 07, 2022, 09:45:11 pm
Just to clarify, since routing to an interface isn't possible i have to create a gateway for that interface right?
the IP for that gateway could technically could be anything right?

Then routing the specific subnet through that gateway would send the traffic through that interface?
Title: Re: Tailscale site-to-site setup
Post by: ColeTrain on January 29, 2023, 01:48:01 am
I am in a similar spot, now, with similar questions. Would love a response or if you figured it out, please provide a link or guide!

Thanks!
Title: Re: Tailscale site-to-site setup
Post by: teb on January 30, 2023, 10:05:58 pm
I think I am in the same boat.  I have tailscale set up with subnet routing on both sides (I am paying for 2 subnets).  I have 2 subnets I want to connect: 192.168.10.0/24 and 192.168.77.0/24.  I can ping any 192.168.77.x IP from my router (192.168.10.1), but I cannot ping anything on 192.168.77.1 from my laptop (192.168.10.24).  I have set up a gateway and route according to the screenshots, but nothing.