Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
Tailscale - Filter Tailscale to ...
« previous
next »
Print
Pages: [
1
]
Author
Topic: Tailscale - Filter Tailscale to ... (Read 1181 times)
michielc
Newbie
Posts: 3
Karma: 0
Tailscale - Filter Tailscale to ...
«
on:
December 25, 2023, 10:08:31 am »
Hi all,
First of all merry christmas
I am having a problem with my OPNSense (OPNsense 23.7.10_1-amd64) Community installation.
My OPNSense is acting as an exit node for clients and i am able to connect my phone to the tailscale network with the firewall as exit node.
This weekend i splitup my network so that i have different vlans and rules per vlan.
Now i want to make sure that traffic from tailscale cant access some host.
When looking at the logs i see all the traffic from my phone is originating from 10.0.6.1 ( Default VLAN interface ).
I tried looking for a sollution but all i can find is routing traffic from lan to tailscale not the other way arround.
Can anyone point me in the right direction on how to be able to filter traffic from tailscale or is this just a limitation to the implemantation on opnsense?
Tailscale parameters: --advertise-exit-node --advertise-routes=10.0.6.0/24
I can even disable or remove the Tailscale interface on my Opnsense and everything keeps working.
«
Last Edit: December 25, 2023, 10:57:27 am by michielc
»
Logged
michielc
Newbie
Posts: 3
Karma: 0
Re: Tailscale - Filter Tailscale to ...
«
Reply #1 on:
December 26, 2023, 08:14:58 am »
Just switched to Zerotier and with that implementation i can filter packages and add rules so if you are looking for a wireguard implementation on opnsense go with zerotier.
Logged
lrosenman
Full Member
Posts: 197
Karma: 8
Re: Tailscale - Filter Tailscale to ...
«
Reply #2 on:
December 26, 2023, 08:15:28 pm »
Have you looked at the tailscale access rules?
Logged
michielc
Newbie
Posts: 3
Karma: 0
Re: Tailscale - Filter Tailscale to ...
«
Reply #3 on:
December 28, 2023, 12:59:35 pm »
Quote from: lrosenman on December 26, 2023, 08:15:28 pm
Have you looked at the tailscale access rules?
Thanks for the suggestion and yes i did test with the access rules in Tailscale, that works but i want to manage it all in de FW itself. I now have a working system with the use of zerotier instead of tailscale and all my rules are managed in OPNSense.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
Tailscale - Filter Tailscale to ...