Use Tailscale+mullvad as tunnel for opnsense box itself

Started by Magician1981, October 26, 2025, 09:07:06 AM

Previous topic - Next topic
October 26, 2025, 09:07:06 AM Last Edit: October 26, 2025, 09:13:32 AM by Magician1981
Hello,

Please help me with the following. I am running opsense baremetal and have installed tailscale+mullvad addon. I want my opsense box itself to use the mullvad connection for internet traffic instead of the normal connection so that for example system updates only go through the tunnel.

This is the current public ip (redacted):

root@OPNsense:~ # curl https://am.i.mullvad.net/connected
You are not connected to Mullvad. Your IP address is 31.xxx.xxx.xxx

Tail scale docs do no provide a install guide to enable this. In opsense webgui it does say this under advanced:

Route traffic to the specified exit node. Note that this only affects traffic routed into your Tailscale interface, which you will have to configure separately using firewall rules and hybrid outbound NAT rules.
So can someone provide me with step by step guide please?

Thank you.



It has been almost a year so I will address at a high level for posterity. I can only speak to the routing of traffic originating on the router as I have no experience with Tailscale. Also this is just how I accomplish this and there could be other ways. Some steps may be redundant.

- Create static routes for WG peer addresses to use ordinary (ISP/WAN) gateway (i.e. System > Routes, add Mullvad server IP + ISP/WAN GW)
- Create interface(s) for WG instance(s): IP configuration types "None", MTU 1420 (research & experiment here), select "Dynamic gateway policy" at bottom
- Create gateway(s) for WG instance(s): IP address same as used in WG instance config*, check Upstream, Far, Failover, Fallback, select unique Monitor IP per GW**
- Back out, assess overview of system Gateways, insert GW priorities for all of them with lower number holding higher significance***
- Enable default GW switching at System > General
- Its OK to make a monitor IP for ISP/WAN GW using assigned GW IP for both addresses. It will participate in GW failover but its very low (high number) priority will prevent selection unless WG fails.
- About your Tailscale I expect you can use FW rules to force traffic from that ip/network over WG GW


(* often tunnel's last octet -1, e.g. VPN provider's assigned (internal) IP=10.10.10.10, GW config=10.10.10.9)
(** must be routable, immune to/participative in persistent ICMP, and something you'll never use otherwise. e.g. 4.2.2.1)
(*** e.g. WG Gateway=100, ISP/WAN GW=200)