Tailscale advertised routes not working for particular subnet

Started by endurium, July 28, 2026, 07:40:43 PM

Previous topic - Next topic
I'm running Tailscale in a Proxmox container  with Proxmox also hosting my OPNSense VM which hosts a wired LAN on it's LAN interface (192.168.1.1) and a WiFi AP on it's WLAN interface at 192.168.3.1. Tailscale is connected to OPNSense LAN via ip 192.168.1.10 has been configured to advertise both LAN and WLAN subnets but with Tailscale connected on my remote device (iPad) I can browse devices on the LAN subnet but not the WLAN.

Both LAN and WLAN firewall rules allow in and out traffic on both interfaces so it's not the firewall rules blocking Tailscale, I can ping 192.168.1.1 from the LXC container and also ping 192.168.3.10 (where the AP is connected) so there's no issue with traffic flow there. Via a SSH session on 192.168.3.10 I'm able to ping 192.168.1.10 so the WLAN AP can see the Tailscale LXC. The subnet routes have been approved in the Tailscale machines management page.

I can't see what else to do in Tailscale to sort out this issue, so I'm guessing I need to do something in OPNSense?

Can anyone please help?
Intel N100 | 6*I226-V | 32GB DDR5 | 512GB NVME | Proxmox 9

I tried connecting to another device on the WLAN network from a Tailscale-connected device and it worked fine so it looks like Tailscale is routing traffic correctly, it just doesn't work when connecting to the ASUS AiMesh access point so I'm guessing the ASUS is refusing to play ball for security reasons (it's a router configured as a WiFi access point).
Intel N100 | 6*I226-V | 32GB DDR5 | 512GB NVME | Proxmox 9