Interface for Tailscale shows down after full config

Started by dwanecl, September 26, 2026, 12:41:07 AM

Previous topic - Next topic
Hello All,

Been working an issue with getting Tailscale up and running on my OPNsense router for days. I have installed the tailscale plugin through the GIU (tried through SSH and have the same results), fully configured, firewall rule has been created. shows up on the tailscale site as online. The issue I have is that the interface shows down and I cannot get the VPN working.

What I am trying to do is connect two networks through two OPNsense routers with tailscale.

Hoping someone knows how to correct this issue.

I have attached a screenshot of the down interface.

If the node shows online in the admin console, auth and the tunnel should probably be fine. The "down" status on the assigned interface is most likely just cosmetic. I would first run tailscale status and tailscale ping <other router> from the shell to confirm this.

For site-to-site between two OPNsense boxes, there are a few things that need to be correct:

Each router has to advertise its own LAN subnet in the plugin, and of course the two subnets must not overlap. Then both routes need to be approved in the admin console (Machines > Edit route settings), otherwise they will stay inactive.

Also check that "Accept routes" is enabled on both routers. If not, they will not install the subnet from the other side.

On each router, you also need a pass rule on the Tailscale interface with the remote LAN subnet as source, not only the 100.64.0.0/10 range.

If it still doesn't pass traffic, can you post the plugin settings and the output of tailscale status from both routers?
François MAYMIL
IT Consultant & MSP — Luxembourg
Creator of Paart — WireGuard for people who manage multiple networks
https://paart.app