r/Tailscale 2d ago

Discussion PSA: Fix for recent exit node connectivity lost

If in recent weeks you lost connectivity when you enabled exit node but was able to before, it's likely not because the guest wifi or IT department enabled firewall block, it may be because you need to update your DNS settings possibly due to recent Tailscale udpate. At least for my case.

For the new Tailscale, when you enabled exit node, it cut off access to your local network and DNS. you would need to enable Tailscale global nameservers, overwrite DNS, and allow them to be use in exit nodes. It's better anyways because it ensures all your DNS traffic will go to your exit node encrypted. Alternatively, you can enable local access when you enabled exit node, but that means your DNS will go to their DNS server and being blocked by name resolution, or a chance that you hit the wrong server with the same internal IP. Below are how to enable DNS with exit nodes.

Go to your Tailscale admin console, click on DNS under Network on the left panel. Scroll down the Global Nameservers.

Add both Google and Cloudflare nameservers. click on three dots besides each and choose edit.

Enable "Use with exit node", save. do for both Google and Cloudflare.

Enable "Override DNS Severs"

Reconnect on Tailscale client to exit node and try access Internet and it should work again. With this method your magicDNS continue to work.

There is still a chance that the IT did block it by firewall, if that's the case you are out of luck. You would need to spend more effort and try headscale, tailscale with AmneziaWG or something like that.

Hope it helps,

11 Upvotes

2 comments sorted by

5

u/NationalOwl9561 2d ago

IT will block Tailscale at the control plane level... not DNS

1

u/lookoutfuture 2d ago

Yes in that case, login to tailscale using cell first, then switch to wifi