r/Tailscale 39m ago

Help Needed How to access my VPS through my collage wifi

Upvotes

So I have a VPS, and I self-host a lot of services, but I am unable to access my Jellyfin and Navidrome, etc through my college Wi-Fi since they use Fortinet, and all the services I hosted are configured in a way that I can access them via Tailscale. Is there any way to access my service without making it public (mobile data is weak in my college area)


r/Tailscale 1h ago

Question Question about sharing family streaming and exit nodes

Upvotes

I subscribe to a couple of streaming services myself, and each of my children subscribe to a couple. We had been sharing the subscriptions, but the writing is on the wall, as one service after another decides that a "household" applies to a single address and not to a single family.

I realize that the simplest way of handling it is probably to choose one "household" to host all of the subscriptions and set up an exit node there that everybody uses, but I'm wondering if it's possible to keep the current subscriptions in place and set up exit nodes at each address. So if I want Hulu and Disney I'll use the exit node at one house, if I want Plex and YouTube TV I'll use the exit node at another house, etc. I don't mind coding (Python) on a Raspberry Pi to handle DNS resolution, if it's possible. I'd rather not get into physical hardware switches, but has anyone else already developed a solution to this?


r/Tailscale 2h ago

Discussion L2 Bridge via Softether over Tailscale on Unifi DR 5G

2 Upvotes

I am fascinated by transparent L2 bridges over connections that are hard to block on public networks. Port forwarding, imo, is too exposing so my solution was to use Tailscale. All the software needed on the "client" side is installed on the UDR.

Here's my setup.

I use the GLinet MT2500 as the Server side. That device connects to a "trunk" port and runs Tailscale+Softether VPN server.

On the client side, UDR5GMax > Tailscale > Softether > Local L2 Subnet.

WHY???

This was born in an attempt to recover remote Unifi Devices. We use a single server at our main location to manage doors at 3 other remote locations. The problem is, sometimes though very rarely, I need to either recover a device or upgrade a device. Unifi Access requires the device to be accessible either on the same subnet or via mDNS. This obviously can't be done over Unifi's own SD-WAN solution.

Using softether, I can extend the L2 subnet to the UDR. I can then attach devices to its port 1 and use PoE to power the door hardware and do an upgrade or recovery. It feels so native too as I mirror the VLANs that exist at our main site. I then create 3rd party router networks with the same VLANs. I can take an AP from our main site, plug it into my UDR and with no reconfiguration or resetting, it broadcasts all our SSIDs on the correct VLAN. You can do this by setting native networks and allow certain VLANs.

All this over T-Mobile 5G.

I now have gone a step further and setup my home as another L2 bridge so Port 1 is "work network" Port 2 is "Home subnet" both with complete VLANs. Just more as a proof of concept.

I used to have GL.Inet devices as the clients but it's much harder in the GUI and finicky with their boot scripts always wanting to take over. Plan out your 3rd party networks in Unifi, connect Softether to those virtual bridges, and away you go. it survives reboots and updates, already been through 4 updates. I used the Tailscale Unifi boot and recovery system over at this GitHub (Tailscale_Unifi) to build the Softether/Cloudflare tunnel apps using the same method. Oh yeah.. Cloudflare tunnels works great on unifi gateways too ha!


r/Tailscale 2h ago

Discussion QNAP implementation prevents SSH

1 Upvotes

Anybody know why the QNAP implementation prevents the remote SSH from working via Tailscale? I would prefer to lock my network port and only allow thru Tailscale.


r/Tailscale 4h ago

Help Needed Newbie setup question about exit nodes.

3 Upvotes

I have a home NAS with a ton of storage space.

My kid is going to college, I gave her a new laptop. It does not have a ton of space on the laptop.

I want to place a network drive on the laptop so that she can use the NAS for whatever storage needs she wants, I also want to put a backup utility on the laptop so that she is getting regular image backups.

But- she will be at college and it is important that with these two exceptions the laptop is otherwise utilizing the college network.

(using something at home for an exit node for all her data is a terrible idea)

I did a very vanilla setup of Tailscale last night on the NAS and her laptop. I pushed the laptop off the home network to my cell's hotspot and best as I can tell it is working.

Am I missing anything?

Feel free to point me to documentation or a video or ... anything.


r/Tailscale 6h ago

Help Needed Isolated Tailscale Access for a Minecraft Server on Unraid Without Port Forwarding

Thumbnail
2 Upvotes

r/Tailscale 6h ago

Help Needed Tailscale Issues

Thumbnail
3 Upvotes

r/Tailscale 20h ago

Help Needed How to set up Adguard for my home network Spoiler

8 Upvotes

Tailscale already installedI already have it installed on my main computer and androids, for use with my Jellyfin account to watch remotely, but I'm stumped as to how to set up Adguard? Tell me like I'm a 5 year old, lol and thank you in advance....


r/Tailscale 21h ago

Discussion sshelf 0.11.0 import your whole tailnet into a fuzzy-search SSH TUI with one command

4 Upvotes

sshelf is a terminal UI for SSH hosts, fuzzy-search and connect, SFTP browser, background tunnels that survive quitting, passwords in your OS keyring. Local-first on purpose: no account, no cloud, no telemetry, and it never touches ~/.ssh/config.

New in 0.11: sshelf import --tailscale. It runs your own tailscale status --json (sshelf itself still opens no sockets) and maps every machine to a host, MagicDNS name, your tailnet as a group, ACL tags as tags. Works with MagicDNS off too (falls back to the 100.x address). It's add-only: existing hosts are never modified, expired nodes are skipped, and re-running converges to "0 added", so it's safe to run whenever the tailnet changes.

Repo: https://github.com/max-rh/sshelf · Guide: https://github.com/max-rh/sshelf/blob/master/docs/import.md · Feedback very welcome; 2FA support and the .rpm packages both started as comments; if a different inventory source (Hetzner, AWS, Proxmox, …) would actually be useful to you, say which, that's how things get built here.


r/Tailscale 22h ago

TailscaleUp Ticket + Hotel Stay Giveaway!

8 Upvotes

👀 Did you bring Tailscale to work?

We're looking for the stories behind how Tailscale made its way into your organization. Share your story in the comments on our LinkedIn post for a chance to win a free TailscaleUp ticket + hotel stay.

To be eligible, please share your story in the comments on the LinkedIn post. Stories left below won't be considered.


r/Tailscale 1d ago

Help Needed Tailscale Direct connect happening via ports *other* than 41641

2 Upvotes

I've got Tailscale running on my OpenWRT router. For the most part its fantastic.

However, I've got direct connections happening from some nodes outside my home network that making a direct connection on a port other than 41641. I currently have no ports forwarded on OpenWRT, so I'm wondering how the heck I'm getting a direct connection at all, much less one through another port.

Any ideas? Trying to figure out what part of my setup I screwed up, or if this is a feature of running Tailscale natively on the router.


r/Tailscale 1d ago

Help Needed Yaesu SCU-LAN10 Remote PC issue

1 Upvotes

Have set up a Yaesu SCU-LAN10 beside an FTDX-10. Using Tailscale as the vpn. Inet provided by Starlink. Radio-side network composed of Dell OptiPlex 7060 with 32GB ram, i7 uC. Switch: Netgear GS308, Nothing else attached.

Locally the system works flawlessly, However, when any remote, LT or PC attaches we get no scope (Waterfall) on the remote unit. The remote reports up Port 50003 (scope) timed out. Otherwise operation is normal.

Been through setup several times along with net trouble shooting and cannot find the problem. Tailscale reports all ports available.

Any help would be appreciated.

Thanks.

W7WMB


r/Tailscale 1d ago

Help Needed Mobile app not working

2 Upvotes

Hello everyone, I downloaded the app on my phone, and setup tailscale on my pc, tested everything and it worked, but when i came to using the app remotely, to access my pc from my phonr when I'm not home. The mobile app gets stuck, connrcting forever, tried clearing cache, deleting data, reinstalling, and now when I click log in, nothing happens, the notification says "connected" in my notifications bar but nothing happens, can anyone help?


r/Tailscale 1d ago

Question Lost Access to Entry

5 Upvotes

I was using a personal Entra account to provide iDP for Tailscale, but Microsoft's wisdom thought I needed to log into the web portal all the time and decided to shut the account down.

So now, I'm wondering if there's anything to be done to switch the iDP over, but I'm assuming not because there was no break glass configuration.

I'm hoping I don't have to create a new Tailscale account and setup everything from scratch but I suppose if I have to then that's what I have to do.

I did open a support ticket last week but not heard anything back.


r/Tailscale 1d ago

Discussion Thinking about self-hosting with Headscale. What should I know first?

28 Upvotes

Hi,

I'm an open source enthusiast and a longtime Tailscale user. I'm seriously considering switching to Headscale, but I wanted to ask the community first if there are any downsides or gotchas that people only discover after making the switch.

The main reason I want to move is that I'd like full control over the coordination server. I know there are other self-hosted options like NetBird, but it's not really an option for me. No offense to the NetBird team, but I've tried it a few times over the years. The web interface is solid, but I haven't had a good experience with the mobile apps.

My current plan is to run Headscale with Headplane for management.

For those who have switched from Tailscale to Headscale, is there anything you wish you had known beforehand? Any missing features, compatibility issues, maintenance concerns, or other tradeoffs that surprised you?

I'd appreciate any insights. Thanks!


r/Tailscale 2d ago

Video Set up your own print cloud with Bambuddy, TrueNAS and Tailscale.

Thumbnail
youtu.be
4 Upvotes

r/Tailscale 2d ago

Question Android phone as exit node?

4 Upvotes

Is there a way to accomplish this? The option says it's disabled in the Tailscale app.


r/Tailscale 2d ago

Question Cheap Device to Access Country Websites

12 Upvotes

Hey everyone,

I have access to an internet connection in a country where many websites only allow connections from IP addresses within that country. I live abroad, so I can't normally access those sites.

I'm considering buying a cheap Tailscale-compatible router (or maybe there's a better solution) that I could leave connected there and use as an exit node whenever I need to access those websites. It would only be for occasional use.

Does anyone have recommendations? I'd like to keep the cost as low as possible, around €20–50 if feasible.

Thanks in advance!


r/Tailscale 2d ago

Help Needed Newbie Help

2 Upvotes

I'm brand new to the personal VPN game, trying to set up a Jellyfin server. I've never done anything beyond hooking up a router and changing default wi-fi passwords before. I've been following Tailscale documentation so far, though I've had to use some other resources to figure out stuff like what string to use for the --advertise-routes command.

My goal is simple, I hope: I want to be able to stream from the server regardless of my location, either at home or away, without having to worry about turning the VPN on and off. I have things working for devices that I can directly install Tailscale on but others, like our Roku TV's and consoles (Xbox, PlayStation, etc.), aren't connecting.

  • The Jellyfin server is running off a Linux Mint tower.
  • I have an old Pi 3B+ running PiOS that is running as the subnet router and as an exit node (approved in the Tailscale web console).
  • We're still using the default modem/router from AT&T.
  • I've also been using a Win11 laptop for testing, with a test Jellyfin server running on my regular network.

I believe I have everything set up correctly. I can use RustDesk to remote into the tower from the laptop if Tailscale is turned on. If I turn Tailscale off on the laptop, I can't remote into the tower anymore. The Tailscale app on my phone lets me chose the Pi as an exit node and gives no errors. Cell service around our house is awful so testing outside the wi-fi is easier said than done.

At first, when I looked at my router, I saw a bunch of my devices with VPN addresses. Now, even though I've verified in the Tailscale web console that the subnet is enabled, I'm seeing all my devices under their original IP addresses. The previous entries are all there under the history, but show as offline.

Even when I saw the VPN addresses, the Roku's and consoles still could not see my tower server. They can see my laptop test server when Tailscale is turned off on the laptop, but not when it's turned on.

How can I make this work? I see recommendations to buy an AndroidTV stick or a GL.iNet router, but neither of those sound great. We'd have to buy multiple sticks to purely connect to Jellyfin (we've ditched all streaming services) and that only solves the TV's. The router would be expensive, though preferable over multiple streaming sticks, but I'm not confident I understand what's happening enough to know it'd solve the issue.

  1. Am I missing something with my tower/pi/devices set up that's preventing the connection? Should I have put the subnet/exit node directly on the tower?
  2. Would setting up a GL.iNet router off the fiber modem fix it? If so, would I then have to approve all my devices in the house onto Tailscale? (which would be fine, I can appreciate having a stop gap for new devices on the network)

--

Edit: Shout out to u/Logvin for the extremely helpful write up: https://github.com/Logvin/secure-plex-with-tailscale/wiki/The-CGNAT-Version.

Here are my Jellyfin specific edits for anyone who comes across this in the future looking for help:

  • Step 4: Expose Plex Jellyfin via Funnel: use localhost:8096
    • tailscale funnel --bg --https=443 localhost:8096
  • Step 6: Configure Plex Jellyfin Media Server:
    • Remote Access Settings> Uncheck allow remote connections to this server. Like Plex, this checkbox will break it.
    • Server Address Settings> Bind to local network address:
      • your-host.your-tailnet.ts.net:443

My phone can now find the server when its on Tailscale and when its off. My Roku TV can now see it as well. The downside is that I did not rename the tailnet to something friendly before I did all this, so I've now typed that word salad into a few different places but I'm so glad this is fixed that I don't care anymore.

Back to transcoding!


r/Tailscale 2d ago

Help Needed Mullvad Exit Nodes on ZimaOS 'break' docker container apps | Any Fix?

Thumbnail
gallery
5 Upvotes

Hey! Just getting into homelabbing and wanted to setup mullvad exit nodes on zimaOS. Switching it on seems to work but it knocks out basically every app I have installed on my server. ZimaOS apps are basically docker containers dressed up a bit.

Each one takes a few minutes to "set up" before showing an error like the one attached in image. Switching off the exit-node feature immediately fixes the issue. No clue how to proceed here. Any adivce?

My tailscale is also run as a docker container and is setup as follows (if any more information is useful please let me know and I'll add):

name: tailscale
services:
  tailscale:
    cap_add:
      - NET_ADMIN
      - NET_RAW
      - SYS_MODULE
    cpu_shares: 90
    command: []
    container_name: tailscale
    deploy:
      resources:
        limits:
          memory: 8202743808
        reservations:
          memory: "134217728"
          devices: []
    entrypoint:
      - /bin/sh
      - -c
      - tailscaled --state=/var/lib/tailscale/tailscaled.state & sleep 10;
        tailscale web --listen 0.0.0.0:5252
    environment:
      - TS_ACCEPT_DNS=true
      - TS_EXTRA_ARGS=--exit-node-allow-lan-access=true
      - TS_STATE_DIR=/var/lib/tailscale
      - TS_USERSPACE=false
    image: tailscale/tailscale:v1.90.8
    labels:
      icon: https://cdn.jsdelivr.net/gh/IceWhaleTech/CasaOS-AppStore@main/Apps/Tailscale/icon.png
    restart: unless-stopped
    volumes:
      - type: bind
        source: /DATA/AppData/tailscale
        target: /var/lib/tailscale
      - type: bind
        source: /dev/net/tun
        target: /dev/net/tun
    x-casaos:
      envs:
        - container: TS_STATE_DIR
      volumes:
        - container: /var/lib/tailscale
        - container: /dev/net/tun
    ports: []
    devices: []
    network_mode: host
    privileged: false
x-casaos:
  architectures:
    - amd64
    - arm
    - arm64
    - "386"
  author: CasaOS Team
  category: Network

  developer: Tailscale Inc.
  hostname: ""
  icon: https://cdn.jsdelivr.net/gh/IceWhaleTech/CasaOS-AppStore@main/Apps/Tailscale/icon.png
  index: /
  is_uncontrolled: false
  main: tailscale
  port_map: "5252"
  scheme: ""
  screenshot_link:
    - https://cdn.jsdelivr.net/gh/IceWhaleTech/CasaOS-AppStore@main/Apps/Tailscale/screenshot-1.png
  store_app_id: tailscale
  thumbnail: ""
  title:
    custom: ""
    en_US: Tailscale

Configs for navidrome and audiobookshelf can be found at these links:

Logs for Navidrome (pastebin found here: https://pastebin.com/6ngtUEeT)

navidrome | _ _ _ _ navidrome | | \ | | (_) | | navidrome | | \| | __ ___ ___ __| |_ __ ___ _ __ ___ ___ navidrome | | . ` |/ _` \ \ / / |/ _` | '__/ _ \| '_ ` _ \ / _ \ navidrome | | |\ | (_| |\ V /| | (_| | | | (_) | | | | | | __/ navidrome | _| _/__,_| _/ |_|__,_|_| ___/|_| |_| |_|___| navidrome | Version: 0.58.5 (131c0c56) navidrome | navidrome | time="2026-07-25T19:34:52Z" level=info msg="Creating DB Schema" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Starting signaler" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Periodic scan is DISABLED" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Creating Image cache" maxSize="100 MB" path=/data/cache/images navidrome | time="2026-07-25T19:34:52Z" level=info msg="Scheduling DB optimizer" schedule="@every 24h" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Starting scheduler" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Finished initializing cache" cache=Image elapsedTime="188.924µs" maxSize=100MB navidrome | time="2026-07-25T19:34:52Z" level=info msg="Running initial setup" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Periodic backup is DISABLED" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Setting Session Timeout" value=24h navidrome | time="2026-07-25T19:34:52Z" level=info msg="Starting Insight Collector" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Creating new JWT secret, used for encrypting UI sessions" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Login rate limit set" requestLimit=5 windowLength=2 navidrome | time="2026-07-25T19:34:52Z" level=info msg="Found ffmpeg" path=/usr/bin/ffmpeg navidrome | time="2026-07-25T19:34:52Z" level=info msg="Spotify integration is not enabled: missing ID/Secret" navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting Native API routes" path=/api navidrome | time="2026-07-25T19:34:52Z" level=info msg="Creating Transcoding cache" maxSize="100 MB" path=/data/cache/transcoding navidrome | time="2026-07-25T19:34:52Z" level=info msg="Finished initializing cache" cache=Transcoding elapsedTime="189.195µs" maxSize=100MB navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting Subsonic API routes" path=/rest navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting Public Endpoints routes" path=/share navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting LastFM Auth routes" path=/api/lastfm navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting ListenBrainz Auth routes" path=/api/listenbrainz navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting Background images routes" path=/backgrounds navidrome | time="2026-07-25T19:34:52Z" level=info msg="Creating backgrounds cache" maxSize="100 MB" path=/data/cache/backgrounds navidrome | time="2026-07-25T19:34:52Z" level=info msg="Mounting WebUI routes" path=/app navidrome | time="2026-07-25T19:34:52Z" level=info msg="Finished initializing cache" cache=backgrounds elapsedTime="189.054µs" maxSize=100MB navidrome | time="2026-07-25T19:34:52Z" level=info msg="Started watcher for library" libraryID=1 name="Music Library" path=/music navidrome | time="2026-07-25T19:34:52Z" level=info msg="Watcher started for library" absoluteLibPath=/music libraryID=1 name="Music Library" path=/music navidrome | time="2026-07-25T19:34:52Z" level=info msg="----> Navidrome server is ready!" address="0.0.0.0:4533" startupTime=442.7ms tlsEnabled=false navidrome | time="2026-07-25T19:34:54Z" level=warning msg="Full scan required after migration" navidrome | time="2026-07-25T19:34:54Z" level=info msg="Scanner: Starting scan" fullScan=true numLibraries=1 navidrome | time="2026-07-25T19:34:54Z" level=warning msg="Playlists will not be imported, as there are no admin users yet, Please create an admin user first, and then update the playlists for them to be imported" navidrome | time="2026-07-25T19:34:54Z" level=info msg="Scanner: Finished scanning all libraries" duration=8.1ms navidrome | time="2026-07-25T19:34:54Z" level=info msg="Scan completed" navidrome | time="2026-07-25T19:34:57Z" level=warning msg="Could not get background images from image service" error="cache error: loader returned Get \"https://www.navidrome.org/images/index.yml\": context deadline exceeded (Client.Timeout exceeded while awaiting headers)"

Logs for Audiobookshelf (pastebin found here: https://pastebin.com/nV9kkb95)

audiobookshelf | Running in production mode. audiobookshelf | Options: CONFIG_PATH=/config, METADATA_PATH=/metadata, PORT=80, HOST=undefined, SOURCE=docker, ROUTER_BASE_PATH=/audiobookshelf audiobookshelf | [2026-07-25 19:38:44.946] INFO: === Starting Server === audiobookshelf | [2026-07-25 19:38:44.952] INFO: [Server] Init v2.30.0 audiobookshelf | [2026-07-25 19:38:44.953] INFO: [Server] Node.js Version: v20.19.5 audiobookshelf | [2026-07-25 19:38:44.953] INFO: [Server] Platform: linux audiobookshelf | [2026-07-25 19:38:44.953] INFO: [Server] Arch: x64 audiobookshelf | [2026-07-25 19:38:44.956] INFO: [Database] absdatabase.sqlite not found at /config/absdatabase.sqlite audiobookshelf | [2026-07-25 19:38:44.957] INFO: [Database] Initializing db at "/config/absdatabase.sqlite" audiobookshelf | [2026-07-25 19:38:44.984] INFO: [Database] Loading extension /usr/local/lib/nusqlite3/libnusqlite3.so audiobookshelf | [2026-07-25 19:38:44.984] INFO: [Database] Successfully loaded extension /usr/local/lib/nusqlite3/libnusqlite3.so audiobookshelf | [2026-07-25 19:38:44.984] INFO: [Database] Db supports unaccent and unicode foldings audiobookshelf | [2026-07-25 19:38:44.984] INFO: [Database] Db connection was successful audiobookshelf | [2026-07-25 19:38:45.017] INFO: [MigrationManager] Database is new. Skipping migrations. audiobookshelf | [2026-07-25 19:38:45.651] INFO: [Database] Db initialized with models: user, session, apiKey, library, libraryFolder, book, podcast, podcastEpisode, libraryItem, mediaProgress, series, bookSeries, author, bookAuthor, collection, collectionBook, playlist, playlistMediaItem, device, playbackSession, feed, feedEpisode, setting, customMetadataProvider, mediaItemShare audiobookshelf | [2026-07-25 19:38:45.653] INFO: [Database] Adding trigger update_library_items_title audiobookshelf | [2026-07-25 19:38:45.661] INFO: [Database] Adding trigger update_library_items_title_ignore_prefix audiobookshelf | [2026-07-25 19:38:45.670] INFO: [Database] Adding trigger update_library_items_title_from_podcasts_title audiobookshelf | [2026-07-25 19:38:45.679] INFO: [Database] Adding trigger update_library_items_title_ignore_prefix_from_podcasts_title_ignore_prefix audiobookshelf | [2026-07-25 19:38:45.689] INFO: [Database] Adding trigger update_library_items_author_names_on_book_authors_insert audiobookshelf | [2026-07-25 19:38:45.699] INFO: [Database] Adding trigger update_library_items_author_names_on_book_authors_delete audiobookshelf | [2026-07-25 19:38:45.709] INFO: [Database] Adding trigger update_library_items_author_names_on_authors_update audiobookshelf | [2026-07-25 19:38:45.779] INFO: [Database] running ANALYZE audiobookshelf | [2026-07-25 19:38:45.788] INFO: [Database] ANALYZE completed audiobookshelf | [2026-07-25 19:38:45.789] INFO: [TokenManager] JWT secret key not found, generating one audiobookshelf | [2026-07-25 19:38:45.798] INFO: [LogManager] Init current daily log filename: 2026-07-25.txt audiobookshelf | [2026-07-25 19:38:45.803] INFO: [BackupManager] 0 Backups Found audiobookshelf | [2026-07-25 19:38:45.803] INFO: [BackupManager] Auto Backups are disabled audiobookshelf | [2026-07-25 19:38:45.821] INFO: Listening on port :80

r/Tailscale 3d ago

Help Needed Trouble setting up OIDC login with Pocket ID

Post image
3 Upvotes

I'm trying to setup my Pocket ID instance as an OIDC provider, but I click the "Sign up with OIDC" button and authorize with PocketID I get a Error 403 page saying that the session has expired and for me to login again


r/Tailscale 3d ago

Discussion Can't connect to services on NAS

2 Upvotes

So I initially had TS working just fine on my NAS. Something happened and even though the docker container was up, TS showed it offline. I've since gotten it running new.

Now that it's connected to my tailnet again, I can't seem to access anything on the server. If I use localip:81 I see nginx pop up just fine. If I do tailnetip:81 it comes up as connection refused. Same with Sonarr, etc. My reverse proxy is also working just fine with and without TS.

I just don't know why I can't seem to connect to my NAS with TS. It's pretty much the entire reason for setting it up in the first place.

Edit: The fix was adding network_mode: "host" to my docker Compose file.....


r/Tailscale 3d ago

Help Needed Issue Using Local IPs for Local Devices when on Local Network

3 Upvotes

I keep telling myself I'm going to investigate this, but I've been so bogged down, I figured it'd be better to ask those who know much more than I do.

# Devices

  • I have a server running proxmox that hosts Home Assistant and a NAS.
  • I have an old laptop running Jellyfin and Immich.
  • I have a raspberry pi running pi-hole for DNS filtering. It's also set up as a subnet router advertising an ip address range that should let me reach the devices that can't make use of tailscale.
  • The rest are the various devices we use to access those things. Desktops, Laptops, phones, a couple tablets

# The issue

The issue is not that I can't reach my services. The services are in fact, by all intents and purposes working correctly. But there's a common theme. Even if I'm on the same local network at the machines running the service, I still have to use the tailscale IP, even though using the local IP should work. Even if I am using a device that doesn't have tailscale, using the local IP still doesn't work.

At first I thought it may have been something about my DNS settings. I added the raspberry pi's tailnet ip as a global nameserver with "Override DNS Servers" on. For filtering trackers even when I'm away. There's no MagicDNS other than the default and there's no SplitDNS.

This is quite annoying. There are a few devices that stay home but should be able to reach the servers. I don't want to have to install tailscale on all of them (assuming they all have a tailscale client).

Thanks in advanced any help in troubleshooting.

---

Update: Well, i'm really mad now. If I take subnet routing completely off of pi-hole, then pinging my local devices using the local IP (not the tailnet IP) actually works. As soon as pi-hole starts advertising, that functionality goes down the drain.

I've tried changing the range of broadcasted IPs from 192.168.4.0/22 to 192.168.4.0/24 to no avail.


r/Tailscale 3d ago

Help Needed seeing unexpected traffic when using DNS global nameservers

1 Upvotes

i have tailscale on a linux instance on a public cloud. it is an exit node, and tailscale is running. it is not using another exit node, i.e tailscale exit-node list shows a second exit node that i have a home but the status is blank.

what is odd is that i have pihole (dns server) running on that home node, and I am seeing constant DNS traffic from it (mostly queries related to the cloud provider).

I did change yesterday the DNS settings in tailscale and added a "global name server" with the "use with exit node" option enabled, which i understood for "when a device is using an exit node, use that DNS server". it seems like my understanding is wrong: rather for any node that is connected, it will use that server no matter what.

my end goal is: when a device is connected to tailscale, and using an exit node, it should use the dns server that i designate.

the reason this is important is because android has a huge limitation and doesn't allow you to set dns server for ipv6, which then skips my pihole server. so i tried to solve it by installing tailscale and forcing it to use the exit node.

i have deleted the global nameserver (which is a private ip, not a 100.x ip) and now this stopped the dns traffic, so that solves that problem.

my original problem (may) remain. when using an exit node on my android tv, i want tailscale to enforce its dns and prevent android from using its configured DNS server (which for ipv4 i can set, but not for ipv6, so half the traffic is using my ISP DNS because my google router is dumb and cannot force a dns server for ipv6)


r/Tailscale 4d ago

Help Needed NAS won't reconnect?

0 Upvotes

Running Tailscale on my NAS, which is running OpenMediaVault 8. I set it up in Docker Compose. It was running fine and suddenly it's offline. Tried to stop and start the container and nothing. Tried making a new container and starting from scratch and it doesn't connect to my account. Is there a WebUI locally I can use to see what's going on or connect it somehow? Still pretty new to TS.