Route LAN Clients w/ tailscale (one-way-only) to Tailscale destinations


This is like a site-to-site network, except I want my LAN machines that don’t have tailscale installed to be able to access servers that are in WAN locations. But I don’t want these WAN servers to be able to initiate connections back to machines on my LAN.

For example:
I have a LAN with machines on subnet
I tave a server in another location that is running Taliscale. Let’s say its IP is
I have setup a machine on my LAN with Tailscale on running Ubunto 24.04. It’s Tailscale IP is
I have setup a static route in the LAN router: via
I have enabled “net.ipv4.ip_forward = 1” and “net.ipv6.conf.all.forwarding = 1” in /etc/sysctl.conf
I have run tailscale up --accept-routes --snat-subnet-routes=true (also tried false)
I have setup a static route on via

Pings from LAN machines to time out.
Traceroutes from machines on the network go => => and then time out.

When pinging, TCPDump on shows:
IP > ICMP echo request, id 1, seq 5251, length 40

but no replies.

What am I missing?