Tailscale on OPNsense

So i have installed Tailscal on my OPNsense box, as described here : Setting up Tailscale on OPNsense - Tailscale

I get an ip, but i have a hard time, getting anything to work.
Can anybody tell, when other steps they did, to make it usable in this setup ?


OPNsense, and FreeBSD more generally, are community supported and built from the Tailscale client code (which is open source). However some of us do run OPNsense ourselves, including me.

The instructions set up tailscale for just the OPNsense host, so you can (for example) remotely connect to its web UI. If you’re expecting OPNsense to route from your LAN to the tailscale network, that can be done but requires an additional option when bringing the network up: https://tailscale.com/kb/1019/subnets

You’ll need to accept the subnet routes in https://login.tailscale.com/admin/machines before they will work. If everything is configured correctly you’ll see a “Subnets” badge on the machine. A screenshot from my admin panel is attached.

One note, however: Subnet Routing isn’t a feature in the free Solo plan. https://tailscale.com/pricing/
(I pay for the Connectivity plan for my personal Tailscale use.)

Sent from Front

Thanks for your answer.

One thing that strikes me, is that Subnet routing is not part of the free plan ?
Is this new ?
I can’t recall to have seen that, and honestly, i have been using it, on my plan.



The subnet routing feature is not disabled in any tier, and we encourage people to try it to make sure it will meet their needs.

Sent from Front

I just installed Tailscale on OPNsense and just with the defaults that showed up (the guide doesn’t show how to configure the rest , ex: dhcp, etc…) I never get an IP. But in my TS portal I do see OPNsense there with an IP. But I still can not access devices directly.

Tailscale interfaces don’t use DHCP to configure themselves, running “service tailscaled start” followed by “tailscale up” is sufficient. You should see an IP address in ifconfig:

root@OPNsense:~ # ifconfig tailscale0
tailscale0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> metric 0 mtu 1280
inet netmask 0xffffffff
inet6 fd7a:115c:a1e0:ab12:4843:cd96:6240:0101 prefixlen 48
groups: tun
Opened by PID 31526

Sent from Front

so i had to stop the tailscaled service and restart it. Now ifconfig hows the IP that the admin console shows. I can ping out to the test site and other devices from opnsense but can not ping the opnsense from any other devices.

Ignore my last email I did not have a default rule for the tailscale interface. working fine now! Thank you!