Skip to content

os-tailscale ignores Firewall Rules altogether. #5029

Description

@jmb988

Important notices
Before you add a new report, we ask you kindly to acknowledge the following:

Describe the bug
Tailscale traffic is treated as local traffic separate from the usual interfaces and firewall rules under the tailscale interface don't apply any changes at all. Example: I set a pass rule with the source being tailscale net, destination !Private_Networks, gateway selected was my VPN gateway. Outbound NAT setup on VPN interface with tailscale. DNS allow rule to :53 This firewall. When I then connect to the exit node, I still see my public WAN IP, and ISP DNS. I can only produce this in the tail scale interface rules. All my other interfaces with those tules support this and behave as expected.

Tip: to validate your setup was working with the previous version, use opnsense-revert (https://docs.opnsense.org/manual/opnsense_tools.html#opnsense-revert)

To Reproduce
Steps to reproduce the behavior:

  1. Go to 'Tailscale interface rules'
  2. Add any rule (DNS, gateway policy routing)
  3. Log the rules while using tailscale
  4. They don't see tailscale at all, bypassing all rules and giving me default DNS and WAN.

Expected behavior
Tailscale would behave as set in it's firewall rules. Sending it through a gateway or using my DNS resolver after setting outbound NAT.

Screenshots
If applicable, add screenshots to help explain your problem.

Relevant log files
If applicable, information from log files supporting your claim.

Additional context
Add any other context about the problem here.

Environment
Software version used and hardware type if relevant.
e.g.:

OPNsense 23.7.8 (amd64).
Intel® Xeon™ E3-1225V5 3.3Ghz Quad Core
Network Intel® I210-AT

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions