I have to ask here, if it works doing what you want it to, as is, why?I will add that snat to both ends of the site-2-site and see if it makes any difference.
Just to test ?
What do you expect or hope to improve; or change?
Last edited:
I have to ask here, if it works doing what you want it to, as is, why?I will add that snat to both ends of the site-2-site and see if it makes any difference.
Just to test. I did enable it on one router. Really didn’t make any difference, it least in my use cases. Went back to TAILMON’s command line.I have to ask here, if it works doing what you want it to, as is, why?
Just to test ?
What do you expect or hope to improve; or change?
tailscale
package has just been updated from 1.68.2-1 to 1.68.2-3 to include the fixes to S06tailscaled I suggested. Note that it also adds Entware's coreutils-nohup
as a prerequisite although that's not necessary for asuswrt.Thank you @ColinTaylor for posting the two requests up on Github, it's been a wee while but they did get on to it in the end, so great result.Pleased to see that Entware'stailscale
package has just been updated from 1.68.2-1 to 1.68.2-3 to include the fixes to S06tailscaled I suggested. Note that it also adds Entware'scoreutils-nohup
as a prerequisite although that's not necessary for asuswrt.
Just wanted to say thanks for such an amazing job with this. I have a home network stuck behind a CGNAT system and this was super easy and extremely effective to get around that... 4G CGnatted systems are very common in Europe, so this is a big help. How do I contribute a coffee or beer money though?
@ColinTaylor did you mean to write updated from 1.58.2-1 to 1.68.2-3?Pleased to see that Entware'stailscale
package has just been updated from 1.68.2-1 to 1.68.2-3 to include the fixes to S06tailscaled I suggested. Note that it also adds Entware'scoreutils-nohup
as a prerequisite although that's not necessary for asuswrt.
No I did mean 1.68.2-1 to 1.68.2-3. There was an additional update on 16th August just for tailscale that replaced the version from 9th August.@ColinTaylor did you mean to write updated from 1.58.2-1 to 1.68.2-3?
Asking as the original Tailscale entware install was based on 1.58.2-1, but I wasn’t aware of an interim update?
k.
Okey dokey, sorry, I missed that one!No I did mean 1.68.2-1 to 1.68.2-3. There was an additional update on 16th August just for tailscale that replaced the version from 9th August.
Only if you can already get a WG connection running, which, if it is behind CGNAT is not possible as far as I am aware. But neither WG nor OPenVPN nor any (?) other VPNs or remote access mechanisms can get past CGNAT AFAIK.Ok, this probably should be a new thread but is it possible to setup Tailscale via Wireguard on a remote Asus router using only the Asus remote app? I.e. just adding information to the Wireguard VPN setup in the GUI? I currently only have access to the remote router via the GUI due to a CGNAT. Or is there another way to get remote access to my LAN that's behind CGNAT using just the Asus web GUI?
Are you saying this is a problem specifically with access the router itself, but accessing other devices on the router's LAN works OK?Can someone help me connect to my routers WebUI+ SSH from outside the network through my tailnet? Currently using it in "Kernel Mode" with Exit Node & Subnets advertised. I have tried using TailScale Serve (#166) and read through this discussion (starting at #342). I'm unable to connect using Tailnet address.
tailscale status
show? Is your client shown as "active"?Yes. The problem is accessing the WebUI and/or SSH through tailscale, outside the network. Accessing other devices on the router's LAN works fine.Are you saying this is a problem specifically with access the router itself, but accessing other devices on the router's LAN works OK?
Accessing http://192.168.50.1 works fine while on LAN. Accessing hostname.tailfXfXX.ts.net does not work (I am also using tailscale cert for SSL certificate in WebUI). Currently using another node inside network to advertise 192.168.50.1/32 so that I can manage it from outside of network.How are you accessing the router's GUI, e.g. http://192.168.50.1 ?
It has a public IP and not behind NAT.Does your router have a public IP address or is it behind NAT?
It shows the list of online devices with the client being active (device2):What does the output oftailscale status
show? Is your client shown as "active"?
username@router:/tmp/home/root# tailscale status
100.X.X.X router username1 linux idle; offers exit node
100.X.X.X device1 username2 iOS -
100.X.X.X device2 username2 macOS active; direct PUBLIC_IP:41641
...
Yes they are both connected (device2 & router as shown above)Are both the router and your client shown as Connected on https://login.tailscale.com/admin/machines ?
macOS Safari -> RT-AX88U routerWhat is your client device?
It's not entirely clear whether you've tried this but you need to be accessing the router using its 192.168.50.1 address (rather than hostname.tailfXfXX.ts.net) as this is what httpd(s) and dropbear are listening on. hostname.tailfXfXX.ts.net would resolve to something like 100.66.22.55 which won't work.Yes. The problem is accessing the WebUI and/or SSH through tailscale, outside the network. Accessing other devices on the router's LAN works fine.
Accessing http://192.168.50.1 works fine while on LAN. Accessing hostname.tailfXfXX.ts.net does not work (I am also using tailscale cert for SSL certificate in WebUI). Currently using another node inside network to advertise 192.168.50.1/32 so that I can manage it from outside of network.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!