How to Setup The Tailscale VPN and Routing on pfsense [YouTube Release]

Additional Resources:

How To Setup pfsense OpenVPN Policy Routing With Kill Switch Using A Privacy VPN

How Tailscale Makes Managing Wireguard Easy

Tailscale VS ZeroTier

Netgate tailscale Blog post

tailsacle NAT write up

Headscale GitHub

tailsacle userspace kernel

Connecting With Us

Lawrence Systems Shirts and Swag

►👕 https://teespring.com/stores/lawrence-technology-services

AFFILIATES & REFERRAL LINKS

Amazon Affiliate Store
:shopping_cart: Lawrence Systems's Amazon Page

Ubiquiti Affiliate
:shopping_cart: Ubiquiti Store United States

All Of Our Affiliates that help us out and can get you discounts!
:shopping_cart: https://www.lawrencesystems.com/partners-and-affiliates/

Gear we use on Kit
:shopping_cart: Kit

Try ITProTV free of charge and get 30% off!
:shopping_cart: Learn technology and pass IT certifications with ITProTV

Use OfferCode LTSERVICES to get 10% off your order at
:shopping_cart: Tech Supply Direct - Refurbished Tech at Unbeatable Prices

Digital Ocean Offer Code
:shopping_cart: DigitalOcean | Cloud Hosting for Builders

HostiFi UniFi Cloud Hosting Service
:shopping_cart: HostiFi - UniFi Cloud Hosting
Netgate tailscale Blog post
Tailscale on pfSense Software!

tailsacle NAT write up

Headscale GitHub

tailsacle userspace kernel

Protect you privacy with a VPN from Private Internet Access
:shopping_cart: Buy VPN with Credit Card or PayPal | Private Internet Access

Patreon
:moneybag: lawrencesystems | creating Tech Tutorials & Reviews | Patreon

:stopwatch: Timestamps :stopwatch:
00:00 pfsense tailscale pacakge
03:31 Headscale server
04:19 Tailscale Web Management
05:26 Tailscale Access Contol Security
06:10 Managing Tailscale in pfsense
09:36 pfsense routes and exit node
10:48 Tailscal Connectivity and Firewall Security

Hi Tom, are you able to update your video, as I was trying to get Tailscale to work on 2.7.2 and the latest PFSense+ and discovered they’ve changed the way outbound NAT works for the Tailscale setup - Even documentation on the Tailscale PFsense setup installation hasn’t updated.

Here’s the URL to the issue that discusses that change after many reported having the same issue - Regression #14987: ``Interface Address`` is no longer an option for outbound NAT targets - pfSense - pfSense bugtracker

So, far I haven’t been able to test Tailscale in a non-production environment to see if there’s a viable workaround.

Was wondering if you’re aware of any to get outbound NAT with Tailscale working?

1 Like

Would this be what’s causing me not to be able to get a direct connection behind my pfSense box on my local network from externally devices (my laptop sitting at a coffee shop)? Doing a tailscale ping test it has to relay through a DERP server to reach my internal network devices, which results, obviously, in much slower speeds.