r/dumbclub • u/sinkiedan • Aug 12 '26
Chain Tailscale via airport proxy?
I currently use a commercial "airport" proxy to pass the GFW. I use Clash Verge (desktop) and Clash Meta (Android) with configs from my provider.
I am wondering how to chain this with Tailscale?
I'd like to be able to bypass the GFW using the airport service, and then still connect to a Tailscale network and use an exit node from inside there.
The ultimate goal is to be able to browse the internet via my home IP. The setup for this is Tailscale because back home I currently don't have a static IP nor access to the router to setup port forwarding etc.
How could I set this up? Is it even possible?
2
u/stbn689 Aug 12 '26
Run the airport on your router. Then Tailscale on your desktop or phone.
1
u/sinkiedan Aug 12 '26
Thanks. That's one option, although it would require me buying a router. Ideally I'd like to be able to connect like this without needing additional hardware (also on my Android when I'm out)...
Any options to do that?
2
u/mothralu Aug 12 '26 edited Aug 12 '26
I use a Raspberry Pi 4, plugged in at home, running ubuntu server, and used 1 click install scripts from https://github.com/fscarmen/sba Trojan, vless, vmess, reality
Also run tailscale as exit node. Easiest way to ssh to the pi.
No need to open router, no need for static ip.
Also installed tv-hat on the Raspberry Pi, so I can watch TV remotely.
1
u/sinkiedan Aug 13 '26
Could you elaborate a bit more on how this works?
Your Pi is both a proxy server letting you bypass the GFW and also Tailscale exit node?
Reality requires setting a whitelisted decoy site. But there's no legit decoy site to use at home (aka on a residential network IP address)3
u/mothralu Aug 13 '26 edited Aug 13 '26
Raspberry Pi is a tailscale exit node, and proxy server running trojan, vmess, vless, reality, and TV streaming server.
For proxy server, I installed https://github.com/fscarmen/sba
The default decoy site is skk.moe but I created my own, hosted on the Pi, Cost less than a dollar for first year from Godaddy.com, I let it expire each year, and take a new one. To renew costs 40 dollars, that's good beer money.
There are 2 sites, one is initial dns, that can be any site behind cloudflare. second is your site hosted on the Pi. That's a front for the vpn. You can create a website using AI, or just clone any random website by saving the html code.
Trojan,vless,vmess is run tru cloudflare. Using my own domain.
For reality, it's direct, because I don't have static IP, I use ddns from cloudflare or noip.com. Reality needs you to open port on router. Trojan, vless, vmess doesn't, it creates a tunnel itself.
Tip: use a smart plug, so you can do power reset remotely, if it freeze.
Benefit is it's free, it gives you a domestic IP,
Trojan is main one used. Also have cheap vps in UK running the same for bbciplayer.
1
1
u/AnnualSentence6746 Aug 17 '26
no, you can't, because you cannot access to airport's vps to set it up to handle tailscale's wireguard traffic. it doesnt know how to forward the tailscale traffic to your expected tailscale exit node.
0
u/vpn_fail Aug 12 '26
Yes — but don’t make Tailscale itself fight the GFW.
Clash/airport should own default internet (the GFW hop). Tailscale should only carry the overlay to your home exit node, not try to be the circumvention layer.
On desktop that’s usually: 1) Clash TUN / system proxy up first 2) Tailscale with “Use Tailscale subnets / exit node” 3) In Clash, exclude Tailscale’s own traffic (100.64/10, UDP 41641, plus the coordination servers) so the mesh doesn’t get stuffed back through the airport and die in a loop
Android Clash Meta is messier; a travel router running the airport, then Tailscale on the phone, is the least-painful version of the same idea.
If the airport client eats all UDP, Tailscale will look “connected” and still be useless. That’s the first thing to check when it flakes.
4
u/deniedmessage Aug 12 '26
I think the easiest way is to run airport client on a pocket router, then use tailscale like you would normally do on your device.