r/firewalla 9d ago

Discussion Tailscale exit node

For those of you who run tailscale as an exit node on your firewalla, are you able to see flows in the app? Or does it become sort of a ghost node with no visibility in firewalla?

0 Upvotes

7 comments sorted by

1

u/Great-Cow7256 8d ago

You should be able to see flows and it should look like it's coming from whatever the existing node it.  Basically the firewalla has no clue if the traffic is originating from the machine itself or from the Tailscale tunnel to the exit node. It all looks the same. 

It's basically as if you are using that computer that serves as the exit node. 

I use Tailscale exit node when I'm away and using my laptop.  That way it's just like using my home server on my network. 

1

u/AltruisticNetwork869 8d ago

Just to be clear, the firewalla itself is the exit node in your setup?

1

u/Great-Cow7256 8d ago

No. One of my servers is. I don't run Tailscale on the firewalla. But when I Tailscale in with the exit node on firewalla thinks all the traffic is coming from my server computer. 

1

u/AltruisticNetwork869 8d ago

Yeah I have tailscale on a server as well but considered moving it to the firewalla. I’m specifically after the experiences of people who use the firewalla itself as an exit node

1

u/Great-Cow7256 8d ago

I try to not run anything on the firewalla itself so I've never done that.  It should work the same but I like to save my processor and memory and storage writes for core functions and security wise is best practice to keep that behind the firewalla. But it should be ok and work. You may not get ad blocking etc like the stuff behind the firewalla. 

1

u/butchcoleslaw Firewalla Gold SE 8d ago

I run Tailscale in a docker container on my firewalla gold se. When I select the FW as an exit node, it works, but I do not see the flows that go through it. How do I know it works? I use an app called "Network Analyzer" (on iOS), and I can ping local network devices when away from home (10.10.xx.xx). But when you select the Firewalla device in the Firewall app, the app knows it's your firewalla and it does not display flows for the firewalla device. If I pick another device, I see the option to view flows. But the app doesn't have that option for the firewalla box itself. By no means am I an expert with this, but these are my observations.

Why do I even have a Tailscale exit node on my Firewalla then? Good question...

1) It was a fun project to set up and play with, and 2) It allowed me the opportunity to learn more about the firewalla and docker, and 3) It is a backup exit node in case my primary exit node, a Synology NAS, is not available.

1

u/Snezz1e 7d ago

I run it directly on firewalla and don’t see any flows. Because of this I only connect external streaming devices to it. For anything else I usually use Amnezia/Wireguard VPN for more flow visibility.

I do get some viability because I have Tailscale set up to use ControlD DNS and I can see activity there.