Skip to content

Broken app connectors and subnets from disabled IP forwarding #661

Description

@ElioDiNino

After updating HAOS to 17.2, which was released this morning, my app connectors and subnets running through the HA Tailscale app have stopped working. I also got notified via a Tailscale webhook that my node "has IP forwarding disabled", with a link to this documentation page.

My IPv4 subnet route still shows as advertised in the Tailscale app, but due to the HAOS update, the IPv6 subnet is no longer advertised (HAOS ref).

I'm not sure if the HAOS change linked above is the sole cause of the disabled IP forwarding issue, or if there is also something wrong with IPv4 forwarding.

Logs
s6-rc: info: service s6rc-oneshot-runner: starting
s6-rc: info: service s6rc-oneshot-runner successfully started
s6-rc: info: service base-addon-banner: starting
-----------------------------------------------------------
 App: Tailscale
 Zero config VPN for building secure networks
-----------------------------------------------------------
 App version: 0.28.1
 You are running the latest version of this app.
 System: Home Assistant OS 17.2  (amd64 / qemux86-64)
 Home Assistant Core: 2026.4.1
 Home Assistant Supervisor: 2026.03.3
-----------------------------------------------------------
 Please, share the above information when looking for help
 or support in, e.g., GitHub, forums or the Discord chat.
-----------------------------------------------------------
s6-rc: info: service base-addon-banner successfully started
s6-rc: info: service fix-attrs: starting
s6-rc: info: service base-addon-log-level: starting
s6-rc: info: service fix-attrs successfully started
Log level is set to INFO
s6-rc: info: service base-addon-log-level successfully started
s6-rc: info: service legacy-cont-init: starting
s6-rc: info: service legacy-cont-init successfully started
s6-rc: info: service local-network: starting
s6-rc: info: service init-nginx: starting
s6-rc: info: service init-magicdns-proxies-upstream-list: starting
s6-rc: info: service init-magicdns-ingress-proxy: starting
s6-rc: info: service web: starting
s6-rc: info: service web successfully started
[09:57:46] INFO: Starting Tailscale web...
s6-rc: info: service local-network successfully started
s6-rc: info: service protect-subnets: starting
s6-rc: info: service protect-subnets successfully started
[09:57:46] NOTICE: To use MagicDNS in Home Assistant, configure MagicDNS's IP address as DNS server with cli, eg. 'ha dns options --servers dns://100.100.100.100'
s6-rc: info: service init-magicdns-proxies-upstream-list successfully started
s6-rc: info: service magicdns-egress-proxy: starting
[09:57:46] NOTICE: Ignore this notice if you already configured your own DNS (like AdGuard) as DNS server for Home Assistant, and in your own DNS you configured MagicDNS's IP address for your tailnet domain as upstream DNS server.
[09:57:46] NOTICE: Please check your configuration based on the app's documentation under the "DNS" section
s6-rc: info: service init-nginx successfully started
s6-rc: info: service nginx: starting
[09:57:46] INFO: Starting MagicDNS egress proxy...
s6-rc: info: service nginx successfully started
dnsmasq[299]: started, version 2.91 cache disabled
s6-rc: info: service magicdns-egress-proxy successfully started
dnsmasq[299]: compile time options: IPv6 GNU-getopt no-DBus no-UBus no-i18n no-IDN DHCP DHCPv6 no-Lua TFTP no-conntrack ipset no-nftset auth no-DNSSEC loop-detect inotify dumpfile
dnsmasq[299]: using nameserver 172.30.32.3#53 for domain controlplane.tailscale.com 
dnsmasq[299]: using nameserver 172.30.32.3#53 for domain acme-v02.api.letsencrypt.org 
[09:57:46] INFO: Setting up drop for MagicDNS ingress proxy (udp, IPv4, DNS)
[09:57:46] INFO: Setting up drop for MagicDNS ingress proxy (tcp, IPv4, DNS)
[09:57:46] INFO: Setting up drop for MagicDNS ingress proxy (udp, IPv4, Supervisor)
[09:57:46] INFO: Setting up drop for MagicDNS ingress proxy (tcp, IPv4, Supervisor)
s6-rc: info: service init-magicdns-ingress-proxy successfully started
s6-rc: info: service tailscaled: starting
s6-rc: info: service tailscaled successfully started
s6-rc: info: service post-tailscaled: starting
[09:57:46] INFO: Starting Tailscale...
[09:57:46] INFO: Adding local subnets to ip rules with higher priority than Tailscale's routing, to prevent routing local subnets if the same subnet is routed within your tailnet.
[09:57:46] INFO:   Adding route 192.168.1.0/24 to ip rules
[09:57:46] INFO: Using dnsmasq as upstream DNS server for tailscaled
[09:57:46] NOTICE: Tailscale logs will be suppressed after 200 lines, set app's configuration option 'log_level' to 'debug' to see further logs
TPM: error opening: stat /dev/tpmrm0: no such file or directory
2026/04/07 09:57:46 You have disabled logging. Tailscale will not be able to provide support.
2026/04/07 09:57:46 logtail started
2026/04/07 09:57:46 Program starting: v1.96.4-t8cf541dfd-g62bc84ce7, Go 1.26.1: []string{"/opt/tailscaled", "--state=/data/tailscaled.state", "--statedir=/data/state", "--no-logs-no-support"}
2026/04/07 09:57:46 LogID: <redacted>
2026/04/07 09:57:46 logpolicy: using system state directory "/var/lib/tailscale"
logpolicy.ConfigFromFile /var/lib/tailscale/tailscaled.log.conf: open /var/lib/tailscale/tailscaled.log.conf: no such file or directory
logpolicy.Config.Validate for /var/lib/tailscale/tailscaled.log.conf: config is nil
2026/04/07 09:57:46 dns: [resolved-ping=yes rc=unknown ret=direct]
2026/04/07 09:57:46 dns: using "direct" mode
2026/04/07 09:57:46 dns: using *dns.directManager
2026/04/07 09:57:46 dns: inotify: NewDirWatcher: context canceled
2026/04/07 09:57:46 wgengine.NewUserspaceEngine(tun "tailscale0") ...
2026/04/07 09:57:46 dns: [resolved-ping=yes rc=unknown ret=direct]
2026/04/07 09:57:46 dns: using "direct" mode
2026/04/07 09:57:46 dns: using *dns.directManager
2026/04/07 09:57:46 link state: interfaces.State{defaultRoute=enp0s18 ifs={docker0:[172.30.232.1/23 llu6] enp0s18:[192.168.1.83/24 <redacted IPv6>/64 llu6] hassio:[172.30.32.1/23 llu6]} v4=true v6=true}
2026/04/07 09:57:46 magicsock: disco key = d:<redacted>
2026/04/07 09:57:46 Creating WireGuard device...
2026/04/07 09:57:46 Bringing WireGuard device up...
2026/04/07 09:57:46 Bringing router up...
2026/04/07 09:57:46 router: using firewall mode pref 
2026/04/07 09:57:46 external route: up
2026/04/07 09:57:46 router: default choosing iptables
2026/04/07 09:57:46 router: portUpdate(port=57838, network=udp6)
2026/04/07 09:57:46 router: netfilter running in iptables mode v6 = true, v6filter = true, v6nat = true
2026/04/07 09:57:46 router: portUpdate(port=47097, network=udp4)
2026/04/07 09:57:46 Clearing router settings...
2026/04/07 09:57:46 Starting network monitor...
dnsmasq[299]: failed to create listening socket for 127.100.100.100: Address in use
2026/04/07 09:57:46 Engine created.
2026/04/07 09:57:46 pm: using backend prefs for "profile-f5dc": Prefs{ra=true dns=true want=true routes=[0.0.0.0/0 ::/0 192.168.1.0/24] snat=false statefulFiltering=false nf=on host="home-assistant" update=check appconnector=advertise Persist{o=, n=[UMolx] u="home-assistant.<redacted>.ts.net" ak=-}}
2026/04/07 09:57:46 envknob: TS_NO_LOGS_NO_SUPPORT="true"
2026/04/07 09:57:46 logpolicy: using system state directory "/var/lib/tailscale"
2026/04/07 09:57:46 linkChange: in state NoState; PAC or proxyConfig changed; updating routes
2026/04/07 09:57:46 got LocalBackend in 14ms
2026/04/07 09:57:46 Start
2026/04/07 09:57:46 ipnext: active extensions: posture, clientupdate, relayserver, taildrop, conn25, portlist
2026/04/07 09:57:46 tka initialized at head 5933565444374536514f57355a32464b564250445143444a4e50564c4652535a4f4e4d33525546364e543444594f554c50414a51
2026/04/07 09:57:46 control: tkaHead: <redacted>
2026/04/07 09:57:46 Backend: logs: be:<redacted> fe:
2026/04/07 09:57:46 control: client.Login(0)
2026/04/07 09:57:46 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:254 Protocol:0 Scope:0 Type:1 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5210 Table:254 Mark:16711680 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
2026/04/07 09:57:46 control: doLogin(regen=false, hasUrl=false)
2026/04/07 09:57:46 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:253 Protocol:0 Scope:0 Type:1 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5230 Table:253 Mark:16711680 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
2026/04/07 09:57:47 health(warnable=warming-up): error: Tailscale is starting. Please wait.
2026/04/07 09:57:47 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:0 Protocol:0 Scope:0 Type:7 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5250 Table:0 Mark:16711680 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
2026/04/07 09:57:47 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:52 Protocol:0 Scope:0 Type:1 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5270 Table:52 Mark:0 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
2026/04/07 09:57:47 web server running on: http://127.0.0.1:25899
2026/04/07 09:57:47 monitor: gateway and self IP changed: gw=192.168.1.254 self=192.168.1.83
[09:57:47] INFO: Starting NGinx...
2026/04/07 09:57:47 localapi: [POST] /localapi/v0/upload-client-metrics
2026/04/07 09:57:47 router: somebody (likely systemd-networkd) deleted ip rules; restoring Tailscale's
2026/04/07 09:57:47 control: control server key from https://controlplane.tailscale.com: ts2021=[fSeS+], legacy=[nlFWp]
2026/04/07 09:57:47 control: RegisterReq: onode= node=[UMolx] fup=false nks=false
2026/04/07 09:57:47 control: RegisterReq: got response; nodeKeyExpired=false, machineAuthorized=true; authURL=false
2026/04/07 09:57:48 health(warnable=not-in-map-poll): ok
2026/04/07 09:57:48 control: netmap: got new dial plan from control
2026/04/07 09:57:48 tkaSyncIfNeeded: isEnabled=true, wantEnabled=true, head=<redacted>
2026/04/07 09:57:48 active login: home-assistant.<redacted>.ts.net
2026/04/07 09:57:48 netmap: suggested exit node: no preferred DERP, try again later
2026/04/07 09:57:48 Switching ipn state NoState -> Starting (WantRunning=true, nm=true)
2026/04/07 09:57:48 appc: handling domains: [disneyplus.com netflix.com.edgesuite.net nflxext.com nflximg.com nflxvideo.net disney-plus.net disney.images.edge.bamgrid.com nflxsearch.net nflxso.net cdn.registerdisney.go.com netflix.com nflximg.net] and wildcards: [disney-plus.net disneyplus.com netflix.com netflix.com.edgesuite.net nflxext.com nflximg.com nflximg.net nflxsearch.net nflxso.net nflxvideo.net]
2026/04/07 09:57:48 magicsock: SetPrivateKey called (init)
2026/04/07 09:57:48 wgengine: Reconfig: configuring userspace WireGuard config (with 3/22 peers)
2026/04/07 09:57:48 wgengine: Reconfig: configuring router
2026/04/07 09:57:48 monitor: RTM_NEWROUTE: src=, dst=192.168.50.0/24, gw=, outif=16, table=52
2026/04/07 09:57:48 monitor: RTM_NEWROUTE: src=, dst=192.168.1.0/24, gw=, outif=16, table=52
2026/04/07 09:57:48 router: enabling connmark-based rp_filter workaround
2026/04/07 09:57:48 router: warning: failed to add connmark rules (rp_filter workaround may not work): adding [-m conntrack --ctstate ESTABLISHED,RELATED -j CONNMARK --restore-mark --nfmask 0xff0000 --ctmask 0xff0000] in mangle/PREROUTING: running [/usr/sbin/iptables -t mangle -I PREROUTING 1 -m conntrack --ctstate ESTABLISHED,RELATED -j CONNMARK --restore-mark --nfmask 0xff0000 --ctmask 0xff0000 --wait]: exit status 2: Warning: Extension CONNMARK revision 0 not supported, missing kernel module?
iptables v1.8.11 (nf_tables): unknown option "--nfmask"
Try `iptables -h' or 'iptables --help' for more information.
2026/04/07 09:57:48 peerapi: serving on http://<redacted IPv4>:47999
2026/04/07 09:57:48 peerapi: serving on http://[<redacted IPv6>]:58078
2026/04/07 09:57:48 health(warnable=router): error: enabling connmark rules: adding [-m conntrack --ctstate ESTABLISHED,RELATED -j CONNMARK --restore-mark --nfmask 0xff0000 --ctmask 0xff0000] in mangle/PREROUTING: running [/usr/sbin/iptables -t mangle -I PREROUTING 1 -m conntrack --ctstate ESTABLISHED,RELATED -j CONNMARK --restore-mark --nfmask 0xff0000 --ctmask 0xff0000 --wait]: exit status 2: Warning: Extension CONNMARK revision 0 not supported, missing kernel module?
iptables v1.8.11 (nf_tables): unknown option "--nfmask"
Try `iptables -h' or 'iptables --help' for more information.
2026/04/07 09:57:48 appc: handling domains: [disney.images.edge.bamgrid.com netflix.com.edgesuite.net disney-plus.net nflxsearch.net cdn.registerdisney.go.com disneyplus.com nflxext.com netflix.com nflximg.com nflximg.net nflxso.net nflxvideo.net] and wildcards: [disney-plus.net disneyplus.com netflix.com netflix.com.edgesuite.net nflxext.com nflximg.com nflximg.net nflxsearch.net nflxso.net nflxvideo.net]
2026/04/07 09:57:48 monitor: RTM_NEWROUTE: src=, dst=192.168.8.0/24, gw=, outif=16, table=52
2026/04/07 09:57:48 portmapper: UPnP meta changed: [{Location:http://192.168.1.254:5431/dyndev/uuid:<redacted> Server:Custom/1.0 UPnP/1.0 Proc/Ver USN:uuid:<redacted>::urn:schemas-upnp-org:device:InternetGatewayDevice:1}]
2026/04/07 09:57:48 portmapper: saw UPnP type WANIPConnection1 at http://192.168.1.254:5431/dyndev/uuid:<redacted>; Actiontec xDSL Router (Actiontec), method=single
2026/04/07 09:57:49 wgengine: Reconfig: configuring userspace WireGuard config (with 4/22 peers)
2026/04/07 09:57:49 magicsock: adding connection to derp-10 for [/81VF]
2026/04/07 09:57:49 magicsock: 1 active derp conns: derp-10=cr0s,wr0s
2026/04/07 09:57:49 derphttp.Client.Connect: connecting to derp-10 (sea)
2026/04/07 09:57:49 magicsock: disco: node [/81VF] d:90a1cae3fd450406 now using [2001:569:50de:8e00:be24:11ff:fec0:9d10]:43500 mtu=1360 tx=2402d2a2ea16
2026/04/07 09:57:49 magicsock: disco: node [/81VF] d:90a1cae3fd450406 now using 192.168.1.80:33974 mtu=1360 tx=e2bee4b06455
2026/04/07 09:57:49 Switching ipn state Starting -> Running (WantRunning=true, nm=true)
2026/04/07 09:57:49 health(warnable=warming-up): ok
2026/04/07 09:57:49 magicsock: derp-10 connected; connGen=1
2026/04/07 09:57:49 magicsock: disco: node [/81VF] d:90a1cae3fd450406 now using [2001:569:50de:8e00:be24:11ff:fec0:9d10]:43500 mtu=1360 tx=0c6f64e871b0
2026/04/07 09:57:49 wgengine: Reconfig: configuring userspace WireGuard config (with 5/22 peers)
Warning: IPv6 forwarding is disabled.
Subnet routes and exit nodes may not work correctly.
See https://tailscale.com/s/ip-forwarding
2026/04/07 09:57:49 magicsock: disco: node [/IBxY] d:f83648eda7f0717f now using 192.168.1.91:41641 mtu=1360 tx=aa9c792031e2
2026/04/07 09:57:50 localapi: [PATCH] /localapi/v0/prefs
2026/04/07 09:57:50 EditPrefs: MaskedPrefs{ControlURL="https://controlplane.tailscale.com" RouteAll=true ExitNodeID="" ExitNodeIP=invalid IP AutoExitNode="" InternalExitNodePrior="" ExitNodeAllowLANAccess=false CorpDNS=true WantRunning=true AdvertiseTags=[] Hostname="home-assistant" AdvertiseRoutes=[0.0.0.0/0 ::/0 192.168.1.0/24] NoSNAT=false NoStatefulFiltering="true" AppConnector={Advertise:true}}
2026/04/07 09:57:50 appc: handling domains: [nflxvideo.net disney-plus.net disney.images.edge.bamgrid.com netflix.com nflxext.com nflxso.net cdn.registerdisney.go.com disneyplus.com netflix.com.edgesuite.net nflximg.com nflximg.net nflxsearch.net] and wildcards: [disney-plus.net disneyplus.com netflix.com netflix.com.edgesuite.net nflxext.com nflximg.com nflximg.net nflxsearch.net nflxso.net nflxvideo.net]
2026/04/07 09:57:50 wgengine: Reconfig: configuring router
2026/04/07 09:57:50 router: enabling connmark-based rp_filter workaround
2026/04/07 09:57:50 router: warning: failed to add connmark rules (rp_filter workaround may not work): adding [-m conntrack --ctstate ESTABLISHED,RELATED -j CONNMARK --restore-mark --nfmask 0xff0000 --ctmask 0xff0000] in mangle/PREROUTING: running [/usr/sbin/iptables -t mangle -I PREROUTING 1 -m conntrack --ctstate ESTABLISHED,RELATED -j CONNMARK --restore-mark --nfmask 0xff0000 --ctmask 0xff0000 --wait]: exit status 2: Warning: Extension CONNMARK revision 0 not supported, missing kernel module?
iptables v1.8.11 (nf_tables): unknown option "--nfmask"
[09:57:50] INFO: Tailscale is running
[09:57:51] WARNING: Currently the following subnets are both present as local subnets and are also routed within your tailnet to other nodes!
[09:57:51] WARNING: Please reconfigure your subnet routing within your tailnet to prevent current or future collisions.
[09:57:51] WARNING:   192.168.1.0/24
s6-rc: info: service post-tailscaled successfully started
s6-rc: info: service taildrive: starting
s6-rc: info: service mss-clamping: starting
s6-rc: info: service magicdns-ingress-proxy: starting
[09:57:51] INFO: Starting MagicDNS ingress proxy...
[09:57:51] INFO: Clamping the MSS to the MTU for interface tailscale0, to support site-to-site networking better (IPv4)
[09:57:51] INFO: Clamping the MSS to the MTU for interface tailscale0, to support site-to-site networking better (IPv6)
s6-rc: info: service mss-clamping successfully started
s6-rc: info: service taildrive successfully started
[09:57:51] INFO: Setting up forwarding for MagicDNS ingress proxy (udp, IPv4, DNS)
[09:57:51] INFO: Setting up forwarding for MagicDNS ingress proxy (tcp, IPv4, DNS)
[09:57:51] INFO: Setting up forwarding for MagicDNS ingress proxy (udp, IPv4, Supervisor)
[09:57:51] INFO: Setting up forwarding for MagicDNS ingress proxy (tcp, IPv4, Supervisor)
[09:57:51] INFO: Removing drop for MagicDNS ingress proxy (tcp, IPv4, DNS)
[09:57:51] INFO: Removing drop for MagicDNS ingress proxy (udp, IPv4, DNS)
[09:57:51] INFO: Removing drop for MagicDNS ingress proxy (tcp, IPv4, Supervisor)
[09:57:51] INFO: Removing drop for MagicDNS ingress proxy (udp, IPv4, Supervisor)
s6-rc: info: service magicdns-ingress-proxy successfully started
s6-rc: info: service forwarding: starting
dnsmasq[738]: started, version 2.91 cache disabled
dnsmasq[738]: compile time options: IPv6 GNU-getopt no-DBus no-UBus no-i18n no-IDN DHCP DHCPv6 no-Lua TFTP no-conntrack ipset no-nftset auth no-DNSSEC loop-detect inotify dumpfile
dnsmasq[738]: using nameserver 100.100.100.100#53
dnsmasq[738]: using only locally-known addresses for acme-v02.api.letsencrypt.org
dnsmasq[738]: using only locally-known addresses for controlplane.tailscale.com
[09:57:51] INFO: Forwarding incoming tailnet connections directed to <redacted IPv4> to the host's 192.168.1.83 address (IPv4)
s6-rc: info: service forwarding successfully started
s6-rc: info: service legacy-services: starting
s6-rc: info: service legacy-services successfully started
Try `iptables -h' or 'iptables --help' for more information.
2026/04/07 09:57:53 wgengine: idle peer [dNDgQ] now active, reconfiguring WireGuard
2026/04/07 09:57:53 wgengine: Reconfig: configuring userspace WireGuard config (with 6/22 peers)
2026/04/07 09:57:53 Drop: TCP{<redacted IPv4>:58073 > <redacted IPv4>:47999} 64 no rules matched
2026/04/07 09:57:53 Drop: TCP{<redacted IPv4>:58072 > <redacted IPv4>:47999} 64 no rules matched
2026/04/07 09:57:53 [RATELIMIT] format("%s: %s %d %s\n%s")
2026/04/07 09:57:53 netstack: decrementing connsInFlightByClient[<redacted IPv4>] because the packet was not handled; new value is 3
2026/04/07 09:57:53 netstack: decrementing connsInFlightByClient[<redacted IPv4>] because the packet was not handled; new value is 5
2026/04/07 09:57:53 netcheck: DetectCaptivePortal(found=false)
2026/04/07 09:57:53 magicsock: home DERP changing from derp-0 [0ms] to derp-13 [46ms]
2026/04/07 09:57:53 magicsock: home is now derp-13 (den)
2026/04/07 09:57:53 magicsock: adding connection to derp-13 for home-keep-alive
2026/04/07 09:57:53 magicsock: 2 active derp conns: derp-10=cr4s,wr48ms derp-13=cr0s,wr0s
2026/04/07 09:57:53 derphttp.Client.Recv: connecting to derp-13 (den)
2026/04/07 09:57:53 control: NetInfo: NetInfo{varies=false ipv6=true ipv6os=true udp=true icmpv4=false derp=#13 portmap=active-U link="" firewallmode="ipt-default"}
2026/04/07 09:57:53 magicsock: endpoints changed: <redacted IPv4>:24706 (portmap), <redacted IPv4>:47097 (stun), [2001:569:50de:8e00:7f36:3b73:2254:1398]:57838 (stun), 172.30.32.1:47097 (local), 172.30.232.1:47097 (local), 192.168.1.83:47097 (local), [2001:569:50de:8e00:7f36:3b73:2254:1398]:47097 (local)
2026/04/07 09:57:53 magicsock: home DERP changing from derp-13 [52ms] to derp-10 [29ms]
2026/04/07 09:57:53 magicsock: home is now derp-10 (sea)
2026/04/07 09:57:53 control: NetInfo: NetInfo{varies=false ipv6=true ipv6os=true udp=true icmpv4=false derp=#10 portmap=active-U link="" firewallmode="ipt-default"}
2026/04/07 09:57:53 health(warnable=no-derp-connection): ok
2026/04/07 09:57:53 magicsock: derp-13 connected; connGen=1
2026/04/07 09:57:54 magicsock: disco: node [dNDgQ] d:<redacted> now using <redacted IPv4>:41641 mtu=1360 tx=1fb8613d7b15
2026/04/07 09:57:55 magicsock: disco: node [LVS5d] d:<redacted> now using <redacted IPv4>:1720 mtu=1360 tx=53dc7f3909a5
2026/04/07 09:57:58 LinkChange: major, rebinding: old: interfaces.State{defaultRoute=enp0s18 ifs={docker0:[172.30.232.1/23 llu6] enp0s18:[192.168.1.83/24 <redacted IPv6>:1398/64 llu6] hassio:[172.30.32.1/23 llu6]} v4=true v6=true} new: interfaces.State{defaultRoute=enp0s18 ifs={docker0:[172.30.232.1/23 llu6] enp0s18:[192.168.1.83/24 <redacted IPv6>:1398/64 llu6] hassio:[172.30.32.1/23 llu6] tailscale0:[<redacted IPv4>/32 <redacted IPv6>/128 llu6]} v4=true v6=true}
2026/04/07 09:57:58 dns: Set: {DefaultResolvers:[] Routes:{<redacted>.ts.net.:[] ts.net.:[199.247.155.53 2620:111:8007::53]}+65arpa SearchDomains:[<redacted>.ts.net.] Hosts:23}
2026/04/07 09:57:58 dns: Resolvercfg: {Routes:{.:[127.100.100.100] ts.net.:[199.247.155.53 2620:111:8007::53]} Hosts:23 LocalDomains:[<redacted>.ts.net.]+65arpa}
2026/04/07 09:57:58 dns: OScfg: {Nameservers:[100.100.100.100 fd7a:115c:a1e0::53] SearchDomains:[<redacted>.ts.net.] }
2026/04/07 09:57:58 rename of "/etc/resolv.conf" to "/etc/resolv.pre-tailscale-backup.conf" failed (rename /etc/resolv.conf /etc/resolv.pre-tailscale-backup.conf: device or resource busy), falling back to copy+delete
2026/04/07 09:57:58 wgengine: set DNS config again after major link change
2026/04/07 09:57:58 router: portUpdate(port=57838, network=udp6)
2026/04/07 09:57:58 Rebind; defIf="enp0s18", ips=[192.168.1.83/24 <redacted IPv6>/64 <redacted IPv6>/64]
2026/04/07 09:57:58 router: portUpdate(port=47097, network=udp4)
2026/04/07 09:57:58 magicsock: 2 active derp conns: derp-10=cr9s,wr5s derp-13=cr5s,wr5s
2026/04/07 09:57:58 post-rebind ping of DERP region 10 okay
2026/04/07 09:57:58 post-rebind ping of DERP region 13 okay
2026/04/07 09:57:59 magicsock: disco: node [dNDgQ] d:<redacted> now using <redacted IPv4> mtu=1360 tx=1b32834a0739
2026/04/07 09:58:00 [RATELIMIT] format("%s: %s %d %s\n%s") (8 dropped)
2026/04/07 09:58:00 Drop: TCP{<redacted IPv4>:58090 > <redacted IPv4>:47999} 64 no rules matched
2026/04/07 09:58:00 [RATELIMIT] format("%s: %s %d %s\n%s")
2026/04/07 09:58:01 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=f8a822ac4391
2026/04/07 09:58:01 magicsock: disco: node [LVS5d] d:<redacted> now using <redacted IPv4>:1297 mtu=1360 tx=073334236cc6
2026/04/07 09:58:01 magicsock: disco: node [/IBxY] d:<redacted> now using [<redacted IPv6>]:41641 mtu=1360 tx=b4b700904755
2026/04/07 09:58:01 magicsock: disco: node [/IBxY] d:<redacted> now using 192.168.1.91:41641 mtu=1360 tx=64000e1fd6f4
2026/04/07 09:59:04 magicsock: closing connection to derp-13 (idle), age 1m11s
2026/04/07 09:59:04 magicsock: 1 active derp conns: derp-10=cr1m0s,wr3s
2026/04/07 09:59:50 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=673603b20054
2026/04/07 09:59:50 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=dc8952369d1e
2026/04/07 10:00:51 open-conn-track: flow TCP <redacted IPv4>:51072 > 192.168.50.60:15847 rejected due to acl
2026/04/07 10:00:52 open-conn-track: flow TCP <redacted IPv4>:51072 > 192.168.50.60:15847 rejected due to acl
2026/04/07 10:00:53 open-conn-track: flow TCP <redacted IPv4>:51072 > 192.168.50.60:15847 rejected due to acl
2026/04/07 10:00:54 open-conn-track: flow TCP <redacted IPv4>:51072 > 192.168.50.60:15847 rejected due to acl
2026/04/07 10:00:55 open-conn-track: flow TCP <redacted IPv4>:51072 > 192.168.50.60:15847 rejected due to acl
2026/04/07 10:00:55 [RATELIMIT] format("open-conn-track: flow %v %v > %v rejected due to %v")
2026/04/07 10:01:01 [RATELIMIT] format("open-conn-track: flow %v %v > %v rejected due to %v") (6 dropped)
2026/04/07 10:01:01 open-conn-track: flow TCP <redacted IPv4>:54360 > 192.168.50.60:15847 rejected due to acl
2026/04/07 10:01:02 open-conn-track: flow TCP <redacted IPv4>:34238 > 192.168.50.60:15847 rejected due to acl
2026/04/07 10:01:02 [RATELIMIT] format("open-conn-track: flow %v %v > %v rejected due to %v")
2026/04/07 10:01:53 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=d6b2c38aeadc
2026/04/07 10:01:53 magicsock: disco: node [dNDgQ] d:<redacted> now using <redacted IPv4>:41641 mtu=1360 tx=2857c94e5777
2026/04/07 10:02:03 magicsock: disco: node [dNDgQ] d:<redacted> now using <redacted IPv4>:1297 mtu=1360 tx=557a94986ab9
2026/04/07 10:03:01 magicsock: disco: node [LVS5d] d:<redacted> now using <redacted IPv4>:1720 mtu=1360 tx=d4a10933dfd8
2026/04/07 10:03:56 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=8b49590301a9
2026/04/07 10:04:57 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=fc47b612be47
2026/04/07 10:04:57 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=2823ed443f61
2026/04/07 10:05:59 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=77d2125fa7dd
2026/04/07 10:08:02 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=258b56ef86df
2026/04/07 10:09:03 wgengine: Reconfig: configuring userspace WireGuard config (with 5/22 peers)
2026/04/07 10:09:03 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=c62cb89c8e2e
2026/04/07 10:09:03 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=1ff3d134faa1
2026/04/07 10:10:04 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=1205d5bd699c
2026/04/07 10:10:31 tkaSyncIfNeeded: isEnabled=true, wantEnabled=true, head=<redacted>
2026/04/07 10:10:31 netmap: suggested exit node: <redacted>
2026/04/07 10:10:31 appc: handling domains: [netflix.com.edgesuite.net nflxext.com cdn.registerdisney.go.com netflix.com nflximg.net nflxsearch.net nflxso.net nflxvideo.net disney-plus.net disney.images.edge.bamgrid.com disneyplus.com nflximg.com] and wildcards: [disney-plus.net disneyplus.com netflix.com netflix.com.edgesuite.net nflxext.com nflximg.com nflximg.net nflxsearch.net nflxso.net nflxvideo.net]
2026/04/07 10:10:31 wgengine: Reconfig: [CL+zM] changed from "discokey:<redacted>" to "discokey:<redacted>"
2026/04/07 10:10:31 tkaSyncIfNeeded: isEnabled=true, wantEnabled=true, head=<redacted>
2026/04/07 10:10:31 netmap: suggested exit node: <redacted>
2026/04/07 10:10:31 appc: handling domains: [cdn.registerdisney.go.com disney-plus.net nflxvideo.net disney.images.edge.bamgrid.com netflix.com nflximg.net nflxsearch.net disneyplus.com nflxext.com netflix.com.edgesuite.net nflximg.com nflxso.net] and wildcards: [disney-plus.net disneyplus.com netflix.com netflix.com.edgesuite.net nflxext.com nflximg.com nflximg.net nflxsearch.net nflxso.net nflxvideo.net]
2026/04/07 10:11:06 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=982d2df28b69
2026/04/07 10:12:07 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=a5c8b90f1e9a
2026/04/07 10:13:09 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=31576c868879
2026/04/07 10:15:12 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=5808d1405d74
2026/04/07 10:16:13 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=308cd3bbee8c
2026/04/07 10:17:01 magicsock: disco: node [LVS5d] d:<redacted> now using <redacted IPv4>:1297 mtu=1360 tx=70cf1fada02e
2026/04/07 10:17:14 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=2518634ae9f1
2026/04/07 10:18:16 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=8e559268a211
2026/04/07 10:19:17 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=ed739a655656
2026/04/07 10:19:59 localapi: [POST] /localapi/v0/upload-client-metrics
2026/04/07 10:19:59 localapi: [POST] /localapi/v0/upload-client-metrics
2026/04/07 10:19:59 localapi: [POST] /localapi/v0/debug-packet-filter-rules
2026/04/07 10:20:05 localapi: [POST] /localapi/v0/upload-client-metrics
2026/04/07 10:20:23 wgengine: idle peer [dNDgQ] now active, reconfiguring WireGuard
2026/04/07 10:20:23 wgengine: Reconfig: configuring userspace WireGuard config (with 6/22 peers)
2026/04/07 10:20:23 magicsock: disco: node [dNDgQ] d:<redacted> now using <redacted IPv4>:41641 mtu=1360 tx=02add3f5b747
2026/04/07 10:20:23 Drop: TCP{<redacted IPv4>:59936 > <redacted IPv4>:47999} 64 no rules matched
2026/04/07 10:20:23 Drop: TCP{<redacted IPv4>:59937 > <redacted IPv4>:47999} 64 no rules matched
2026/04/07 10:21:01 magicsock: disco: node [LVS5d] d:<redacted> now using <redacted IPv4>:1720 mtu=1360 tx=c38aba364668
2026/04/07 10:21:20 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=fa28b954e6ef
2026/04/07 10:22:22 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=384e1d80b48a
2026/04/07 10:23:23 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=2acc134461b8
2026/04/07 10:24:25 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=91e71d1e89c3
2026/04/07 10:25:26 magicsock: disco: node [/81VF] d:<redacted> now using [<redacted IPv6>]:43500 mtu=1360 tx=47835f3ad515
2026/04/07 10:26:27 magicsock: disco: node [/81VF] d:<redacted> now using 192.168.1.80:33974 mtu=1360 tx=c773ce3c2507
2026/04/07 10:27:29 wgengine: Reconfig: configuring userspace WireGuard config (with 5/22 peers)
[further tailscaled logs suppressed, set app's configuration option 'log_level' to 'debug' to see further tailscaled logs]

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions