VectleSkillsThis machine is misconfigured and cannot relay traffic (exit node false positive)

This machine is misconfigured and cannot relay traffic (exit node false positive)

Export

Fixes the Tailscale admin console wrongly reporting 'This machine is misconfigured and cannot relay traffic' or 'This machine has IP forwarding disabled' on exit nodes that actually work. Use when the console shows the warning badge but ip_forward is enabled and client traffic relays fine. Covers the restart and route-toggle workarounds confirmed by Tailscale staff. Not for exit nodes that genuinely cannot relay.

Fix "This machine is misconfigured and cannot relay traffic" (false positive)

TL;DR: The console is lying: your exit node is fine, but it reported its forwarding state before you enabled IP forwarding. Restart Tailscale (or toggle the advertised routes) so it re-reports, and the badge clears.

The error

This machine is misconfigured and cannot relay traffic.
This machine has IP forwarding disabled and cannot relay traffic.

Shown in the admin console machines list and in Edit route settings, with an Exit Node ! badge, even though traffic relays fine.

Fix it

1. Confirm it is the false positive

sysctl net.ipv4.ip_forward net.ipv6.conf.all.forwarding
tailscale status

Expected: both sysctls are 1, and a client test through the exit node works. If forwarding is actually 0, just enable it persistently and skip to step 3.

2. Restart Tailscale so it re-reports

sudo systemctl restart tailscaled

Expected: on the next MapRequest the client reports forwarding correctly and the console clears the badge within a few minutes.

3. If the badge sticks, toggle the advertised routes

In the admin console, open the machine's Edit route settings, uncheck "Use as exit node", save, then re-check it and save again. Or from the CLI:

sudo tailscale up --advertise-exit-node=false
sudo tailscale up --advertise-exit-node

Expected: the route state refreshes and the warning disappears.

4. Or just wait

The forwarding state also refreshes on disco key rotation. If nothing is actually broken, the badge can clear on its own.

When this applies

  • Console says misconfigured / IP forwarding disabled
  • sysctl shows forwarding enabled
  • Real exit-node traffic works
  • You enabled the exit-node flag before enabling IP forwarding

When it does not apply

  • Forwarding is actually disabled (enable it: sysctl -w net.ipv4.ip_forward=1 plus persistent config)
  • Clients genuinely cannot reach the internet through the node (real misconfiguration)
  • The node never advertised exit routes at all

Tool compatibility

Tailscale 1.9x on Linux. The control-side fix was merged; the client-side refresh behavior ships in later 1.9x.

Variant phrasings

Exit Node ! badge with "Unable to relay traffic" in route settings

Same false positive, seen in the Edit route settings panel. Same fix.

Why it happens

The client detects IP forwarding once, when it sends its MapRequest to the control server. If you flipped the exit-node flag first and enabled forwarding after, the control plane kept the stale "disabled" reading until something forced a fresh report.

Edge cases

  • Order matters on new builds: enable IP forwarding BEFORE first advertising the exit node to avoid this entirely.
  • Persistent sysctl: set net.ipv4.ip_forward=1 in /etc/sysctl.conf or a drop-in so a reboot does not reintroduce the real version of this warning.
  • API says fine, UI says broken: trust the API route state plus a live traffic test over the console badge.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=This+machine+is+misconfigured+and+cannot+relay+traffic+%28exit+node+false+positive%29&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.