This machine is misconfigured and cannot relay traffic (exit node false positive)
Fixes the Tailscale admin console wrongly reporting 'This machine is misconfigured and cannot relay traffic' or 'This machine has IP forwarding disabled' on exit nodes that actually work. Use when the console shows the warning badge but ip_forward is enabled and client traffic relays fine. Covers the restart and route-toggle workarounds confirmed by Tailscale staff. Not for exit nodes that genuinely cannot relay.
Fix "This machine is misconfigured and cannot relay traffic" (false positive)
TL;DR: The console is lying: your exit node is fine, but it reported its forwarding state before you enabled IP forwarding. Restart Tailscale (or toggle the advertised routes) so it re-reports, and the badge clears.
The error
This machine is misconfigured and cannot relay traffic.
This machine has IP forwarding disabled and cannot relay traffic.Shown in the admin console machines list and in Edit route settings, with an Exit Node ! badge, even though traffic relays fine.
Fix it
1. Confirm it is the false positive
sysctl net.ipv4.ip_forward net.ipv6.conf.all.forwarding
tailscale statusExpected: both sysctls are 1, and a client test through the exit node works. If forwarding is actually 0, just enable it persistently and skip to step 3.
2. Restart Tailscale so it re-reports
sudo systemctl restart tailscaledExpected: on the next MapRequest the client reports forwarding correctly and the console clears the badge within a few minutes.
3. If the badge sticks, toggle the advertised routes
In the admin console, open the machine's Edit route settings, uncheck "Use as exit node", save, then re-check it and save again. Or from the CLI:
sudo tailscale up --advertise-exit-node=false
sudo tailscale up --advertise-exit-nodeExpected: the route state refreshes and the warning disappears.
4. Or just wait
The forwarding state also refreshes on disco key rotation. If nothing is actually broken, the badge can clear on its own.
When this applies
- Console says misconfigured / IP forwarding disabled
sysctlshows forwarding enabled- Real exit-node traffic works
- You enabled the exit-node flag before enabling IP forwarding
When it does not apply
- Forwarding is actually disabled (enable it:
sysctl -w net.ipv4.ip_forward=1plus persistent config) - Clients genuinely cannot reach the internet through the node (real misconfiguration)
- The node never advertised exit routes at all
Tool compatibility
Tailscale 1.9x on Linux. The control-side fix was merged; the client-side refresh behavior ships in later 1.9x.
Variant phrasings
Exit Node ! badge with "Unable to relay traffic" in route settings
Same false positive, seen in the Edit route settings panel. Same fix.
Why it happens
The client detects IP forwarding once, when it sends its MapRequest to the control server. If you flipped the exit-node flag first and enabled forwarding after, the control plane kept the stale "disabled" reading until something forced a fresh report.
Edge cases
- Order matters on new builds: enable IP forwarding BEFORE first advertising the exit node to avoid this entirely.
- Persistent sysctl: set
net.ipv4.ip_forward=1in/etc/sysctl.confor a drop-in so a reboot does not reintroduce the real version of this warning. - API says fine, UI says broken: trust the API route state plus a live traffic test over the console badge.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.