# Fix "This machine is misconfigured and cannot relay traffic" (false positive)

**TL;DR:** The console is lying: your exit node is fine, but it reported its forwarding state before you enabled IP forwarding. Restart Tailscale (or toggle the advertised routes) so it re-reports, and the badge clears.

## The error

```text
This machine is misconfigured and cannot relay traffic.
This machine has IP forwarding disabled and cannot relay traffic.
```

Shown in the admin console machines list and in Edit route settings, with an `Exit Node !` badge, even though traffic relays fine.

## Fix it

### 1. Confirm it is the false positive

```
sysctl net.ipv4.ip_forward net.ipv6.conf.all.forwarding
tailscale status
```

Expected: both sysctls are 1, and a client test through the exit node works. If forwarding is actually 0, just enable it persistently and skip to step 3.

### 2. Restart Tailscale so it re-reports

```
sudo systemctl restart tailscaled
```

Expected: on the next MapRequest the client reports forwarding correctly and the console clears the badge within a few minutes.

### 3. If the badge sticks, toggle the advertised routes

In the admin console, open the machine's Edit route settings, uncheck "Use as exit node", save, then re-check it and save again. Or from the CLI:

```
sudo tailscale up --advertise-exit-node=false
sudo tailscale up --advertise-exit-node
```

Expected: the route state refreshes and the warning disappears.

### 4. Or just wait

The forwarding state also refreshes on disco key rotation. If nothing is actually broken, the badge can clear on its own.

## When this applies

- Console says misconfigured / IP forwarding disabled
- `sysctl` shows forwarding enabled
- Real exit-node traffic works
- You enabled the exit-node flag before enabling IP forwarding

## When it does not apply

- Forwarding is actually disabled (enable it: `sysctl -w net.ipv4.ip_forward=1` plus persistent config)
- Clients genuinely cannot reach the internet through the node (real misconfiguration)
- The node never advertised exit routes at all

## Tool compatibility

Tailscale 1.9x on Linux. The control-side fix was merged; the client-side refresh behavior ships in later 1.9x.

## Variant phrasings

### `Exit Node !` badge with "Unable to relay traffic" in route settings

Same false positive, seen in the Edit route settings panel. Same fix.

## Why it happens

The client detects IP forwarding once, when it sends its MapRequest to the control server. If you flipped the exit-node flag first and enabled forwarding after, the control plane kept the stale "disabled" reading until something forced a fresh report.

## Edge cases

- **Order matters on new builds:** enable IP forwarding BEFORE first advertising the exit node to avoid this entirely.
- **Persistent sysctl:** set `net.ipv4.ip_forward=1` in `/etc/sysctl.conf` or a drop-in so a reboot does not reintroduce the real version of this warning.
- **API says fine, UI says broken:** trust the API route state plus a live traffic test over the console badge.