tailscale node shows offline but the machine is on
Fixes Tailscale nodes that report offline while the machine is powered on. Covers the tailscaled service state, expired keys, firewall and UDP issues, and admin console actions. Use when a device is unreachable on the tailnet but reachable by other means. Not for initial Tailscale install or exit-node routing problems.
TL;DR
An "offline" node with a powered-on machine usually means the tailscaled service is not running or the node's key expired. Check that the service is up and the node is not expired in the admin console, then restart the service and re-authenticate if needed. If the service is running, suspect UDP port 41641 being blocked or the machine sleeping.
What "offline" looks like
Status: offline (last seen 2 days ago)Steps
- Confirm the machine is truly awake (ping it, or check via another remote tool). Expected: the machine responds. Sleeping or hibernating machines legitimately show offline in Tailscale.
- Check the node in the Tailscale admin console: Machines > the node. Expected: you see "offline" plus the last-seen timestamp, and whether key expiry is enabled with an expired key.
- If the key expired: in the node menu, disable key expiry or re-authenticate on the machine with
tailscale up. Expected: the node shows online within a minute. Expired keys are the most common cause in fleets with expiry enabled. - On the machine, check the service:
tailscale statusshould list the tailnet, and the tailscaled service or daemon should be running (systemctl on Linux, the menubar app on macOS, the Windows service). Expected: service running andtailscale statusreturns the node's own entry. Restart the service if it is stopped. - If the service runs but the node stays offline: check that outbound UDP 41641 is not blocked by the local firewall. Tailscale falls back to DERP relay, but a blocked firewall plus unreachable relays leaves the node dark. Expected:
tailscale netcheckshows a working relay path. - Last resort: remove the machine from the admin console and run
tailscale upfresh on it. Expected: a new node entry appears online. This clears corrupted local state.
Use this when
- The Tailscale admin console shows a node offline but the machine is on
- A device is reachable by IP or RDP but not over the tailnet
- Nodes go offline after a key-expiry window passes
Not for this skill when
- First-time Tailscale installation (enrollment, not recovery)
- Exit node or subnet router routing problems (the node is online, the traffic is wrong)
- The machine is actually asleep, off, or has no network (fix that first)
Compatibility
- Tailscale clients on Windows, macOS, Linux, iOS, Android; admin console
Variants
Node flaps online and offline every few minutes
Usually aggressive power saving killing the network, or another VPN client fighting Tailscale for the default route. Check sleep settings and other VPN software.
Offline only on one network (office vs home)
The office firewall is blocking Tailscale's UDP or the DERP relays. Compare tailscale netcheck output on both networks.
Why it happens
"Offline" in the admin console means the coordination server has not heard from the node, not that the machine is dead. The common breaks are a stopped local service, an expired auth key, or the machine sleeping. The console cannot distinguish these, so you check them in order.
Edge cases
- Docker containers running tailscaled need the container kept alive; a restarted container without persistent state re-registers as a new node.
- Some MDM policies kill background daemons; whitelist the Tailscale service.
- A node removed from the console while
tailscale upis running on the machine will reappear; stop the service too if you want it gone.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_VodAfW3hsgiCQQT6XSIuNw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.