## TL;DR
An "offline" node with a powered-on machine usually means the tailscaled service is not running or the node's key expired. Check that the service is up and the node is not expired in the admin console, then restart the service and re-authenticate if needed. If the service is running, suspect UDP port 41641 being blocked or the machine sleeping.

## What "offline" looks like
```text
Status: offline (last seen 2 days ago)
```

## Steps
1. Confirm the machine is truly awake (ping it, or check via another remote tool). Expected: the machine responds. Sleeping or hibernating machines legitimately show offline in Tailscale.
2. Check the node in the Tailscale admin console: Machines > the node. Expected: you see "offline" plus the last-seen timestamp, and whether key expiry is enabled with an expired key.
3. If the key expired: in the node menu, disable key expiry or re-authenticate on the machine with `tailscale up`. Expected: the node shows online within a minute. Expired keys are the most common cause in fleets with expiry enabled.
4. On the machine, check the service: `tailscale status` should list the tailnet, and the tailscaled service or daemon should be running (systemctl on Linux, the menubar app on macOS, the Windows service). Expected: service running and `tailscale status` returns the node's own entry. Restart the service if it is stopped.
5. If the service runs but the node stays offline: check that outbound UDP 41641 is not blocked by the local firewall. Tailscale falls back to DERP relay, but a blocked firewall plus unreachable relays leaves the node dark. Expected: `tailscale netcheck` shows a working relay path.
6. Last resort: remove the machine from the admin console and run `tailscale up` fresh on it. Expected: a new node entry appears online. This clears corrupted local state.

## Use this when
- The Tailscale admin console shows a node offline but the machine is on
- A device is reachable by IP or RDP but not over the tailnet
- Nodes go offline after a key-expiry window passes

## Not for this skill when
- First-time Tailscale installation (enrollment, not recovery)
- Exit node or subnet router routing problems (the node is online, the traffic is wrong)
- The machine is actually asleep, off, or has no network (fix that first)

## Compatibility
- Tailscale clients on Windows, macOS, Linux, iOS, Android; admin console

## Variants
### Node flaps online and offline every few minutes
Usually aggressive power saving killing the network, or another VPN client fighting Tailscale for the default route. Check sleep settings and other VPN software.
### Offline only on one network (office vs home)
The office firewall is blocking Tailscale's UDP or the DERP relays. Compare `tailscale netcheck` output on both networks.

## Why it happens
"Offline" in the admin console means the coordination server has not heard from the node, not that the machine is dead. The common breaks are a stopped local service, an expired auth key, or the machine sleeping. The console cannot distinguish these, so you check them in order.

## Edge cases
- Docker containers running tailscaled need the container kept alive; a restarted container without persistent state re-registers as a new node.
- Some MDM policies kill background daemons; whitelist the Tailscale service.
- A node removed from the console while `tailscale up` is running on the machine will reappear; stop the service too if you want it gone.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_VodAfW3hsgiCQQT6XSIuNw
