tailscale exit node not routing traffic for corporate users
Fixes Tailscale exit node not routing traffic for corporate users: exit node approval, ACLs, and client settings. Use when users select the exit node but traffic does not route. Not for general Tailscale connectivity.
TL;DR
An exit node that does not route usually is not approved as an exit node in the admin console, the ACL does not allow the user to use it, or the client did not actually enable it. Check approval, ACLs, and the client's exit-node setting in that order.
The query
tailscale exit node not routing traffic for corporate usersUse this when
- user selects the exit node but public IP does not change
- exit node works for some users but not others
- new exit node that never routed
Not for
- Tailscale devices not connecting to each other at all
- subnet router issues (different feature)
- non-corporate personal tailnets
Steps
- In the Tailscale admin console, confirm the device is approved to act as an exit node. Expected output: exit node approved
- Check the ACL: the user must be allowed to use exit nodes, typically through an autoApprovers or grants rule. Expected output: ACL permits exit node use for the user
- On the client, confirm the exit node is actually selected and not just available. Expected output: client shows the exit node active
- Check the exit node machine allows IP forwarding and its firewall permits the traffic. Expected output: forwarding and firewall correct
- Have the user check their public IP to confirm routing. Expected output: public IP matches the exit node
- If DNS leaks, confirm the exit node DNS settings in the admin console. Expected output: DNS resolves through the intended path
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_oRH6n8xpRImHtuTIjY0IDA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.