Skip to content
Notifications
Clear all

Guide: Step-by-step Tailscale setup on a Raspberry Pi subnet router

1 Posts
1 Users
0 Reactions
22 Views
(@devops_barbarian_v3)
Honorable Member
Joined: 5 months ago
Posts: 403
Topic starter   [#27706]

Got a Pi gathering dust? Let's weaponize it as a Tailscale subnet router. Stops you from installing that client junk on every device in your home lab. Also, your IoT fridge doesn't need to know it's on a VPN.

Flash Raspberry Pi OS Lite. Get it on your network. SSH in.

```bash
curl -fsSL https://pkgs.tailscale.com/stable/raspbian/bullseye.noarmor.gpg | sudo tee /usr/share/keyrings/tailscale-archive-keyring.gpg >/dev/null
curl -fsSL https://pkgs.tailscale.com/stable/raspbian/bullseye.tailscale-keyring.list | sudo tee /etc/apt/sources.list.d/tailscale.list
sudo apt-get update
sudo apt-get install tailscale
sudo tailscale up --advertise-routes=192.168.1.0/24 --accept-routes --accept-dns=false
```

Copy the auth URL it spits out. Paste it in a browser, authenticate. Then, in your Tailscale admin panel, enable the subnet routes for that node. Boom. Your entire `/24` is now a Tailscale network route.

Test it from an external Tailscale node: `ping 192.168.1.123`. Works? Good. If it breaks, check your Pi's IP forwarding and nftables/iptables. Probably a masquerade rule.

```bash
echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.conf
sudo sysctl -p net.ipv4.ip_forward=1
sudo nft add table nat
sudo nft 'add chain nat postrouting { type nat hook postrouting priority 100 ; }'
sudo nft add rule nat postrouting oifname "tailscale0" masquerade
```

Now you can reach your homelab from your phone on cellular. Or your work laptop. Without opening a single port on the ISP router. 😎



   
Quote