I run a few GL routers at my kids' apartments, each pointed at a Pi 5 exit node at my house so they come out on my home IP. Been working for months.
Problem: on the AXT1800, the second I select the exit node, all internet dies — router and clients both. Clear the exit node and it's back instantly, no reboot. Same thing happened on a Slate 7 at a hotel on a completely different ISP.
Ruled out quite a bit from help from my friend Opus5, but still having some issues. The exit node itself is fine, my phone on a work guest wifi uses it and gets my home IP no problem. Not DNS (router's on 1.1.1.1/8.8.8.8 and accept-dns is off). Not MTU, it's 100% loss on 64-byte pings. Not relay vs direct.
What I think is happening:
AXT1800 on 4.8.3, Tailscale 1.80.3. nft list chain ip filter ts-forward gives me:
iifname "tailscale0*" meta mark set meta mark & 0xffff04ff | 0x00000400
That wipes 0x0000fb00, which includes 0x8000. GL uses 0x8000 in the 0xf000 nibble as its "allowed out the WAN" tag — shows up in uci show route_policy as mark='0x8000' and in ip rule at priority 6000. Lose that tag and you fall through to the blackhole rules at 9910/9920.
Opus/Perplexity found that this is Tailscale issue #11803, where the nftables backend writes marks 8 bits low from an endianness bug. In a forum, a GL staff confirmed the same mechanism over in the Flint 3 thread (68294) and said their dev submitted the fwmark patch to admon's updater.
Annoying part: AXT1800 is capped at 4.8.3, so it'll never get the native ts_killswitch rule at 5280 that the 4.9 devices have.
Things I'd love input on:
- Anyone actually running a Tailscale exit node on an AXT1800, or anything else stuck on 4.8.x? What does
nft list chain ip nat ts-postroutingshow for you,0x00ff0000or0x0000ff00? - Has anyone flipped
TS_DEBUG_FIREWALL_MODEfromautotoiptablesin/etc/init.d/tailscaleon 4.8.x? Myip nattable is nft-owned andiptables -t nat -Lerrors out, so I'm not sure that switch lands cleanly. - For admon's updater — which release are people ending up on that actually includes the GL fwmark patch, and does it stick across a reboot on 4.8.x?
The Slate Ax router is 500 miles away with GoodCloud as my only out-of-band, so I'd rather not find out the hard way…
Source: r/GlInet · by /u/indypharmd