Skip to content
DnsLister Forum

Where domain hunters compare notes

AXT1800 + Tailscale exit node = total internet loss. Think I found it (fwmark collision), want a sanity check.

I run a few GL routers at my kids' apartments, each pointed at a Pi 5 exit node at my house so they come out on my home IP. Been working for months.

Problem: on the AXT1800, the second I select the exit node, all internet dies — router and clients both. Clear the exit node and it's back instantly, no reboot. Same thing happened on a Slate 7 at a hotel on a completely different ISP.

Ruled out quite a bit from help from my friend Opus5, but still having some issues. The exit node itself is fine, my phone on a work guest wifi uses it and gets my home IP no problem. Not DNS (router's on 1.1.1.1/8.8.8.8 and accept-dns is off). Not MTU, it's 100% loss on 64-byte pings. Not relay vs direct.

What I think is happening:

AXT1800 on 4.8.3, Tailscale 1.80.3. nft list chain ip filter ts-forward gives me:

iifname "tailscale0*" meta mark set meta mark & 0xffff04ff | 0x00000400 

That wipes 0x0000fb00, which includes 0x8000. GL uses 0x8000 in the 0xf000 nibble as its "allowed out the WAN" tag — shows up in uci show route_policy as mark='0x8000' and in ip rule at priority 6000. Lose that tag and you fall through to the blackhole rules at 9910/9920.

Opus/Perplexity found that this is Tailscale issue #11803, where the nftables backend writes marks 8 bits low from an endianness bug. In a forum, a GL staff confirmed the same mechanism over in the Flint 3 thread (68294) and said their dev submitted the fwmark patch to admon's updater.

Annoying part: AXT1800 is capped at 4.8.3, so it'll never get the native ts_killswitch rule at 5280 that the 4.9 devices have.

Things I'd love input on:

  1. Anyone actually running a Tailscale exit node on an AXT1800, or anything else stuck on 4.8.x? What does nft list chain ip nat ts-postrouting show for you, 0x00ff0000 or 0x0000ff00?
  2. Has anyone flipped TS_DEBUG_FIREWALL_MODE from auto to iptables in /etc/init.d/tailscale on 4.8.x? My ip nat table is nft-owned and iptables -t nat -L errors out, so I'm not sure that switch lands cleanly.
  3. For admon's updater — which release are people ending up on that actually includes the GL fwmark patch, and does it stick across a reboot on 4.8.x?

The Slate Ax router is 500 miles away with GoodCloud as my only out-of-band, so I'd rather not find out the hard way…

Source: r/GlInet · by /u/indypharmd

Leave a Reply

Your email address will not be published. Required fields are marked *