tailscale / tailscale/tailscale

Subnet router working incorrectly when using the mobile and windows clients

Open
#21,306 0 comments 0 reactions 0 assignees View on GitHub
bug needs-triage
Dominant language
Go
Stars
36.5k
Forks
3.2k
Avg merge
2d 3h
Merged PRs (30d)
123

Description

### What is the issue?

Let's explain my configuration first.

I have a subnet router that advertises 192.168.0.0/24 for an easy access to my LAN from the "outside world". My ACL config allows everything because i'm the admin. Yet, for some reason, after the update 1.98.8 my printer stopped connecting to the phone, when i'm connected to mentioned above LAN via WiFi with Tailscale on.

After further investigation i found out, that several of my local IPs were totally inaccessible, despite them working perfectly before. I can access the same addresses from my desktop linux PC (with Tailscale enabled), and they see it as if i'm accessing them from my subnet router's local IP, which is how it's supposed to be.

Some local IPs do not work under any circumstances, but other local IPs are working as usual? What? The problem disappears after completely disabling Tailscale. I repeat, everything has worked perfectly fine throughout the year and the ACL config remained almost unchanged.

The same issue persists on my relative's phone, which is also a google pixel, just like mine. Same issue can also be observed on the windows tailscale app.

The IPs i cannot access, basically VMs, do not have any kind of firewall enabled. I could access them without any issues before, around one month ago. My relative has all ACL rules correctly set up, for them to access the needed IP address.

May be important (?) - the subnet router also functions as an exit node. It had not caused any issues before for a long long time, so i do not believe that it was the real issue.

I would be really happy it was a misconfiguration issue on my side, because i heavily rely on your service

### Steps to reproduce

1. Turn on a subnet router at 192.168.0.0/24
2. Be connected to the very same LAN, where both the subnet and the router are.
3. Try to access a service by it's local IP, for example a local website located at 192.168.0.125. Some local websites/services CAN be accessed, while some CANNOT be accessed, despite both being in the same subnet in the same LAN in the same NAT.
4. Turn off tailscale to actually access needed services or devices like printers, which makes tailscale usage extremely annoying for the admins, and literally unusable for the clients.

### Are there any recent changes that introduced the issue?

Started on version 1.98.8, the config remained identical

### OS

Android

### OS version

Graphene OS 2026091000

### Tailscale version

1.98.8 (after updating to 1.102.3 the issue persisted)

### Other software

Nothing that could cause conflict on the server, and literally nothing else on client devices

### Bug report

BUG-4ccf0f7e4acd4346eb4a02121d94a7839d2fb6061ab472a4a93df013c9d4e74e-20260915235014Z-6fdccd0149d31a9f

Contributor guide

Open the contributing guide

Research direction

Reproduce the issue with a subnet router advertising 192.168.0.0/24 while the client is on the same LAN, testing both Android and Windows with Tailscale enabled. Compare access to working and inaccessible local IPs, including 192.168.0.125, on versions 1.98.8 and 1.102.3; done means the affected services are reachable without disabling Tailscale.

Written by the indexing model from the issue text.

Assessment

Tech stack
android
Domain
networking
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.