Beryl 7 does not use TailScale exit node’s DNS

I’ve a Flint 2 as a home router. It runs Adguard Home and uses Unbound in recursive mode to resolve DNS. This all works brilliantly.

It’s also configured as an exit node in my TailNet, which has worked brilliantly for my phone. If I activate TailScale on my phone, it changes my IP to my home IP and correctly uses the Adguard Home/Unbound setup to resolve DNS.

I’ve now bought a Beryl 7 for travel. I’ve been able to add it to my TailNet and configure it to use my Flint 2 as an exit node. When I connect a device to the Beryl, it shows my IP as my home IP, but a DNS leak test shows that it is not using the Adguard Home/Unbound DNS resolver.

At this point, I’m at a loss to figure out why. Both the Flint and the Beryl are running software v4.9.0. Both have up-to-date TailScale. I do not have any DNS settings configured in TailScale admin. The Flint is advertising its WAN and LAN in TailScale, as is the Beryl. I’ve tried every combination of —accept-dns=true/false on both devices. I’ve tried disabling DNS Override in the Beryl, all to no avail. The Beryl is clearly using the Flint as an exit node (the IP address changes) but not the DNS resolver.

The fact that my phone, when not connected to the Beryl, is able to use the Flint as an exit node and does use the Adguard Home/Unbound as the DNS resolver leaves me fairly well convinced that the issue is on the Beryl.

Any help would be appreciated! Hoping to get this resolved, as the inability to use a TailScale exit node would render the Beryl pointless for me.

If you enable tailscale on the MT3600BE and set Flint 2 as the exit node, all network exits will use tailscale, but the DNS will still use the router's native DNS.

This is different from enabling tailscale directly on a mobile phone or computer.

This is because the MT3600BE has more complex routing and interfaces.

If you need to use Flint 2's DNS, you can try setting up manual DNS on the MT3600BE to see if it works.

That feels…counterintuitive to me. Tailscale is pretty clear that when using an exit node, the exit node’s DNS will be used. If GL iNet routers are overwriting this, I think that should be documented pretty specifically as it breaks expectations.

Also, won’t manually setting the DNS to the Tailscale IP break if I ever use the Beryl without Tailscale enabled?

Thank you for the update.

Because not all exit node devices have built-in DNS functionality.

When a router has tailscale enabled and other devices are set as exit nodes, the exit node's DNS will not be used.

Therefore, manual DNS settings are required, but DNS issues may still occur when tailscale is turned off.

However, we think your idea is also very reasonable.

Perhaps we can enable the router's accept DNS under certain circumstances.

That makes sense! Thanks for the quick reply and explanation.

I’ll try it out over my lunch break and report back.

Your suggestion did the trick! Thanks for the help - love the products and the support :+1:

1 Like