Brume-3 tailscale masquerading question

Like my title says this is more a question than an issue as my current setup works fine.

My setup -

Drop in mode enabled

Adguard home enabled

Wireguard domain based policy enabled

Tailscale exit node enabled with ip masquerading switched off

The question -

When i have turned on ip masquerading this breaks my Internet to all my lan devices, they all remain connected to the wifi but with no Internet. If i go on any website like Google.com for example I get connection refused. A reboot does not fix it and turning it back off with a reboot also does not fix this. It breaks my Internet so bad, I have to restore from a backup I made incase I ever run into such a problem, this was my only fix.

So any idea why ip masquerading on breaks my Internet? This really baffles me and I do not know the answer to it, as I thought it was only suppose to change my tailscale ips into an internal one. I.E. 100.68.xxx.xx into a 192.68.xxx.xx

My suspicion is it is not compatible with drop in mode enabled but i havent turned this off to test as i need my lan devices to use my adguard dns and vpn policy and like i said it works fine with masquerading off. Either this is a bug i have encountered and can help gli.net fix in a future update or it is just simply incompatible with my setup and helps me find the answer i am looking for.

Found a working fix -

Enabling masquerading in luci > firewall

Turning it on this way fixes it and doesn't break my Internet, only the native dashboard breaks it. Both must setup firewalls differently.

1 Like