How to use Tailscale VPN only on main WiFi, not guest (GL-SFT1200)

I just bought a GL-SFT1200 (Opal) router. My goal is to set it up so that any clients connected to my main WiFi automatically go through Tailscale, while any clients connected to the guest WiFi do not.

I’m fairly new to OpenWRT and Tailscale, but it seems like this is doable using the LuCI interface. I’m also comfortable on the command line. I just don’t want to accidentally break things.

How would you recommend accomplishing this setup?

Hi

Because of the limited storage and memory on the GL-SFT1200 (Opal), we are unable to provide official Tailscale support on this model. While some users may attempt manual installation, stability and performance cannot be guaranteed.

If you need reliable Tailscale support, we recommend choosing a more capable router, such as the MT3000, which has sufficient hardware resources for this feature.

Thank you. I’m looking for community support.

As far as the official features go, the question applies to any VPN, not just Tailscale.

For built-in OpenVPN and WireGuard, you can use VPN Policy mode to route only devices on the main network—including the primary Wi-Fi and LAN—through the VPN, while allowing the guest network to bypass it.

For more details, please refer to the documentation below: