Just taking a quick look at their guide here:

https://tailscale.com/kb/1082/firewall-ports

It says that you might want to open UDP port 41641. Try that and see?