Tailscale cannot reach subnets on other devices

I had this issue - devices in my home GL-MT1300 network couldn’t ping the Tailnet or subnet routes exposed by the Tailnet. However if I SSHed into the GL-MT1300, it could.

To fix:

  1. Log in to the advanced Luci GUI panel, go to NetworkFirewall (not StatusFirewall)
  2. Edit the first row
  3. On the second tab add covered devices: tailscale0
  4. Save and Save & Apply

How I got Tailscale on my Beryl MT-1300