The following criteria must be met in order to use this feature:
- A Route10 must be v1.5c or later firmware
- If using local Control, v1.1z or later firmware
Tailscale connects devices in a private network called a tailnet. On Route10, it can provide remote access to selected local networks or carry a remote device’s full internet connection.
Enable Tailscale
- Sign in to manage.alta.inc and open the site containing the Route10.
- Select the Route10, then open VPN → Tailscale.
- Turn on Enable and open the authentication link. (may take a few moments to generate)
- Sign in to Tailscale, associate the Route10 with your tailnet, and select Connect.
- If your tailnet requires device approval, authorize the Route10 in the Tailscale admin console.
- Return to Alta Control and confirm Login successful. An active connection is also shown by the green status icon.
Choose a routing mode
Mode |
VPN Behavior |
Use it when |
|---|---|---|
| Standard tailnet connection | Only traffic between Tailscale devices uses the tunnel. | You only need the Route10 itself reachable through Tailscale. |
| Subnet router | Split tunnel: traffic for selected Route10 LAN/VLAN subnets uses Tailscale; normal internet traffic exits locally. | Remote users need printers, cameras, servers, or other devices that cannot run Tailscale. |
| Exit node | Full tunnel: a client selecting the Route10 sends internet traffic through it. This role does not advertise Route10 LAN/VLAN subnets. | You want protected browsing on untrusted Wi-Fi or internet access from the Route10 site’s location. |
Enable both roles when remote clients need full-tunnel internet access and access to LAN devices behind the Route10. Approve advertised routes or exit-node use in the Tailscale admin console if required by your tailnet policy.
Verify
- Subnet router: From an authorized remote Tailscale device, reach a device in an advertised subnet and confirm ordinary internet traffic still exits locally.
- Exit node: Select the Route10 as the client’s exit node, then confirm the client’s public IP matches the Route10 site’s current WAN egress IP.
Key expiry and reauthentication
If key expiry is enabled for the Route10 in Tailscale, the Route10 must be reauthenticated when its device key expires. New Tailscale domains default to 180 days, but your configured interval may differ. When reauthentication is required, the Route10’s green Tailscale status globe becomes yellow and a new authentication link appears. Open the link, complete the same sign-in and connection flow used during setup, and confirm the status globe returns to green.
Tailscale allows key expiry to be disabled for trusted subnet routers and other always-on devices. This avoids periodic reauthentication but removes periodic key rotation for that device. If used, scope the change to the Route10, re-enable key expiry to roll it back, and verify the Route10’s key-expiry status on Tailscale’s Machines page.
Comments
0 comments
Article is closed for comments.