Install Tailscale package iptables-nft and tailscale from OpenWrt console:


Enable and connect Tailscale service in OpenWrt:
1 | $ ssh -l root SenseWrt |
NOTE: 192.168.88.0/24 is the ip range of local network setup in OpenWrt.
Disable key expiry for OpenWrt machine in Tailscale console, then enable all OpenWrt clients access Tailscale network:

Now add Tailscale virtual network as a new interface in OpenWrt:

Create firewall for Tailscale virtual network interface in OpenWrt:

Configure firewall for Tailscale virtual network interface in OpenWrt:

NOTE: opt network is for the downstream DHCP clients.
References
- 韩风 Talk - Tailscale 玩法之内网穿透、异地组网、全隧道模式、纯 IP 的双栈 DERP 搭建、Headscale 协调服务器搭建,用一期搞定,看一看不亏吧?https://www.youtube.com/watch?v=mgDpJX3oNvI