October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk6 min

How to Plan Tailscale Exit-Node Split Tunneling with WireGuard on Linux

Tailscale exit nodes, WireGuard, and Linux namespaces can support different routing designs, but there is no documented universal recipe for combining them. Learn what each component controls and how to plan and verify selective routing safely.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no documented, one-size-fits-all recipe for combining a Tailscale exit node, WireGuard, and Linux network namespaces into a selective-routing setup. The safe approach is to decide which traffic belongs in each path, then design and test the routes, namespace boundaries, permissions, DNS, and failure behavior for your particular system. A Tailscale exit node normally routes a device’s non-Tailscale internet traffic through the selected tailnet device; that is not the same as an integrated per-process WireGuard split tunnel.

What traffic do you want to route selectively?

Write down the traffic classes before configuring anything. For example, you might want tailnet destinations to use Tailscale, a chosen application or destination set to use WireGuard, and everything else to remain on the ordinary network. Those are separate routing goals; do not assume that choosing a Tailscale exit node automatically creates the WireGuard path or selects applications for it.

As an Amazon Associate I earn from qualifying purchases.

  • Tailnet traffic: connections to devices and routes within your Tailscale network.
  • Exit-node traffic: internet-bound traffic from a client that you choose to send through a Tailscale exit node.
  • WireGuard traffic: traffic assigned to the WireGuard interface or routing domain by your Linux configuration.
  • Ordinary-network traffic: traffic that should use the host’s normal network connection rather than either tunnel.

Be specific about whether “selected” means destinations, IP ranges, processes, users, or an entire namespace. Those choices determine where the route policy must live.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does each component control?

Tailscale exit-node selection, Linux route tables, network namespace placement, and tailnet access policy are related but distinct controls. Routes select where packets go; ACLs or grants decide whether a connection is allowed. Both the route and the applicable permission must allow a connection for it to work, as Tailscale explains in its route-injection reference.

#1 Best Overall
GL.iNet GL-SFT1200 Opal Travel Router, AC1200 Dual-Band Wi-Fi
  • 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
  • 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
  • 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
  • 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.
Mechanism Documented scope Where the decision is made What it does not establish
Tailscale exit node Routes a client device’s non-Tailscale internet traffic through a selected tailnet device by default. Exit-node advertisement and approval, client selection, and tailnet policy. A per-process Linux WireGuard split tunnel.
Tailscale subnet router or app connector Provides routes to selected network destinations or application destinations, respectively. Tailscale route configuration and policy. An integrated namespace-and-WireGuard arrangement.
WireGuard with Linux network namespaces Can separate routing state and interfaces; WireGuard documents namespace-based routing designs. Linux interface placement, namespace routing, and the operator’s network configuration. A ready-made Tailscale configuration or proof that a specific combined topology will work.

Tailscale’s exit-node documentation describes default routing behavior and separately discusses subnet routers, app connectors, and local-network access. It also identifies app-based split tunneling on Android; it does not document an equivalent integrated per-application Linux control for this combined setup. See Tailscale’s exit-node overview.

What must be configured to use a Tailscale exit node?

On Linux, the exit-node host must be configured to advertise itself, have IP forwarding enabled for IPv4 and IPv6, and be approved by an administrator in the Tailscale admin console. The client then selects that exit node separately. Tailscale’s Linux setup documentation gives the command tailscale set --advertise-exit-node; follow its current instructions for the rest of the host and admin-console setup: Set up an exit node on Linux.

Rank #2
GL.iNet GL-MT6000 Flint 2 Wi-Fi 6 Gaming Router Dual 2.5G Ports
  • Please update the firmware upon initial setup of the router, as it greatly enhances the device's performance and ensures a superior user experience.*** 【WiFi 6 Standard with ultra-low latency】Wi-Fi 6 speeds up to 6 Gbps to let you enjoy smoother 4K streaming, gaming, video calls and more, DDR4 1GB / eMMC 8GB
  • 【High Speed Gaming Router】Dominate with uninterrupted performance with the ultimate MT6000 gaming internet router, equipped with 8-stream Wi-Fi 6 technology, the Flint 2 delivers blazing speeds, ensuring a stable and high-speed connection during intense multiplayer battles.
  • 【Rapid OpenVPN & Wireguard speed】Wireguard VPN and OpenVPN speeds up to 900Mbps and 880Mbps respectively, giving you complete control over your gaming, streaming and working bandwidth. Actual speed may differ depending on internet service provider, network environment, VPN server location, VPN service provider, etc.
  • 【AdGuard Home Supported】Enabling the use of a DNS server for blocking unwanted tracking and offers a convenient web interface for filtering selected digital advertisements. Users can take full control of their online experience and enjoy a clutter-free browsing environment with ease.
  • 【Mass device connectivity】Experience enhanced online connectivity with our higher storage capacity, catering to over a hundred devices and fulfilling the requirements of DIY users seeking to install additional plugins. Enjoy stable and reliable connections, ensuring seamless performance and accommodating a wide range of digital needs.
  1. Enable forwarding on the intended Linux exit-node host. Tailscale’s setup requires IPv4 and IPv6 forwarding. The exact persistent setting depends on the Linux distribution and host configuration.
  2. Advertise the exit-node capability. On that host, use the documented command tailscale set --advertise-exit-node.
  3. Approve it in the admin console. Advertising the capability does not itself mean clients can use it; an administrator must approve the exit node.
  4. Check tailnet policy. A customized policy may need a grant or ACL permitting autogroup:internet. Permission to connect to the exit-node device itself is not the same as permission to route internet traffic through it.
  5. Select the exit node on the client. This is a separate client-side choice. Tailscale documents that local-network access is disabled by default while using an exit node and provides an option to enable it.

The exit node’s default behavior is broad: it routes non-Tailscale traffic through the selected device, apart from traffic already directed to a subnet router or app connector. If your goal is to send only particular applications through a tunnel, do not treat exit-node selection as that application-level policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What do WireGuard and namespaces contribute?

Linux network namespaces provide separate network stacks and routing tables, among other isolated resources. WireGuard’s project documentation states, “Like all Linux network interfaces, WireGuard integrates into the network namespace infrastructure.” Its example describes placing a physical interface in a physical namespace while leaving the WireGuard interface in the initial namespace to route internet traffic through WireGuard. That illustrates what the components can do; it is not a Tailscale setup recipe. See WireGuard’s Routing & Network Namespaces documentation and the Linux network_namespaces(7) reference.

Rank #3
GL.iNet GL-MT3000 Beryl AX Wi-Fi 6 Travel Router, 2.5G WAN, VPN, OpenWrt
  • 【DUAL BAND AX TRAVEL ROUTER】Products with US, UK, EU Plug; Dual band network with wireless speed 574Mbps (2.4G)+2402Mbps (5G); 2.5G Multi-gigabit WAN port and a 1G gigabit LAN port; USB 3.0 port; Wi-Fi 6 offers more than double the total Wi-Fi speed with the MT3000 VPN Router.
  • 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Beryl AX automatically encrypts all network traffic within the connected network. Max. VPN speed of 150 Mbps (OpenVPN); 300 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【OpenWrt 21.02 FIRMWARE】The Beryl AX is a portable wifi box and mini router that runs on OpenWrt 21.02 firmware. It supports more than 5,000 ready-made plug-ins for customization. Simply browse, install, and manage packages with our no-code interface within Beryl AX's Admin Panel.
  • 【PROTECT YOUR NETWORK SECURITY】Our pocket wifi, unlike other vulnerable portable wifi hotspot for travel purposes supports WPA3 protocol–Preventive measures against password brute-force attacks; DNS over HTTPS & DNS over TLS–Protecting domain name system traffic and preventing data eavesdropping from malicious parties; IPv6–Built-in authentication for privacy protection, eliminating the need for network address translation.
  • 【VPN CASCADING AT EASE】Surpassing the mediocre performance of most VPN routers for home usage, the Beryl AX is capable of hosting a VPN server and VPN client at the same time within the same device, enabling users to remote access local network resources like Wi-Fi printers or local web servers, and accessing the public internet as a VPN client simultaneously.

A namespace can isolate processes and routes, but it does not decide by itself how packets should pass among Tailscale, WireGuard, and the host. Before implementing a combined topology, establish which namespace owns each interface, which routing table each traffic class consults, and how any required forwarding between namespaces is configured. The correct arrangement depends on the target system and cannot be inferred merely from the fact that both Tailscale and WireGuard use Linux networking.

How should you choose where split-routing policy lives?

Choose the mechanism that matches the unit of traffic you want to select. These are different designs, not interchangeable recipes:

Rank #4
GL.iNet GL-MT3600BE Beryl 7 Dual-Band Wi-Fi 7 Travel Router
  • 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port. Enjoy gaming and streaming across up to 120 devices.
  • 【HIGH SPEED VPN CLIENT & SERVER】Max. VPN speed of 1100 Mbps (WireGuard); 1000 Mbps (OpenVPN-DCO). OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing account with our portable wifi device, and Beryl 7 automatically encrypts all network traffic within the connected network. *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【OpenWrt 21.02 FIRMWARE】The Beryl 7 (GL-MT3600BE) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 21.02 (Kernel 5.4.281) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
  • 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Beryl 7 is an ideal international wireless portable wifi travel router. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go. portable wi-fi for traveling, hotels or cruise ships.
  • 【PROTECT YOUR NETWORK SECURITY】Our pocket wifi, unlike other vulnerable portable wifi hotspot devices for travel purposes supports WPA3 protocol–Preventive measures against password brute-force attacks; DNS over HTTPS & DNS over TLS–Protecting domain name system traffic and preventing data eavesdropping from malicious parties; IPv6–Built-in authentication for privacy protection, eliminating the need for network address translation.
  • All internet traffic from a tailnet client: use the documented Tailscale exit-node model, accepting its default non-Tailscale traffic scope unless you have separately designed and validated additional routing.
  • Selected network destinations: consider Tailscale subnet routing or app connectors where their documented destination-based behavior fits. These are distinct from per-process WireGuard routing.
  • Traffic isolated by process or network stack: a namespace-based WireGuard design may be appropriate, but you must define interface ownership, routes, forwarding, DNS, and firewall behavior for your own topology.
  • More than one tunnel in the same host design: document route precedence and policy ownership explicitly. The wg-quick manual describes policy-routing facilities, including Table, PostUp, and PreDown; their availability does not prove that a particular configuration will coexist safely with Tailscale. Consult the wg-quick(8) manual.

Before applying configuration, make a route plan that identifies, for every traffic class, its originating process or namespace, destination scope, intended interface or tunnel, DNS resolver, and allowed fallback. Do not copy a topology from a different distribution or firewall setup without checking how its routes and packet filtering interact with yours.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can you verify the design without assuming it works?

Verify each traffic class independently on the target host. Tailscale recommends checking the public IP to confirm exit-node routing; that check only establishes the observed egress for the test you ran, not that every application, address family, or failure case follows the intended path.

Best Value
Sale
GL.iNet GL-BE3600 Slate 7 Wi-Fi 7 Travel Router Touchscreen 2.5G
  • 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
  • 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
  • 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
  • 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.
  • Inspect the relevant namespace’s interfaces and routing tables to confirm that the intended routes exist in the place where the traffic originates.
  • Test a destination that should use the Tailscale exit node and check its externally visible public IP.
  • Test a destination or process assigned to WireGuard separately; verify its route and observed egress rather than inferring success from an active interface.
  • Test traffic meant to remain on the ordinary network and confirm it does not enter either tunnel.
  • Check DNS resolution from each relevant namespace or process context. A correct IP route does not by itself prove that DNS queries use the intended resolver or path.
  • Test IPv4 and IPv6 separately. The Linux exit-node setup calls for forwarding both address families, and one family can behave differently from the other.
  • Test local-LAN access explicitly if it is required, because it is disabled by default while a Tailscale exit node is in use unless enabled.

Also test failure behavior before relying on the arrangement: bring down each tunnel or endpoint in a controlled environment and observe whether affected traffic stops, falls back to the ordinary network, or becomes unreachable. Decide whether fallback is acceptable for each traffic class. The referenced documentation does not establish the fallback behavior of an arbitrary combined topology.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.