On Fedora with firewalld, `tailscale up` can leave the tailscale0 interface unassigned to any zone, silently dropping real traffic while tailscale's own control-plane pings keep working.
Docker sets the kernel FORWARD chain policy to DROP and leaves DOCKER-USER empty, silently killing traffic from libvirt's default NAT network even when firewalld and libvirt are both configured correctly.