On Fedora with firewalld, `tailscale up` can leave the tailscale0 interface unassigned to any zone, silently dropping real traffic while tailscale's own control-plane pings keep working.
Docker sets the kernel FORWARD chain policy to DROP and leaves DOCKER-USER empty, silently killing traffic from libvirt's default NAT network even when firewalld and libvirt are both configured correctly.
Key-only SSH and Tailscale on Steam Deck / SteamOS that survive every update — the atomic update whitelist for SSH and the official deck-tailscale installer, explained.
Install the os-tailscale plugin on OPNSense, connect to Tailscale or Headscale, and advertise subnet routes — the WebUI steps most guides skip, including firewall rules and route approval.