-
Notifications
You must be signed in to change notification settings - Fork 3.2k
FR: Publish Little Snitch ruleset for Tailscale #1872
Copy link
Copy link
Open
Labels
L2 FewLikelihoodLikelihoodOS-macosIssues involving Tailscale for macOSIssues involving Tailscale for macOSP1 NuisancePriority levelPriority levelT0 New featureIssue typeIssue typeconnectivityIssues with general connectivity with TailscaleIssues with general connectivity with TailscaleenhancementNew feature or requestNew feature or requestfrFeature requestFeature request
Description
Activity
Metadata
Metadata
Assignees
Labels
L2 FewLikelihoodLikelihoodOS-macosIssues involving Tailscale for macOSIssues involving Tailscale for macOSP1 NuisancePriority levelPriority levelT0 New featureIssue typeIssue typeconnectivityIssues with general connectivity with TailscaleIssues with general connectivity with TailscaleenhancementNew feature or requestNew feature or requestfrFeature requestFeature request
Little Snitch is a macOS application layer firewall, popular among privacy enthusiasts. By default, it (correctly) blocks Tailscale from dialing out, and also blocks inbound UDP, which makes some easy NAT traversal cases harder.
According to https://help.obdev.at/littlesnitch4/lsc-rule-group-subscriptions , we can publish a Little Snitch ruleset on tailscale.com (or pkgs.tailscale.com or whatever), with the exact ruleset we need to have Tailscale work. LS users can then subscribe to that for a more seamless experience than "piecemeal authorize individual bits of what Tailscale does".