Tailscale

4via6 subnet routes require IPv6 addresses in ACL destinations

warning
configurationUpdated Feb 2, 2026(via Exa)
Technologies:
How to detect:

When targeting resources behind a 4via6 subnet router, using IPv4 addresses in ACL destination fields will fail. The ACL must specify the IPv6 CIDR or address, not the IPv4 address, for proper routing.

Recommended action:

For 4via6 subnet destinations, use `tailscale debug via` to retrieve the correct IPv6 CIDR. Replace any IPv4 addresses in the `dst` field with the corresponding IPv6 addresses or CIDR ranges.