Tailscale and NordVPN together: why it breaks and what works
With NordVPN on, tailscale ping answers but ping and SSH to your tailnet fail. Why NordVPN blocks Tailscale, and what works, Mullvad exit nodes included.
With NordVPN connected, Tailscale stays signed in and tailscale ping still reaches your other devices through one of Tailscale’s relays, but everything else sent to their 100.x addresses fails: on Windows, ping prints “General failure” and SSH says “Permission denied”. Tailscale documents why: most VPNs drop traffic that does not pass through their own tunnel, and some use the same 100.64.0.0/10 addresses Tailscale does. NordVPN’s Linux app does the first, and its Meshnet does the second. Disconnecting NordVPN fixes it at once. To keep a privacy VPN and your tailnet at the same time, the route Tailscale documents is its Mullvad exit nodes ($5 a month for five devices). On Linux, NordVPN’s allowlist can exempt Tailscale’s range; on Windows and macOS, neither company documents a NordVPN setting that lets the two run together.
What it looks like
On September 29, 2026, a Windows laptop with NordVPN connected tried to reach a Linux server on the same tailnet. tailscale ping to the server answered, by way of a Tailscale relay (DERP). An ordinary ping to the server’s 100.x address printed “General failure”, and SSH to the same address failed with “Permission denied”. With NordVPN disconnected, the same commands worked, tailscale ping showed a direct path instead of the relay, and nothing on the server had been changed: no firewall rule was added there.
The SSH message reads like a login being refused. It was not: the same command logged in to the same, unchanged server as soon as NordVPN was off.
The same pattern on a Mac was reported to Tailscale in September 2026: with NordVPN connected, tailscale ping worked through a relay while every new TCP connection to a tailnet address timed out, and disconnecting NordVPN brought them back at once, with no Tailscale restart.
To check whether you are in this case, run:
tailscale ping <device-name-or-ip>If it answers “via DERP(…)” while ordinary connections to the same device fail, Tailscale itself is up, but that alone does not say what is stopping the rest: a tailnet access rule on the other device can produce the same pattern. What places it on NordVPN is the comparison above: disconnect NordVPN and try the ordinary connection again. By default tailscale ping sends Tailscale’s own path-discovery messages between the two Tailscale clients, which is why it can succeed when nothing else does.
Why NordVPN breaks it
Tailscale’s page on running alongside other VPNs gives three reasons the two usually conflict. Most VPNs set firewall rules so that all traffic goes through them, which can drop all of Tailscale’s. iOS and Android run only one VPN at a time. And a VPN that uses addresses from the 100.64.0.0/10 range conflicts with Tailscale’s 100.x addresses.
NordVPN’s Linux app is open source, and its firewall rules show the first reason directly: while the VPN is connected, or the kill switch is on, they drop traffic by default and let through only the tunnel, allowlisted subnets and ports, and Meshnet. Traffic to a tailnet address goes out through Tailscale’s network interface, not NordVPN’s tunnel, so it is dropped. Tailscale’s own traffic to the internet is ordinary traffic that NordVPN carries, which is likely why the client stays connected and a relay still works. The same source defines Meshnet’s subnet as 100.64.0.0/10, so with Meshnet on, the address conflict applies as well. Meshnet did not go away with the shutdown NordVPN announced for December 2025: its October 2025 release notes reversed it, saying Meshnet features “will stay live and supported”. The Windows and macOS apps are not open source, so their rules are not published; the symptoms above are what they produce.
The fix: disconnect NordVPN while you use the tailnet
Turn NordVPN off while you use the tailnet, and back on afterwards. It is the change that restored every connection on the Windows laptop above, and it is the answer the Mac report was closed with: macOS does not want two VPNs running at once, so “you can’t use both at the same time”, and the way to switch is to turn one off before starting the other. Nothing on the server needs to change.
On Linux, disconnecting is not enough if NordVPN’s kill switch is on: its firewall applies the same drop-by-default rules whenever the kill switch is set, connected or not. Turn it off as well:
nordvpn disconnect
nordvpn set killswitch offBoth at once: Tailscale’s Mullvad exit nodes
Before any workaround, Tailscale’s own advice is to see whether its Mullvad exit nodes cover the need. The add-on adds Mullvad’s VPN servers to your tailnet as exit nodes, so your public internet traffic leaves through a Mullvad server while traffic to your own devices stays on the tailnet, all from the one Tailscale client. The NordVPN app stays off: this replaces NordVPN with Mullvad rather than combining them.
It is in beta, and costs $5 a month for every five devices (as of October 1, 2026). You buy it in the admin console under General settings, Mullvad VPN, Configure. Buying it is not enough: each device that should use it has to be added there with Add devices, or given the mullvad attribute in the tailnet policy’s nodeAttrs, before its exit nodes appear on that device. Then choose a location in the client: on Windows, the Tailscale menu’s Exit Nodes, then Location Based Exit Nodes, then Location Based. On Linux:
tailscale exit-node list
sudo tailscale set --exit-node=<mullvad-exit-node>It also works on iOS and Android, where a second VPN app cannot run. It is not the same as running Mullvad’s own app beside Tailscale: Mullvad is on Tailscale’s list of software that can conflict with it. How an exit node takes over a device’s internet traffic is covered in the Tailscale exit node guide.
On Linux: NordVPN’s allowlist
Tailscale’s documented workaround for a VPN that blocks it is to make that VPN exclude Tailscale’s ranges, 100.64.0.0/10 and fd7a:115c:a1e0::/48, plus any subnet routes you use. NordVPN offers that on Linux only, where its allowlist excludes ports or subnets from VPN protection:
nordvpn allowlist add subnet 100.64.0.0/10The allowlist takes IPv4 subnets only (the command’s own help says so), so Tailscale’s IPv6 range stays blocked. NordVPN’s help center notes that allowlisted traffic bypasses both the tunnel and the kill switch, incoming as well as outgoing. If you use Meshnet, it shares the range, which Tailscale’s documentation says will conflict; turn it off with nordvpn set meshnet off. Neither company documents Tailscale working once the allowlist is in place, and on Tailscale’s long-running NordVPN issue, a 2021 report from a much older NordVPN app found that allowlisting Tailscale’s addresses and port did not restore the connection, so test it before you rely on it.
Settings that are not documented fixes
- Split tunneling on Windows and Android. NordVPN’s split tunneling there chooses apps, not address ranges, so it cannot express the exclusion Tailscale’s workaround asks for, and neither company documents excluding an app as a fix.
- Changing Tailscale’s addresses. Tailscale’s IP pool (beta) only picks a smaller block inside 100.64.0.0/10. Its documented fix for an address conflict is to disable IPv4 so the tailnet runs on IPv6 alone, which cuts off IPv4-only resources, including IPv4-only exit nodes. Both deal with overlapping addresses. Neither gets traffic past a firewall that drops whatever is outside its tunnel, and NordVPN’s Linux rules cover IPv6 too.
- Userspace networking. Tailscale lists it as a workaround for address conflicts, but in that mode Tailscale becomes a SOCKS5 or HTTP proxy each application has to be pointed at, the standard
pingstops working for tailnet addresses, and its documentation is written for Linux and containers. - Switching NordVPN’s protocol. On the same issue, one user found in 2021 that Tailscale worked with NordVPN on OpenVPN instead of NordLynx, and another found in 2022 that it did not. Neither company documents it.
- “Stay invisible on LAN”. NordVPN documents this setting for reaching devices on your local network, such as a printer. Tailscale’s addresses are not on your local network, and neither company connects the setting to Tailscale.
Phones, Macs and other VPNs
On iOS and Android only one VPN runs at a time, so NordVPN and Tailscale cannot both be on; a Mullvad exit node is the one documented way to get both jobs from one app. If the tailnet is how you reach a server from your phone, the phone SSH toolkit covers the client side. On a Mac, the September 2026 report shows NordVPN’s app producing the same failure, and the answer was to turn one off.
Other consumer VPNs run into the same three documented reasons, and whether one breaks Tailscale depends on its firewall rules and its addresses. Tailscale’s interoperability page lists Proton VPN, PIA, Mullvad, TunnelBear and Cloudflare WARP among software that “may or may not cause problems, depending on operating systems, versions, and configurations”. Where the devices that need your server must keep a VPN on, a web service published through Cloudflare Tunnel instead of a tailnet is ordinary HTTPS to a public hostname, which needs no second VPN on the device.