Set up high availability
Deploy multiple subnet routers or app connectors to keep resources accessible if one goes offline. The tailnet's route selection option determines how Tailscale selects among eligible connectors. Multiple hosts for a Tailscale Service can also provide redundant access. Configure Service hosts separately from the subnet router and app connector procedures in this guide.
Choose a route selection option
Compare selection behavior, availability, limitations, and failover timing in Route selection. Then choose the route selection option for your tailnet and complete the setup steps for app connectors or subnet routers below.
App connector high availability
To make app connectors highly available, run two or more app connectors with the same tag and assign your apps to that tag.
Step 1: Set up multiple app connectors
Follow Set up an app connector in your tailnet. Assign the same tag to all app connectors. For example, run this command on two or more devices:
sudo tailscale up --advertise-connector --advertise-tags="tag:connector"
Step 2: Assign an app to the app connectors
Assign the app to the same tag:connector tag. Follow the steps in Set up an app connector in your tailnet.
Step 3: Done
Your app connectors now provide redundant access to the configured apps. Check routing from your clients to confirm that they can reach the apps.
Subnet router high availability
To make subnet routers highly available, run two or more subnet routers that advertise the same routes, then approve the routes in the admin console.
Step 1: Set up multiple subnet routers
Follow Set up a subnet router on two or more devices in the same network. Advertise the same routes on each device. For example:
sudo tailscale set --advertise-routes=10.0.0.0/24,10.1.0.0/24
You can configure as many subnet routers as you need for failover.
Advertise the exact same route prefixes on each subnet router. Review the prefix matching requirements before configuring overlapping routes.
When setting up subnet routers for high availability (HA), be careful with the --accept-routes flag. This applies to active-passive failover when routers advertise the same routes, and to regional routing with in-region failover when they do so in the same region. If you enable --accept-routes on those routers, a standby router can accept its own advertised routes from the primary router.
This leads to an inefficient routing path. If both subnet routers advertise and accept 192.168.1.0/24, the standby router will send all 192.168.1.0/24 traffic through the primary router, even though it is directly connected to that network.
For most HA subnet router setups, use the --advertise-routes flag alone. Avoid using --accept-routes unless you specifically need that routing behavior.
Step 2: Activate the subnet routers in the admin console
- Open the Machines page of the admin console.
- Find your subnet router and open its
menu.
- Select Review subnet routes to open the subnet settings.
- Select Enable for the routes you want to use. Tailscale distributes these routes to the other devices in your tailnet.
You may want to disable key expiry on your server to avoid having to periodically reauthenticate. Refer to key expiry for more information about machine keys and how to disable their expiry.
Step 3: Done
Your subnet routers now provide redundant access to the approved routes. Check routing from your clients to confirm that they can reach the destinations.
Further reading
For examples that use regional routing or MagicRoute with subnet routers, app connectors, and Tailscale Service hosts, refer to Route selection use cases.