Ghaa, this is so frustrating. I've got a LAN, a #tailscale node in the LAN, another tailscale node elsewhere (remotely). I can ssh into the remote tailscale host from the local host that has the tailscale daemon running, but not from other machines in the LAN.
I have another LAN, very similar to the first LAN. I can ssh into the remote tailscale host just fine from any host in that second LAN.
The #headscale policies are the same for both LANs. I'm sure something is different, but after many hours trying to debug I can't find it.
Tcpdump shows traffic is going out on the tailscale interface on the local host that has the tailscale daemon running in the first LAN, but it's not coming out on the other end.
I'm sure it is some little stupid thing I'm not seeing, but ghaaaaaaaaaaa.