{"id":4532,"date":"2026-09-14T12:23:50","date_gmt":"2026-09-14T16:23:50","guid":{"rendered":"https:\/\/increasec.com\/?p=4532"},"modified":"2026-09-14T12:23:50","modified_gmt":"2026-09-14T16:23:50","slug":"linux-debian-networkd-restart-kills-tailscale-routing","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=4532","title":{"rendered":"Linux Debian Networkd restart kills Tailscale routing"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Systemd-networkd deletes unmanaged custom IP routing policy rules on startup or restart <mark>because its default settings clean up &#8220;foreign&#8221; configurations<\/mark>. [<a href=\"https:\/\/serverfault.com\/questions\/1121521\/something-deletes-my-ip-rules\">1<\/a>, <a href=\"https:\/\/github.com\/netbirdio\/netbird\/issues\/4578\">2<\/a>]<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Logs Show:<br>Sep 13 06:49:23 MySvrName tailscaled[103604]: router: somebody (likely systemd-networkd) deleted ip rules; restoring Tailscale&#8217;s<br>&#8230;.<br>Sep 13 06:49:24 MySvrName tailscaled[103604]: Rebind; defIf=&#8221;eth0&#8243;, ips=[<em>some ips NOT including tailscale<\/em>]<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Disable Foreign Rule Management Globally (Quickest Fix)<br>nano \/etc\/systemd\/networkd.conf      Under the [Network] section, add or uncomment the following lines<br>[Network]<br>ManageForeignRoutes=no<br>ManageForeignRoutingPolicyRules=no<br>ManageForeignNextHops=no<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This WILL require a network service restart to apply.   Maybe do this in a scheduled job in the wee hours of the morning<br>sudo systemctl restart systemd-networkd<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Systemd-networkd deletes unmanaged custom IP routing policy rules on startup or restart because its default settings clean up &#8220;foreign&#8221; configurations. [1, 2] Logs Show:Sep 13 06:49:23 MySvrName tailscaled[103604]: router: somebody&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[10,205],"class_list":["post-4532","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-linux","tag-tailscale"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/4532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4532"}],"version-history":[{"count":1,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/4532\/revisions"}],"predecessor-version":[{"id":4533,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/4532\/revisions\/4533"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}