[GH-ISSUE #4946] Access policy directions not working correctly #10165

Closed
opened 2026-08-05 01:24:51 -04:00 by saavagebueno · 4 comments
Owner

Originally created by @umutbesler on GitHub (Dec 13, 2025).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/4946

Hello,

I've newly installed Netbird and added some peers.

Policies seems not working as expected. I removed all policies. Then i've added one policy and set it to "Management Group can access all peers (one way Management -> All)".

Before this rule, no peers can connect to each other. But after adding this rule, all peers that are not in Management group can connect to peers that is in Management group.

Also when i look at the Accessible Peers page on peer2 it shows the peers from management group.

The weirest thing is, it is shown correctly on Beta Control Center page. It is shown as peer1 can connect to peer2 and peer2 cannot connect to any peer on control center page.

To Reproduce

Steps to reproduce the behavior:

  1. Add 2 peers peer1 and peer2
  2. Create a group named management and add peer1 to group
  3. Clear all the policies if existed and add a new policy, source management, destination all and set direction to ->

Expected behavior

Peer1 can connect to peer2 but peer2 cannot connect to peer1

Are you using NetBird Cloud?

Selfhosted

NetBird version

0.60.7

Is any other VPN software installed?

No

Screenshots

If applicable, add screenshots to help explain your problem.

Additional context

Add any other context about the problem here.

Have you tried these troubleshooting steps?

  • Reviewed client troubleshooting (if applicable)
  • Checked for newer NetBird versions
  • Searched for similar issues on GitHub (including closed ones)
  • Restarted the NetBird client
  • Disabled other VPN software
  • Checked firewall settings
Originally created by @umutbesler on GitHub (Dec 13, 2025). Original GitHub issue: https://github.com/netbirdio/netbird/issues/4946 Hello, I've newly installed Netbird and added some peers. Policies seems not working as expected. I removed all policies. Then i've added one policy and set it to "Management Group can access all peers (one way Management -> All)". Before this rule, no peers can connect to each other. But after adding this rule, all peers that are not in Management group can connect to peers that is in Management group. Also when i look at the Accessible Peers page on peer2 it shows the peers from management group. The weirest thing is, it is shown correctly on Beta Control Center page. It is shown as peer1 can connect to peer2 and peer2 cannot connect to any peer on control center page. **To Reproduce** Steps to reproduce the behavior: 1. Add 2 peers peer1 and peer2 2. Create a group named management and add peer1 to group 3. Clear all the policies if existed and add a new policy, source management, destination all and set direction to -> **Expected behavior** Peer1 can connect to peer2 but peer2 cannot connect to peer1 **Are you using NetBird Cloud?** Selfhosted **NetBird version** 0.60.7 **Is any other VPN software installed?** No **Screenshots** If applicable, add screenshots to help explain your problem. **Additional context** Add any other context about the problem here. **Have you tried these troubleshooting steps?** - [X] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [X] Checked for newer NetBird versions - [X] Searched for similar issues on GitHub (including closed ones) - [X] Restarted the NetBird client - [X] Disabled other VPN software - [X] Checked firewall settings
saavagebueno added the triage-needed label 2026-08-05 01:24:51 -04:00
Author
Owner

@brenner-tobias commented on GitHub (Dec 24, 2025):

Are you sure the "Management" peers are actually available from "All"?
Came here to raise the same issue, though for me it looks like a frontend / visualisation issue. The peers from "Management" are indeed shown in "Accessible Peers" from "All", though for me they are not reachable. Tested with an additional rule allowing the other direction, which works fine, so I suspect a UI bug.

<!-- gh-comment-id:3690482090 --> @brenner-tobias commented on GitHub (Dec 24, 2025): Are you sure the "Management" peers are actually available from "All"? Came here to raise the same issue, though for me it looks like a frontend / visualisation issue. The peers from "Management" are indeed shown in "Accessible Peers" from "All", though for me they are not reachable. Tested with an additional rule allowing the other direction, which works fine, so I suspect a UI bug.
Author
Owner

@umutbesler commented on GitHub (Dec 25, 2025):

Hello Brenner,

I've checked again now and it works perfectly now.
I've changed nothing on my side. I think is was fixed on last updates.

<!-- gh-comment-id:3691249294 --> @umutbesler commented on GitHub (Dec 25, 2025): Hello Brenner, I've checked again now and it works perfectly now. I've changed nothing on my side. I think is was fixed on last updates.
Author
Owner

@brenner-tobias commented on GitHub (Dec 25, 2025):

Is it also showing correctly in the UI?

<!-- gh-comment-id:3691251638 --> @brenner-tobias commented on GitHub (Dec 25, 2025): Is it also showing correctly in the UI?
Author
Owner

@umutbesler commented on GitHub (Dec 25, 2025):

It was already shown correctly on the Beta Control Center page (and still correct). But on the peer page, Accessible Peers tab shows wrong peers. For my scenario it should show no peers on the accessible peers page. But it shows all peers that can access this peer.

It should display peers that this peer can connect (at least it is written as "This peer can connect to the following peers within the NetBird network." on the Accessible Peers tab).

<!-- gh-comment-id:3691267622 --> @umutbesler commented on GitHub (Dec 25, 2025): It was already shown correctly on the Beta Control Center page (and still correct). But on the peer page, Accessible Peers tab shows wrong peers. For my scenario it should show no peers on the accessible peers page. But it shows all peers that can access this peer. It should display peers that this peer can connect (at least it is written as "This peer can connect to the following peers within the NetBird network." on the Accessible Peers tab).
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#10165