[GH-ISSUE #5437] Netbird not honoring large peer network ranges #10559

Open
opened 2026-08-05 01:26:22 -04:00 by saavagebueno · 0 comments
Owner

Originally created by @ev5unleash on GitHub (Feb 24, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5437

Describe the problem

A large subnet like 10.130.0.0/16 is NOT honored by the peer network range posture check. Only smaller subnets like /24 work.

To Reproduce

Steps to reproduce the behavior:

  1. Create a rather large peer network range such as 10.130.0.0/8 in a posture check and select BLOCK.
  2. Ensure that the client is on a subnet that falls into the range such as 10.130.150.15/24
  3. Connect the system to the Netbird network and check "netbird networks list". The network that should have been blocked is still appearing and connected.

Expected behavior

Netbird should take into consideration ALL encompassing subnets that would be applied to a large subnet filter.

Are you using NetBird Cloud?

No.

NetBird version

0.65.3

Is any other VPN software installed?

No.

Debug output

Screenshots

If applicable, add screenshots to help explain your problem.

Additional context

Add any other context about the problem here.

Have you tried these troubleshooting steps?

  • Reviewed client troubleshooting (if applicable)
  • Checked for newer NetBird versions
  • Searched for similar issues on GitHub (including closed ones)
  • Restarted the NetBird client
  • Disabled other VPN software
  • Checked firewall settings
Originally created by @ev5unleash on GitHub (Feb 24, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/5437 **Describe the problem** A large subnet like 10.130.0.0/16 is NOT honored by the peer network range posture check. Only smaller subnets like /24 work. **To Reproduce** Steps to reproduce the behavior: 1. Create a rather large peer network range such as 10.130.0.0/8 in a posture check and select BLOCK. 2. Ensure that the client is on a subnet that falls into the range such as 10.130.150.15/24 3. Connect the system to the Netbird network and check "netbird networks list". The network that should have been blocked is still appearing and connected. **Expected behavior** Netbird should take into consideration ALL encompassing subnets that would be applied to a large subnet filter. **Are you using NetBird Cloud?** No. **NetBird version** 0.65.3 **Is any other VPN software installed?** No. **Debug output** **Screenshots** If applicable, add screenshots to help explain your problem. **Additional context** Add any other context about the problem here. **Have you tried these troubleshooting steps?** - [X] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [X] Checked for newer NetBird versions - [X] Searched for similar issues on GitHub (including closed ones) - [X] Restarted the NetBird client - [X] Disabled other VPN software - [X] Checked firewall settings
saavagebueno added the triage-needed label 2026-08-05 01:26:22 -04:00
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#10559