[GH-ISSUE #5440] Option to select IP address or FQDN in the target field of the reverse proxy service #10561

Open
opened 2026-08-05 01:26:22 -04:00 by saavagebueno · 1 comment
Owner

Originally created by @SalvaTirados on GitHub (Feb 24, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5440

For internal services without internet access, ACME (DNS) certificates can be manually created using CNAME records. This certificate can then be uploaded to the internal service. If the service configuration does not allow the use of a Fully Qualified Domain Name (FQDN), an IP SANs error will occur. By allowing an FQDN to be applied in the service field instead of an IP address, a domain such as DNSexit could be used to create the certificate with an internal FQDN. Configuring a domain zone with an A record for the internal destination service would resolve the service's IP address and prevent the IP SANs error.

Originally created by @SalvaTirados on GitHub (Feb 24, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/5440 For internal services without internet access, ACME (DNS) certificates can be manually created using CNAME records. This certificate can then be uploaded to the internal service. If the service configuration does not allow the use of a Fully Qualified Domain Name (FQDN), an IP SANs error will occur. By allowing an FQDN to be applied in the service field instead of an IP address, a domain such as DNSexit could be used to create the certificate with an internal FQDN. Configuring a domain zone with an A record for the internal destination service would resolve the service's IP address and prevent the IP SANs error.
saavagebueno added the feature-request label 2026-08-05 01:26:22 -04:00
Author
Owner

@Crushedice commented on GitHub (Mar 17, 2026):

Greetings,
I would like to push this request up a bit .
For me, its not the same reason why i would want the ability to select an Network Interface IP, instead of only the "peer" .
I got on one machine 3 public ip's and its internal netbird one,
For reasons, i would like to point one proxy rule towards the devices secondary ip on a diff interface, and not to the Peer... if that makes sense.

Thanks

<!-- gh-comment-id:4077340632 --> @Crushedice commented on GitHub (Mar 17, 2026): Greetings, I would like to push this request up a bit . For me, its not the same reason why i would want the ability to select an Network Interface IP, instead of only the "peer" . I got on one machine 3 public ip's and its internal netbird one, For reasons, i would like to point one proxy rule towards the devices secondary ip on a diff interface, and not to the Peer... if that makes sense. Thanks
Sign in to join this conversation.
No Label feature-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#10561