[GH-ISSUE #5027] Netbird peer IP change result in connection loss #10574

Closed
opened 2026-08-05 01:26:28 -04:00 by saavagebueno · 10 comments
Owner

Originally created by @Skyfay on GitHub (Jan 3, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5027

Describe the problem

When I change the peer IP of a device in the Netbird Management Dashboard, I can no longer reach the device with either the old or the new Netbird IP. Ping, SSH, etc. nothing works anymore (from other clients with Netbird installed). The problem is only resolved when you manually restart the Netbird service on the peer where the IP address was changed.

Is this a bug or is this behavior normal? If it is normal, why doesn't the management server send the client a direct impulse to restart when the IP is changed?

To Reproduce

Steps to reproduce the behavior:

  1. Go to the Management Dashboard
  2. Change the IP form a Peer
  3. Try to reach this Peer with Ping from another Netbird device.

In this case i changed the IP from 100.127.192.98 to 100.100.90.27. The Logs i provide form the client are after the change and before the restart form the netbird peer agent.

PING 100.127.192.98 (100.127.192.98): 56 data bytes
Request timeout for icmp_seq 0
Request timeout for icmp_seq 1
Request timeout for icmp_seq 2
PING 100.100.90.27 (100.100.90.27): 56 data bytes
Request timeout for icmp_seq 0
Request timeout for icmp_seq 1
Request timeout for icmp_seq 2

Expected behavior

The dashboard says “Changes take effect when the peer reconnects.” However, I would expect to at least still be able to connect via the old Netbird IP, or for the management server to prompt the client to restart the service.

Are you using NetBird Cloud?

self-host NetBird's control plane.

NetBird version

0.61.2

Is any other VPN software installed?

No

Debug output

To help us resolve the problem, please attach the following anonymized status output

Peers detail:
 skyh80.anon-W9cnn.domain:
  NetBird IP: 100.68.69.98
  Public key: jA36HupQ7Mf6zbvO6QgZR+t+CjDEkQPVA7iacuLNDWA=
  Status: Connected
  -- detail --
  Connection type: Relayed
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: rels://anon-F3Q4A.domain/relay
  Last connection update: 41 minutes, 48 seconds ago
  Last WireGuard handshake: 36 seconds ago
  Transfer status (received/sent) 117.0 KiB/5.4 KiB
  Quantum resistance: false
  Networks: -
  Latency: 0s

 skywinpc.anon-W9cnn.domain:
  NetBird IP: 100.100.20.2
  Public key: K+b5to7IUeTXY8raPTcZDo5h9rY9DUR89+m7pNNgZw8=
  Status: Connecting
  -- detail --
  Connection type: -
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: 
  Last connection update: 3 hours, 21 minutes ago
  Last WireGuard handshake: -
  Transfer status (received/sent) 0 B/0 B
  Quantum resistance: false
  Networks: -
  Latency: 0s

 skymac.anon-W9cnn.domain:
  NetBird IP: 100.100.20.3
  Public key: drW8qt3C7ABBBnHEZg9gmjuvQwfADxPLAW60ZRu0N0o=
  Status: Connected
  -- detail --
  Connection type: Relayed
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: rels://anon-F3Q4A.domain/relay
  Last connection update: 5 minutes, 18 seconds ago
  Last WireGuard handshake: 1 minute, 8 seconds ago
  Transfer status (received/sent) 1.4 KiB/340 B
  Quantum resistance: false
  Networks: -
  Latency: 18.285568ms

 skyphone.anon-W9cnn.domain:
  NetBird IP: 100.100.20.187
  Public key: +R2hbDQ3CRubJInnFMjNg7SjZ1lvy5Qo1chOgs0lnys=
  Status: Connected
  -- detail --
  Connection type: Relayed
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: rels://anon-F3Q4A.domain/relay
  Last connection update: 6 minutes, 27 seconds ago
  Last WireGuard handshake: 2 minutes, 4 seconds ago
  Transfer status (received/sent) 404 B/892 B
  Quantum resistance: false
  Networks: -
  Latency: 0s

 chrome-143-browser-client-129-25.anon-W9cnn.domain:
  NetBird IP: 100.125.129.25
  Public key: MjuZA64ReUQTj/zaJ7aHp+sD6Z/q9WIkLSCbEbqzC3A=
  Status: Connecting
  -- detail --
  Connection type: -
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: 
  Last connection update: 14 minutes, 59 seconds ago
  Last WireGuard handshake: -
  Transfer status (received/sent) 0 B/0 B
  Quantum resistance: false
  Networks: -
  Latency: 0s

 skyh81.anon-W9cnn.domain:
  NetBird IP: 100.125.251.202
  Public key: SeE1TcHDZokBJo1Rl18zC+oi/nQTm4lK9KNuIc2JuQE=
  Status: Connected
  -- detail --
  Connection type: Relayed
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: rels://anon-F3Q4A.domain/relay
  Last connection update: 46 minutes, 52 seconds ago
  Last WireGuard handshake: 13 seconds ago
  Transfer status (received/sent) 19.8 KiB/6.1 KiB
  Quantum resistance: false
  Networks: -
  Latency: 0s

Events:
  [INFO] SYSTEM (d2f1a96b-47c1-4549-b7fd-d91cfdfcc4fd)
    Message: Network map updated
    Time: 18 minutes, 45 seconds ago
  [INFO] SYSTEM (78b3eef5-0603-40b7-93df-4b110eb0dfe0)
    Message: Network map updated
    Time: 18 minutes, 35 seconds ago
  [INFO] SYSTEM (32576b9d-a0f0-478c-84f2-f1bff9e56309)
    Message: Network map updated
    Time: 18 minutes, 35 seconds ago
  [INFO] SYSTEM (d25a0dd6-c90a-458e-968d-1bda35a8a860)
    Message: Network map updated
    Time: 18 minutes, 35 seconds ago
  [INFO] SYSTEM (3495c400-5226-42f6-b039-f995631504d7)
    Message: Network map updated
    Time: 6 minutes, 7 seconds ago
  [INFO] SYSTEM (832cc98d-bb23-40cd-8fe5-ccf09452536c)
    Message: Network map updated
    Time: 5 minutes, 51 seconds ago
  [INFO] SYSTEM (41f1e505-266e-45ad-a9b9-a61d06264c29)
    Message: Network map updated
    Time: 3 minutes, 44 seconds ago
  [INFO] SYSTEM (e4c0b970-cd9c-4815-b85c-f4bca59879b8)
    Message: Network map updated
    Time: 3 minutes, 27 seconds ago
  [INFO] SYSTEM (7a9d9c11-24f2-4939-9a8b-ad746ecdc2ed)
    Message: Network map updated
    Time: 3 minutes, 5 seconds ago
  [INFO] SYSTEM (8872e5a7-ff84-4921-a460-77f299175043)
    Message: Network map updated
    Time: 2 minutes, 58 seconds ago
OS: linux/amd64
Daemon version: 0.61.2
CLI version: 0.61.2
Profile: default
Management: Connected to https://anon-F3Q4A.domain:443
Signal: Connected to https://anon-F3Q4A.domain:443
Relays: 
  [stun:anon-F3Q4A.domain:3478] is Available
  [turn:anon-F3Q4A.domain:3478?transport=udp] is Available
  [rels://anon-F3Q4A.domain/relay] is Available
Nameservers: 
FQDN: hetv27.anon-W9cnn.domain
NetBird IP: 100.127.192.98/10
Interface type: Kernel
Quantum resistance: false
Lazy connection: false
SSH Server: Enabled
Networks: -
Forwarding rules: 0
Peers count: 4/6 Connected

(the connection try was from skymac.anon-W9cnn.domain

Have you tried these troubleshooting steps?

  • Reviewed client troubleshooting (if applicable)
  • Checked for newer NetBird versions
  • Searched for similar issues on GitHub (including closed ones)
  • Restarted the NetBird client
  • Disabled other VPN software
  • Checked firewall settings
Originally created by @Skyfay on GitHub (Jan 3, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/5027 **Describe the problem** When I change the peer IP of a device in the Netbird Management Dashboard, I can no longer reach the device with either the old or the new Netbird IP. Ping, SSH, etc. nothing works anymore (from other clients with Netbird installed). The problem is only resolved when you manually restart the Netbird service on the peer where the IP address was changed. Is this a bug or is this behavior normal? If it is normal, why doesn't the management server send the client a direct impulse to restart when the IP is changed? **To Reproduce** Steps to reproduce the behavior: 1. Go to the Management Dashboard 2. Change the IP form a Peer 3. Try to reach this Peer with Ping from another Netbird device. In this case i changed the IP from 100.127.192.98 to 100.100.90.27. The Logs i provide form the client are after the change and before the restart form the netbird peer agent. ``` PING 100.127.192.98 (100.127.192.98): 56 data bytes Request timeout for icmp_seq 0 Request timeout for icmp_seq 1 Request timeout for icmp_seq 2 ``` ``` PING 100.100.90.27 (100.100.90.27): 56 data bytes Request timeout for icmp_seq 0 Request timeout for icmp_seq 1 Request timeout for icmp_seq 2 ``` **Expected behavior** The dashboard says “Changes take effect when the peer reconnects.” However, I would expect to at least still be able to connect via the old Netbird IP, or for the management server to prompt the client to restart the service. **Are you using NetBird Cloud?** self-host NetBird's control plane. **NetBird version** 0.61.2 **Is any other VPN software installed?** No **Debug output** To help us resolve the problem, please attach the following anonymized status output ``` Peers detail: skyh80.anon-W9cnn.domain: NetBird IP: 100.68.69.98 Public key: jA36HupQ7Mf6zbvO6QgZR+t+CjDEkQPVA7iacuLNDWA= Status: Connected -- detail -- Connection type: Relayed ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: rels://anon-F3Q4A.domain/relay Last connection update: 41 minutes, 48 seconds ago Last WireGuard handshake: 36 seconds ago Transfer status (received/sent) 117.0 KiB/5.4 KiB Quantum resistance: false Networks: - Latency: 0s skywinpc.anon-W9cnn.domain: NetBird IP: 100.100.20.2 Public key: K+b5to7IUeTXY8raPTcZDo5h9rY9DUR89+m7pNNgZw8= Status: Connecting -- detail -- Connection type: - ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: Last connection update: 3 hours, 21 minutes ago Last WireGuard handshake: - Transfer status (received/sent) 0 B/0 B Quantum resistance: false Networks: - Latency: 0s skymac.anon-W9cnn.domain: NetBird IP: 100.100.20.3 Public key: drW8qt3C7ABBBnHEZg9gmjuvQwfADxPLAW60ZRu0N0o= Status: Connected -- detail -- Connection type: Relayed ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: rels://anon-F3Q4A.domain/relay Last connection update: 5 minutes, 18 seconds ago Last WireGuard handshake: 1 minute, 8 seconds ago Transfer status (received/sent) 1.4 KiB/340 B Quantum resistance: false Networks: - Latency: 18.285568ms skyphone.anon-W9cnn.domain: NetBird IP: 100.100.20.187 Public key: +R2hbDQ3CRubJInnFMjNg7SjZ1lvy5Qo1chOgs0lnys= Status: Connected -- detail -- Connection type: Relayed ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: rels://anon-F3Q4A.domain/relay Last connection update: 6 minutes, 27 seconds ago Last WireGuard handshake: 2 minutes, 4 seconds ago Transfer status (received/sent) 404 B/892 B Quantum resistance: false Networks: - Latency: 0s chrome-143-browser-client-129-25.anon-W9cnn.domain: NetBird IP: 100.125.129.25 Public key: MjuZA64ReUQTj/zaJ7aHp+sD6Z/q9WIkLSCbEbqzC3A= Status: Connecting -- detail -- Connection type: - ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: Last connection update: 14 minutes, 59 seconds ago Last WireGuard handshake: - Transfer status (received/sent) 0 B/0 B Quantum resistance: false Networks: - Latency: 0s skyh81.anon-W9cnn.domain: NetBird IP: 100.125.251.202 Public key: SeE1TcHDZokBJo1Rl18zC+oi/nQTm4lK9KNuIc2JuQE= Status: Connected -- detail -- Connection type: Relayed ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: rels://anon-F3Q4A.domain/relay Last connection update: 46 minutes, 52 seconds ago Last WireGuard handshake: 13 seconds ago Transfer status (received/sent) 19.8 KiB/6.1 KiB Quantum resistance: false Networks: - Latency: 0s Events: [INFO] SYSTEM (d2f1a96b-47c1-4549-b7fd-d91cfdfcc4fd) Message: Network map updated Time: 18 minutes, 45 seconds ago [INFO] SYSTEM (78b3eef5-0603-40b7-93df-4b110eb0dfe0) Message: Network map updated Time: 18 minutes, 35 seconds ago [INFO] SYSTEM (32576b9d-a0f0-478c-84f2-f1bff9e56309) Message: Network map updated Time: 18 minutes, 35 seconds ago [INFO] SYSTEM (d25a0dd6-c90a-458e-968d-1bda35a8a860) Message: Network map updated Time: 18 minutes, 35 seconds ago [INFO] SYSTEM (3495c400-5226-42f6-b039-f995631504d7) Message: Network map updated Time: 6 minutes, 7 seconds ago [INFO] SYSTEM (832cc98d-bb23-40cd-8fe5-ccf09452536c) Message: Network map updated Time: 5 minutes, 51 seconds ago [INFO] SYSTEM (41f1e505-266e-45ad-a9b9-a61d06264c29) Message: Network map updated Time: 3 minutes, 44 seconds ago [INFO] SYSTEM (e4c0b970-cd9c-4815-b85c-f4bca59879b8) Message: Network map updated Time: 3 minutes, 27 seconds ago [INFO] SYSTEM (7a9d9c11-24f2-4939-9a8b-ad746ecdc2ed) Message: Network map updated Time: 3 minutes, 5 seconds ago [INFO] SYSTEM (8872e5a7-ff84-4921-a460-77f299175043) Message: Network map updated Time: 2 minutes, 58 seconds ago OS: linux/amd64 Daemon version: 0.61.2 CLI version: 0.61.2 Profile: default Management: Connected to https://anon-F3Q4A.domain:443 Signal: Connected to https://anon-F3Q4A.domain:443 Relays: [stun:anon-F3Q4A.domain:3478] is Available [turn:anon-F3Q4A.domain:3478?transport=udp] is Available [rels://anon-F3Q4A.domain/relay] is Available Nameservers: FQDN: hetv27.anon-W9cnn.domain NetBird IP: 100.127.192.98/10 Interface type: Kernel Quantum resistance: false Lazy connection: false SSH Server: Enabled Networks: - Forwarding rules: 0 Peers count: 4/6 Connected ``` (the connection try was from skymac.anon-W9cnn.domain **Have you tried these troubleshooting steps?** - [X] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [X] Checked for newer NetBird versions - [X] Searched for similar issues on GitHub (including closed ones) - [X] Restarted the NetBird client - [X] Disabled other VPN software - [X] Checked firewall settings
saavagebueno added the triage-needed label 2026-08-05 01:26:28 -04:00
Author
Owner

@Morningstar2808 commented on GitHub (Jan 7, 2026):

I'm just wondering how a device or server with Netbird should apply a new IP address without restarting the service? How do you imagine it?

<!-- gh-comment-id:3720265542 --> @Morningstar2808 commented on GitHub (Jan 7, 2026): I'm just wondering how a device or server with Netbird should apply a new IP address without restarting the service? How do you imagine it?
Author
Owner

@Morningstar2808 commented on GitHub (Jan 7, 2026):

Obviously, the device or server needs to restart the service so that it can accept and use a new IP address.

<!-- gh-comment-id:3720284610 --> @Morningstar2808 commented on GitHub (Jan 7, 2026): Obviously, the device or server needs to restart the service so that it can accept and use a new IP address.
Author
Owner

@Skyfay commented on GitHub (Jan 7, 2026):

Obviously, the device or server needs to restart the service so that it can accept and use a new IP address.

Yes, but why doesn't Netbird trigger a restart of the Netbird service when you change the IP? That's exactly the problem. Otherwise, you lose all connection to the device. And how do you plan to restart it if you lost connection? However, the device is still connected via management, so the service could also be restarted. Or it is restarted directly when the new IP is transferred.

Tailscale does the same thing: I change the IP and can access the device directly via the new IP without having to restart the service myself.

<!-- gh-comment-id:3720398858 --> @Skyfay commented on GitHub (Jan 7, 2026): > Obviously, the device or server needs to restart the service so that it can accept and use a new IP address. Yes, but why doesn't Netbird trigger a restart of the Netbird service when you change the IP? That's exactly the problem. Otherwise, you lose all connection to the device. And how do you plan to restart it if you lost connection? However, the device is still connected via management, so the service could also be restarted. Or it is restarted directly when the new IP is transferred. Tailscale does the same thing: I change the IP and can access the device directly via the new IP without having to restart the service myself.
Author
Owner

@Morningstar2808 commented on GitHub (Jan 7, 2026):

Obviously, the device or server needs to restart the service so that it can accept and use a new IP address.

Yes, but why doesn't Netbird trigger a restart of the Netbird service when you change the IP? That's exactly the problem. Otherwise, you lose all connection to the device. And how do you plan to restart it if you lost connection? However, the device is still connected via management, so the service could also be restarted. Or it is restarted directly when the new IP is transferred.

Tailscale does the same thing: I change the IP and can access the device directly via the new IP without having to restart the service myself.

I don't know how the panel should send a command to the device or server that it needs to restart the service to apply the changes when the Netbird ip of this device or server has already been changed in the panel🤔
As for Tailscale, I had a case when I changed the domain name of the server, and it immediately stopped working for those services that looked at this domain name. And this device didn't work and didn't use the new name until I restarted the Tailscale service manually, the panel didn't do it automatically

<!-- gh-comment-id:3720504776 --> @Morningstar2808 commented on GitHub (Jan 7, 2026): > > Obviously, the device or server needs to restart the service so that it can accept and use a new IP address. > > Yes, but why doesn't Netbird trigger a restart of the Netbird service when you change the IP? That's exactly the problem. Otherwise, you lose all connection to the device. And how do you plan to restart it if you lost connection? However, the device is still connected via management, so the service could also be restarted. Or it is restarted directly when the new IP is transferred. > > Tailscale does the same thing: I change the IP and can access the device directly via the new IP without having to restart the service myself. I don't know how the panel should send a command to the device or server that it needs to restart the service to apply the changes when the Netbird ip of this device or server has already been changed in the panel🤔 As for Tailscale, I had a case when I changed the domain name of the server, and it immediately stopped working for those services that looked at this domain name. And this device didn't work and didn't use the new name until I restarted the Tailscale service manually, the panel didn't do it automatically
Author
Owner

@Skyfay commented on GitHub (Jan 7, 2026):

I don't know how the panel should send a command to the device or server that it needs to restart the service to apply the changes when the Netbird ip of this device or server has already been changed in the panel🤔

Even if the IP has already been changed, the agent is still connected to the management server, as can be seen from the status. That would certainly be possible. Or, as suggested, you could program this directly into the client or include it directly with the IP change request. I think, there are several possible solutions.

As for Tailscale, I had a case when I changed the domain name of the server, and it immediately stopped working for those services that looked at this domain name. And this device didn't work and didn't use the new name until I restarted the Tailscale service manually, the panel didn't do it automatically

I never had any problems with that. As I said, it was about IP change, not DNS.

<!-- gh-comment-id:3720537343 --> @Skyfay commented on GitHub (Jan 7, 2026): > I don't know how the panel should send a command to the device or server that it needs to restart the service to apply the changes when the Netbird ip of this device or server has already been changed in the panel🤔 Even if the IP has already been changed, the agent is still connected to the management server, as can be seen from the status. That would certainly be possible. Or, as suggested, you could program this directly into the client or include it directly with the IP change request. I think, there are several possible solutions. > As for Tailscale, I had a case when I changed the domain name of the server, and it immediately stopped working for those services that looked at this domain name. And this device didn't work and didn't use the new name until I restarted the Tailscale service manually, the panel didn't do it automatically I never had any problems with that. As I said, it was about IP change, not DNS.
Author
Owner

@Dimtar commented on GitHub (Feb 14, 2026):

I feel like I had a similar issue today.
I added one peer to my mesh/network and then decided to renumber the network. From 192.168.86.0/24 to 192.168.89.0/24
The peers list updated with the "new" IP but the peer still had the old IP and couldn't reach anything until I did a netbird down/up

I confirmed the peer still had the old IP with netbird status

<!-- gh-comment-id:3903283034 --> @Dimtar commented on GitHub (Feb 14, 2026): I feel like I had a similar issue today. I added one peer to my mesh/network and then decided to renumber the network. From 192.168.86.0/24 to 192.168.89.0/24 The peers list updated with the "new" IP but the peer still had the old IP and couldn't reach anything until I did a netbird down/up I confirmed the peer still had the old IP with netbird status
Author
Owner

@imecar-github commented on GitHub (Mar 4, 2026):

Im facing the same issue. But now I see the ip change. But both ip access and dns access does not work.

<!-- gh-comment-id:3996456916 --> @imecar-github commented on GitHub (Mar 4, 2026): Im facing the same issue. But now I see the ip change. But both ip access and dns access does not work.
Author
Owner

@fuomag9 commented on GitHub (Mar 16, 2026):

Had the same issue today, this makes netbird completely useless for me as it doesn't support IPv6 and I only have dynamic addresses, I had ALL my peers offline today

<!-- gh-comment-id:4069830059 --> @fuomag9 commented on GitHub (Mar 16, 2026): Had the same issue today, this makes netbird completely useless for me as it doesn't support IPv6 and I only have dynamic addresses, I had ALL my peers offline today
Author
Owner

@Skyfay commented on GitHub (Mar 16, 2026):

this makes netbird completely useless for me as it doesn't support IPv6

Netbird support IPv6 at least my nodes works with ipv6 peer to peer.

<!-- gh-comment-id:4070472251 --> @Skyfay commented on GitHub (Mar 16, 2026): > this makes netbird completely useless for me as it doesn't support IPv6 Netbird support IPv6 at least my nodes works with ipv6 peer to peer.
Author
Owner

@lixmal commented on GitHub (Apr 8, 2026):

Fixed by #5614 (v0.67.0) which restarts the engine automatically when the peer IP changes.

<!-- gh-comment-id:4205370753 --> @lixmal commented on GitHub (Apr 8, 2026): Fixed by #5614 (v0.67.0) which restarts the engine automatically when the peer IP changes.
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#10574