[GH-ISSUE #5514] Unable to use the reverse proxy feature with any HTTPS connection #10688

Closed
opened 2026-08-05 01:26:54 -04:00 by saavagebueno · 14 comments
Owner

Originally created by @nvaert1986 on GitHub (Mar 5, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5514

Describe the problem

I am unable to create a reverse proxy connection to any internal service when it's running on HTTPS internally. I always receive the error: Error 502 Connection Error An unexpected error occurred while connecting to the service. Please try again later. Whenever I connect over HTTP it works fine. The internal HTTPS services are using self-signed SSL certificates. Since they're internal services, valid certificates are not possible. I'm not sure whether that's related or not, but if it is perhaps add a flag / option in the GUI which ignores invalid certificates?

To Reproduce

Steps to reproduce the behavior:

  1. Create a service via HTTPS
  2. Try to access it

Expected behavior

A working reverse proxy connection

Are you using NetBird Cloud?

I'm using netbirds selfhosted control plane

NetBird version

0.66.2

Is any other VPN software installed?

No

Debug output

To help us resolve the problem, please attach the following anonymized status output

The command does not seem to be available on the server and the client isn't installed.

Create and upload a debug bundle, and share the returned file key:

netbird debug for 1m -AS -U

Uploaded files are automatically deleted after 30 days.

Alternatively, create the file only and attach it here manually:

netbird debug for 1m -AS

Screenshots

If applicable, add screenshots to help explain your problem.

Additional context

Add any other context about the problem here.

Have you tried these troubleshooting steps?

  • Reviewed client troubleshooting (if applicable)
  • Checked for newer NetBird versions
  • Searched for similar issues on GitHub (including closed ones)
  • Restarted the NetBird client
  • Disabled other VPN software
  • Checked firewall settings
Originally created by @nvaert1986 on GitHub (Mar 5, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/5514 **Describe the problem** I am unable to create a reverse proxy connection to any internal service when it's running on HTTPS internally. I always receive the error: Error 502 Connection Error An unexpected error occurred while connecting to the service. Please try again later. Whenever I connect over HTTP it works fine. The internal HTTPS services are using self-signed SSL certificates. Since they're internal services, valid certificates are not possible. I'm not sure whether that's related or not, but if it is perhaps add a flag / option in the GUI which ignores invalid certificates? **To Reproduce** Steps to reproduce the behavior: 1. Create a service via HTTPS 2. Try to access it **Expected behavior** A working reverse proxy connection **Are you using NetBird Cloud?** I'm using netbirds selfhosted control plane **NetBird version** 0.66.2 **Is any other VPN software installed?** No **Debug output** To help us resolve the problem, please attach the following anonymized status output The command does not seem to be available on the server and the client isn't installed. Create and upload a debug bundle, and share the returned file key: netbird debug for 1m -AS -U *Uploaded files are automatically deleted after 30 days.* Alternatively, create the file only and attach it here manually: netbird debug for 1m -AS **Screenshots** If applicable, add screenshots to help explain your problem. **Additional context** Add any other context about the problem here. **Have you tried these troubleshooting steps?** - [X] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [X] Checked for newer NetBird versions - [X] Searched for similar issues on GitHub (including closed ones) - [X] Restarted the NetBird client - [X] Disabled other VPN software - [X] Checked firewall settings
saavagebueno added the triage-needed label 2026-08-05 01:26:54 -04:00
Author
Owner

@bokamm commented on GitHub (Mar 9, 2026):

I encountered the same issue, but am using NetBird Cloud.

<!-- gh-comment-id:4023668632 --> @bokamm commented on GitHub (Mar 9, 2026): I encountered the same issue, but am using NetBird Cloud.
Author
Owner

@popomomo commented on GitHub (Mar 11, 2026):

I encountered the same issue, but am using NetBird Cloud.

Same here after trying with NetBird Cloud

<!-- gh-comment-id:4037732073 --> @popomomo commented on GitHub (Mar 11, 2026): > I encountered the same issue, but am using NetBird Cloud. Same here after trying with NetBird Cloud
Author
Owner

@popomomo commented on GitHub (Mar 11, 2026):

After I tried Cloudflare tunnel and approach same error as NetBird. I search for a solution and found that if I enable "No TLS Verify" in Cloudflare tunnel. It will solve this issue.

Any option to do that option in NetBird as well?

<!-- gh-comment-id:4038099702 --> @popomomo commented on GitHub (Mar 11, 2026): After I tried Cloudflare tunnel and approach same error as NetBird. I search for a solution and found that if I enable "No TLS Verify" in Cloudflare tunnel. It will solve this issue. Any option to do that option in NetBird as well?
Author
Owner

@lixmal commented on GitHub (Mar 11, 2026):

The dashboard now offers a skip TLS verification option for targets.

<!-- gh-comment-id:4038948992 --> @lixmal commented on GitHub (Mar 11, 2026): The dashboard now offers a `skip TLS verification` option for targets.
Author
Owner

@popomomo commented on GitHub (Mar 11, 2026):

The dashboard now offers a skip TLS verification option for targets.

@lixmal Turn it on already but still can't access. Show Error 502

<!-- gh-comment-id:4039369087 --> @popomomo commented on GitHub (Mar 11, 2026): > The dashboard now offers a `skip TLS verification` option for targets. @lixmal Turn it on already but still can't access. Show Error 502
Author
Owner

@namekal commented on GitHub (Mar 12, 2026):

@popomomo @lixmal
I'm experiencing the same. Netbird Cloud. Tried with all options for a local https target:

  1. HTTP: redirects to target IP as https (i think this is just the behavior of the service, so currently as expected)

  2. HTTPS: Connection error 502

  3. HTTPS + Skip TLS Verification: Connection error 502

Also attempted deleting and recreating in case i clicked a wrong option, and made sure that the status changed when disabling the target, etc. to show that changes were affected in basically real-time

<!-- gh-comment-id:4049729390 --> @namekal commented on GitHub (Mar 12, 2026): @popomomo @lixmal I'm experiencing the same. Netbird Cloud. Tried with all options for a local https target: 1. HTTP: redirects to target IP as https (i think this is just the behavior of the service, so currently as expected) 2. HTTPS: Connection error 502 3. HTTPS + Skip TLS Verification: Connection error 502 Also attempted deleting and recreating in case i clicked a wrong option, and made sure that the status changed when disabling the target, etc. to show that changes were affected in basically real-time
Author
Owner

@nvaert1986 commented on GitHub (Mar 19, 2026):

Still the same here.

<!-- gh-comment-id:4090464225 --> @nvaert1986 commented on GitHub (Mar 19, 2026): Still the same here.
Author
Owner

@northway commented on GitHub (Mar 20, 2026):

Image

The toggle is there for sure, but it's still not working.

<!-- gh-comment-id:4096733496 --> @northway commented on GitHub (Mar 20, 2026): <img width="508" height="554" alt="Image" src="https://github.com/user-attachments/assets/23bc6aca-f932-4773-8730-7d95cac62361" /> The toggle is there for sure, but it's still not working.
Author
Owner

@chxp82q commented on GitHub (Mar 20, 2026):

Skip TLS Verification toggle works for me on v0.66.4

<!-- gh-comment-id:4101683345 --> @chxp82q commented on GitHub (Mar 20, 2026): Skip TLS Verification toggle works for me on v0.66.4
Author
Owner

@VPjoon commented on GitHub (Mar 23, 2026):

For me still is not working, although a valid LetsEncrypt key is issued. Here is the page I see:

Image

I am also on v0.66.4, self hosted

<!-- gh-comment-id:4109421978 --> @VPjoon commented on GitHub (Mar 23, 2026): For me still is not working, although a valid LetsEncrypt key is issued. Here is the page I see: <img width="1324" height="688" alt="Image" src="https://github.com/user-attachments/assets/7ea946a6-188f-42d8-a881-5455eca4186b" /> **I am also on v0.66.4, self hosted**
Author
Owner

@mculumov commented on GitHub (Apr 6, 2026):

I'm experiencing the same issue. It suddenly stopped working for certain services overnight, and since I am using the cloud version of Netbird, the 'Skip TLS Verification' option isn't available to me

<!-- gh-comment-id:4190678617 --> @mculumov commented on GitHub (Apr 6, 2026): I'm experiencing the same issue. It suddenly stopped working for certain services overnight, and since I am using the cloud version of Netbird, the 'Skip TLS Verification' option isn't available to me
Author
Owner

@alexisskeates commented on GitHub (Apr 7, 2026):

Been seeing this a lot as well. It seems to be hit and miss. Without changing anything sometimes it will work other times it wont. I was wondering if it was a rate limiting thing while still in beta. Using cloud version here as well.

<!-- gh-comment-id:4199103893 --> @alexisskeates commented on GitHub (Apr 7, 2026): Been seeing this a lot as well. It seems to be hit and miss. Without changing anything sometimes it will work other times it wont. I was wondering if it was a rate limiting thing while still in beta. Using cloud version here as well.
Author
Owner

@ppetrix commented on GitHub (Apr 22, 2026):

First thank you for your hard work @netbird.

Got Same error here, but only for ONE "service", from 6 "services" only ONE is not working. :((. Skip is checked for all. Tried all options: Rewrite Redirects on/off, etc. The only thing I don't know how to use is Custom Headers (is true that it is an old ILO interface, there is a quick start.html that redirects to login.html).
v0.69 linux
Cloud

<!-- gh-comment-id:4297365042 --> @ppetrix commented on GitHub (Apr 22, 2026): First thank you for your hard work @netbird. Got Same error here, but only for ONE "service", from 6 "services" only ONE is not working. :((. Skip is checked for all. Tried all options: Rewrite Redirects on/off, etc. The only thing I don't know how to use is Custom Headers (is true that it is an old ILO interface, there is a quick start.html that redirects to login.html). v0.69 linux Cloud
Author
Owner

@wm-ek commented on GitHub (May 24, 2026):

@lixmal

Still experiencing this issue on self-hosted setup using the official docker-compose.

Environment:

  • Netbird version: 0.74.4 7 / Dashboard 2.38.1 / Peer 0.71.4
  • Self-hosted (official docker-compose.yml with Traefik)
  • Backend: LiteSpeed Enterprise
  • Self-signed certificate with correct CN/SAN for the domain

Verified working:

  • curl --resolve with SNI → HTTP/2 200, correct certificate
  • Skip TLS Verification toggle: enabled
  • Result: Error 502

The backend service is confirmed reachable and responding correctly
via direct curl from within the Netbird network. The issue appears
to be in the proxy → backend TLS handling despite Skip TLS enabled.

<!-- gh-comment-id:4529198844 --> @wm-ek commented on GitHub (May 24, 2026): @lixmal Still experiencing this issue on self-hosted setup using the official docker-compose. **Environment:** - Netbird version: 0.74.4 7 / Dashboard 2.38.1 / Peer 0.71.4 - Self-hosted (official docker-compose.yml with Traefik) - Backend: LiteSpeed Enterprise - Self-signed certificate with correct CN/SAN for the domain **Verified working:** - curl --resolve with SNI → HTTP/2 200, correct certificate - Skip TLS Verification toggle: enabled - Result: Error 502 The backend service is confirmed reachable and responding correctly via direct curl from within the Netbird network. The issue appears to be in the proxy → backend TLS handling despite Skip TLS enabled.
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#10688