[GH-ISSUE #5964] Routing via an exit node doesn't work on macOS if I only add one exit node #12567

Open
opened 2026-08-05 02:06:11 -04:00 by saavagebueno · 6 comments
Owner

Originally created by @Christopher87R on GitHub (Apr 22, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5964

Describe the problem

Routing via an exit node does not work on macOS if I add only one exit node.
There is a workaround: If I add a network (named "all") with the IP address 0.0.0.0/0 using the same routing node, it works even though the "all" network is disabled.

To Reproduce

Under "Network Routes," add a new exit node; all settings are default

Expected behavior

Adding an exit node under "Network Routes" should be sufficient to route all traffic through it.

Are you using NetBird Cloud?

Self-Hosted

  • Management: v0.69.0
  • Dashboard: v2.37.0

NetBird version

0.69.0

Is any other VPN software installed?
no

If yes, which one?

Debug output

To help us resolve the problem, please attach the following anonymized status output

netbird status -dA

Peers detail:
 iphone-christopher.netbird.selfhosted:
  NetBird IP: 100.76.134.206/32
  Public key: key
  Status: Idle
  -- detail --
  Connection type: -
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: 
  Last connection update: 1 minute, 36 seconds ago
  Last WireGuard handshake: -
  Transfer status (received/sent) 0 B/0 B
  Quantum resistance: false
  Networks: -
  Latency: 0s

 work05.netbird.selfhosted:
  NetBird IP: 100.76.180.62/32
  Public key: key
  Status: Idle
  -- detail --
  Connection type: -
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: 
  Last connection update: 1 minute, 36 seconds ago
  Last WireGuard handshake: -
  Transfer status (received/sent) 0 B/0 B
  Quantum resistance: false
  Networks: -
  Latency: 0s

 instance-xyz.netbird.selfhosted:
  NetBird IP: 100.76.57.247
  Public key: key
  Status: Connected
  -- detail --
  Connection type: P2P
  ICE candidate (Local/Remote): srflx/srflx
  ICE candidate endpoints (Local/Remote): 198.51.100.0:51820/198.51.100.1:57077
  Relay server address: rels://netbird.anon-441J7.domain:443
  Last connection update: 11 minutes, 22 seconds ago
  Last WireGuard handshake: 58 seconds ago
  Transfer status (received/sent) 584 B/1.9 KiB
  Quantum resistance: false
  Networks: -
  Latency: 78.219041ms

 raspberrypi.netbird.selfhosted:
  NetBird IP: 100.76.88.237
  Public key: key
  Status: Connected
  -- detail --
  Connection type: Relayed
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: rels://netbird.anon-441J7.domain:443
  Last connection update: 11 minutes, 23 seconds ago
  Last WireGuard handshake: 2 minutes, 38 seconds ago
  Transfer status (received/sent) 752 B/1.2 KiB
  Quantum resistance: false
  Networks: -
  Latency: 0s

 christopherwindows.netbird.selfhosted:
  NetBird IP: 100.76.118.4
  Public key: key
  Status: Connecting
  -- detail --
  Connection type: -
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: 
  Last connection update: 11 minutes, 23 seconds ago
  Last WireGuard handshake: -
  Transfer status (received/sent) 0 B/0 B
  Quantum resistance: false
  Networks: -
  Latency: 0s

 pve.netbird.selfhosted:
  NetBird IP: 100.76.137.232
  Public key: key
  Status: Connected
  -- detail --
  Connection type: Relayed
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: rels://netbird.anon-441J7.domain:443
  Last connection update: 11 minutes, 23 seconds ago
  Last WireGuard handshake: 58 seconds ago
  Transfer status (received/sent) 744 B/1.9 KiB
  Quantum resistance: false
  Networks: -
  Latency: 0s

 xxxxx.netbird.selfhosted:
  NetBird IP: 100.76.158.240
  Public key: key
  Status: Connected
  -- detail --
  Connection type: P2P
  ICE candidate (Local/Remote): srflx/host
  ICE candidate endpoints (Local/Remote): 198.51.100.0:51820/198.51.100.2:52820
  Relay server address: rels://netbird.anon-441J7.domain:443
  Last connection update: 11 minutes, 23 seconds ago
  Last WireGuard handshake: 30 seconds ago
  Transfer status (received/sent) 1.3 MiB/676.1 KiB
  Quantum resistance: false
  Networks: -
  Latency: 57.505792ms

 debian.netbird.selfhosted:
  NetBird IP: 100.76.224.35
  Public key: key
  Status: Connected
  -- detail --
  Connection type: Relayed
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: rels://netbird.anon-441J7.domain:443
  Last connection update: 8 minutes, 59 seconds ago
  Last WireGuard handshake: 39 seconds ago
  Transfer status (received/sent) 492 B/1.5 KiB
  Quantum resistance: false
  Networks: -
  Latency: 0s

Events:
  [INFO] SYSTEM (f8c9965d-7ca0-44ac-945b-809de156e3d8)
    Message: Network map updated
    Time: 9 minutes, 48 seconds ago
  [INFO] SYSTEM (e1b8ec14-2507-4495-b935-e4fc174287eb)
    Message: Network selection changed
    Time: 8 minutes, 49 seconds ago
    Metadata: all: false, append: true, networks: Netcup Exit Node
  [INFO] NETWORK (88f5548c-6ade-4d44-8e0b-3729dd399fbf)
    Message: Default route added
    Time: 8 minutes, 49 seconds ago
    Metadata: id: Netcup Exit Node, network: 0.0.0.0/0, peer: /38tiyHRLDtBVHdBpDQy4Ilgm8pVEgi1hP1UypXGslc=
  [INFO] NETWORK (1a601fa9-0890-43b1-9e9f-d106606278df)
    Message: Default route added
    Time: 8 minutes, 49 seconds ago
    Metadata: id: Netcup Exit Node, network: 0.0.0.0/0, peer: /38tiyHRLDtBVHdBpDQy4Ilgm8pVEgi1hP1UypXGslc=
  [INFO] SYSTEM (641c2623-f068-49d3-b058-8d04d2c34928)
    Message: Network map updated
    Time: 8 minutes, 4 seconds ago
  [INFO] NETWORK (b58495db-bfee-49cc-98c4-ecc7330c5b27)
    Message: Default route removed
    Time: 7 minutes, 52 seconds ago
    Metadata: id: Netcup Exit Node, network: 0.0.0.0/0, peer: /38tiyHRLDtBVHdBpDQy4Ilgm8pVEgi1hP1UypXGslc=
  [INFO] SYSTEM (57abb8f3-fe96-4ac4-9866-3cae547ef52e)
    Message: Network deselection changed
    Time: 7 minutes, 52 seconds ago
    Metadata: all: false, append: false, networks: Netcup Exit Node
  [INFO] SYSTEM (070a37ec-4de5-4a03-8fe7-a96be2046f7e)
    Message: Network map updated
    Time: 5 minutes, 56 seconds ago
  [INFO] SYSTEM (ebb132f3-2071-4808-8404-3bca28995995)
    Message: Network map updated
    Time: 3 minutes, 47 seconds ago
  [INFO] SYSTEM (5a2c417b-4f34-47e2-8ece-4776f7268524)
    Message: Network map updated
    Time: 1 minute, 36 seconds ago
OS: darwin/arm64
Daemon version: 0.69.0
CLI version: 0.69.0
Profile: default
Management: Connected to https://netbird.anon-441J7.domain:443
Signal: Connected to https://netbird.anon-441J7.domain:443
Relays: 
  [stun:stun.netbird.anon-441J7.domain:3478] is Available
  [rels://netbird.anon-441J7.domain:443] is Available
Nameservers: 
  [8.8.8.8:53, 8.8.4.4:53] for [.] is Available
FQDN: macbookpro.netbird.selfhosted
NetBird IP: 100.76.96.30/16
Interface type: Userspace
Quantum resistance: false
Lazy connection: false
SSH Server: Disabled
Networks: -
Peers count: 5/8 Connected

Create and upload a debug bundle, and share the returned file key:

netbird debug for 1m -AS -U
ca33ea3e2480c16948013fa957822358bcf757eb1dbfa4896438de18ef0c77c9/66b7fe1e-605a-4389-b64e-f86c205933e0

Uploaded files are automatically deleted after 30 days.

Alternatively, create the file only and attach it here manually:

netbird debug for 1m -AS
With enabled exit-node, upload was not possible

netbird.debug.2505071488.zip

Screenshots

Image Image

Additional context

Add any other context about the problem here.

Have you tried these troubleshooting steps?

  • [ x] Reviewed client troubleshooting (if applicable)
  • [ x] Checked for newer NetBird versions
  • [ x] Searched for similar issues on GitHub (including closed ones)
  • [ x] Restarted the NetBird client
  • [ x] Disabled other VPN software
  • [ x] Checked firewall settings
Originally created by @Christopher87R on GitHub (Apr 22, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/5964 **Describe the problem** Routing via an exit node does not work on macOS if I add only one exit node. There is a workaround: If I add a network (named "all") with the IP address 0.0.0.0/0 using the same routing node, it works even though the "all" network is disabled. **To Reproduce** Under "Network Routes," add a new exit node; all settings are default **Expected behavior** Adding an exit node under "Network Routes" should be sufficient to route all traffic through it. **Are you using NetBird Cloud?** Self-Hosted - Management: v0.69.0 - Dashboard: v2.37.0 **NetBird version** 0.69.0 **Is any other VPN software installed?** no If yes, which one? **Debug output** To help us resolve the problem, please attach the following anonymized status output netbird status -dA ``` Peers detail: iphone-christopher.netbird.selfhosted: NetBird IP: 100.76.134.206/32 Public key: key Status: Idle -- detail -- Connection type: - ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: Last connection update: 1 minute, 36 seconds ago Last WireGuard handshake: - Transfer status (received/sent) 0 B/0 B Quantum resistance: false Networks: - Latency: 0s work05.netbird.selfhosted: NetBird IP: 100.76.180.62/32 Public key: key Status: Idle -- detail -- Connection type: - ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: Last connection update: 1 minute, 36 seconds ago Last WireGuard handshake: - Transfer status (received/sent) 0 B/0 B Quantum resistance: false Networks: - Latency: 0s instance-xyz.netbird.selfhosted: NetBird IP: 100.76.57.247 Public key: key Status: Connected -- detail -- Connection type: P2P ICE candidate (Local/Remote): srflx/srflx ICE candidate endpoints (Local/Remote): 198.51.100.0:51820/198.51.100.1:57077 Relay server address: rels://netbird.anon-441J7.domain:443 Last connection update: 11 minutes, 22 seconds ago Last WireGuard handshake: 58 seconds ago Transfer status (received/sent) 584 B/1.9 KiB Quantum resistance: false Networks: - Latency: 78.219041ms raspberrypi.netbird.selfhosted: NetBird IP: 100.76.88.237 Public key: key Status: Connected -- detail -- Connection type: Relayed ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: rels://netbird.anon-441J7.domain:443 Last connection update: 11 minutes, 23 seconds ago Last WireGuard handshake: 2 minutes, 38 seconds ago Transfer status (received/sent) 752 B/1.2 KiB Quantum resistance: false Networks: - Latency: 0s christopherwindows.netbird.selfhosted: NetBird IP: 100.76.118.4 Public key: key Status: Connecting -- detail -- Connection type: - ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: Last connection update: 11 minutes, 23 seconds ago Last WireGuard handshake: - Transfer status (received/sent) 0 B/0 B Quantum resistance: false Networks: - Latency: 0s pve.netbird.selfhosted: NetBird IP: 100.76.137.232 Public key: key Status: Connected -- detail -- Connection type: Relayed ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: rels://netbird.anon-441J7.domain:443 Last connection update: 11 minutes, 23 seconds ago Last WireGuard handshake: 58 seconds ago Transfer status (received/sent) 744 B/1.9 KiB Quantum resistance: false Networks: - Latency: 0s xxxxx.netbird.selfhosted: NetBird IP: 100.76.158.240 Public key: key Status: Connected -- detail -- Connection type: P2P ICE candidate (Local/Remote): srflx/host ICE candidate endpoints (Local/Remote): 198.51.100.0:51820/198.51.100.2:52820 Relay server address: rels://netbird.anon-441J7.domain:443 Last connection update: 11 minutes, 23 seconds ago Last WireGuard handshake: 30 seconds ago Transfer status (received/sent) 1.3 MiB/676.1 KiB Quantum resistance: false Networks: - Latency: 57.505792ms debian.netbird.selfhosted: NetBird IP: 100.76.224.35 Public key: key Status: Connected -- detail -- Connection type: Relayed ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: rels://netbird.anon-441J7.domain:443 Last connection update: 8 minutes, 59 seconds ago Last WireGuard handshake: 39 seconds ago Transfer status (received/sent) 492 B/1.5 KiB Quantum resistance: false Networks: - Latency: 0s Events: [INFO] SYSTEM (f8c9965d-7ca0-44ac-945b-809de156e3d8) Message: Network map updated Time: 9 minutes, 48 seconds ago [INFO] SYSTEM (e1b8ec14-2507-4495-b935-e4fc174287eb) Message: Network selection changed Time: 8 minutes, 49 seconds ago Metadata: all: false, append: true, networks: Netcup Exit Node [INFO] NETWORK (88f5548c-6ade-4d44-8e0b-3729dd399fbf) Message: Default route added Time: 8 minutes, 49 seconds ago Metadata: id: Netcup Exit Node, network: 0.0.0.0/0, peer: /38tiyHRLDtBVHdBpDQy4Ilgm8pVEgi1hP1UypXGslc= [INFO] NETWORK (1a601fa9-0890-43b1-9e9f-d106606278df) Message: Default route added Time: 8 minutes, 49 seconds ago Metadata: id: Netcup Exit Node, network: 0.0.0.0/0, peer: /38tiyHRLDtBVHdBpDQy4Ilgm8pVEgi1hP1UypXGslc= [INFO] SYSTEM (641c2623-f068-49d3-b058-8d04d2c34928) Message: Network map updated Time: 8 minutes, 4 seconds ago [INFO] NETWORK (b58495db-bfee-49cc-98c4-ecc7330c5b27) Message: Default route removed Time: 7 minutes, 52 seconds ago Metadata: id: Netcup Exit Node, network: 0.0.0.0/0, peer: /38tiyHRLDtBVHdBpDQy4Ilgm8pVEgi1hP1UypXGslc= [INFO] SYSTEM (57abb8f3-fe96-4ac4-9866-3cae547ef52e) Message: Network deselection changed Time: 7 minutes, 52 seconds ago Metadata: all: false, append: false, networks: Netcup Exit Node [INFO] SYSTEM (070a37ec-4de5-4a03-8fe7-a96be2046f7e) Message: Network map updated Time: 5 minutes, 56 seconds ago [INFO] SYSTEM (ebb132f3-2071-4808-8404-3bca28995995) Message: Network map updated Time: 3 minutes, 47 seconds ago [INFO] SYSTEM (5a2c417b-4f34-47e2-8ece-4776f7268524) Message: Network map updated Time: 1 minute, 36 seconds ago OS: darwin/arm64 Daemon version: 0.69.0 CLI version: 0.69.0 Profile: default Management: Connected to https://netbird.anon-441J7.domain:443 Signal: Connected to https://netbird.anon-441J7.domain:443 Relays: [stun:stun.netbird.anon-441J7.domain:3478] is Available [rels://netbird.anon-441J7.domain:443] is Available Nameservers: [8.8.8.8:53, 8.8.4.4:53] for [.] is Available FQDN: macbookpro.netbird.selfhosted NetBird IP: 100.76.96.30/16 Interface type: Userspace Quantum resistance: false Lazy connection: false SSH Server: Disabled Networks: - Peers count: 5/8 Connected ``` Create and upload a debug bundle, and share the returned file key: netbird debug for 1m -AS -U ca33ea3e2480c16948013fa957822358bcf757eb1dbfa4896438de18ef0c77c9/66b7fe1e-605a-4389-b64e-f86c205933e0 *Uploaded files are automatically deleted after 30 days.* Alternatively, create the file only and attach it here manually: netbird debug for 1m -AS With enabled exit-node, upload was not possible [netbird.debug.2505071488.zip](https://github.com/user-attachments/files/26969193/netbird.debug.2505071488.zip) **Screenshots** <img width="1543" height="748" alt="Image" src="https://github.com/user-attachments/assets/5839a064-4149-4d8e-9ea5-55177717cb67" /> <img width="1584" height="650" alt="Image" src="https://github.com/user-attachments/assets/6e580d8b-d8a4-464a-aeb0-f5bf638725a2" /> **Additional context** Add any other context about the problem here. **Have you tried these troubleshooting steps?** - [ x] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [ x] Checked for newer NetBird versions - [ x] Searched for similar issues on GitHub (including closed ones) - [ x] Restarted the NetBird client - [ x] Disabled other VPN software - [ x] Checked firewall settings
saavagebueno added the triage-needed label 2026-08-05 02:06:11 -04:00
Author
Owner

@Christopher87R commented on GitHub (May 7, 2026):

any update on this issue - it's still not working with the most recent version?

<!-- gh-comment-id:4398258148 --> @Christopher87R commented on GitHub (May 7, 2026): any update on this issue - it's still not working with the most recent version?
Author
Owner

@lixmal commented on GitHub (May 7, 2026):

Do you have a policy in place like mentioned in the box here https://docs.netbird.io/manage/network-routes/use-cases/by-scenario/exit-nodes#distribution-groups

The minimum access policy required for peers to use an exit node is Users (source) → Routing Peer (destination) over ICMP. Ensure a policy with this configuration exists for the distribution groups assigned to the exit node route.

<!-- gh-comment-id:4398533071 --> @lixmal commented on GitHub (May 7, 2026): Do you have a policy in place like mentioned in the box here https://docs.netbird.io/manage/network-routes/use-cases/by-scenario/exit-nodes#distribution-groups >The minimum access policy required for peers to use an exit node is Users (source) → Routing Peer (destination) over ICMP. Ensure a policy with this configuration exists for the distribution groups assigned to the exit node route.
Author
Owner

@Christopher87R commented on GitHub (May 7, 2026):

Do you have a policy in place like mentioned in the box here https://docs.netbird.io/manage/network-routes/use-cases/by-scenario/exit-nodes#distribution-groups

The minimum access policy required for peers to use an exit node is Users (source) → Routing Peer (destination) over ICMP. Ensure a policy with this configuration exists for the distribution groups assigned to the exit node route.

Sure, I did.

Here's how I see it: I have two options for routing all traffic through a single node.
Manually, by defining a network with a resource and the address 0.0.0.0/0, along with the appropriate routing peers—this method works!

A slightly more convenient option is via the “Network Routes” section—but unfortunately, it doesn't work here, despite the policy.

<!-- gh-comment-id:4399142313 --> @Christopher87R commented on GitHub (May 7, 2026): > Do you have a policy in place like mentioned in the box here https://docs.netbird.io/manage/network-routes/use-cases/by-scenario/exit-nodes#distribution-groups > > > The minimum access policy required for peers to use an exit node is Users (source) → Routing Peer (destination) over ICMP. Ensure a policy with this configuration exists for the distribution groups assigned to the exit node route. Sure, I did. Here's how I see it: I have two options for routing all traffic through a single node. Manually, by defining a network with a resource and the address 0.0.0.0/0, along with the appropriate routing peers—this method works! A slightly more convenient option is via the “Network Routes” section—but unfortunately, it doesn't work here, despite the policy.
Author
Owner

@leoneltrich commented on GitHub (May 12, 2026):

It's also not working for me, I would much appreciate a fix :(

<!-- gh-comment-id:4432865350 --> @leoneltrich commented on GitHub (May 12, 2026): It's also not working for me, I would much appreciate a fix :(
Author
Owner

@Christopher87R commented on GitHub (May 12, 2026):

I also checked it for windows and it’s also not working

<!-- gh-comment-id:4433297057 --> @Christopher87R commented on GitHub (May 12, 2026): I also checked it for windows and it’s also not working
Author
Owner

@mohammedsalameh-spec commented on GitHub (May 25, 2026):

Hello, I also am having simialr issue, on linux ubuntu even when I manually setup netowrk, the traffic is passing through the peer set as exist node, but it is not masquerading. meaning I cannot access blocked sites from my pc even if the peer can access them and it is set as exit node.
https://github.com/netbirdio/netbird/discussions/6187

but as your scenrio just to route traffic without masquerading, it was done and applied through network routes and I have the same setup.

try assigning the exit node by clicking the little green shape near the peer name in peer dashboard, check the configurations generated if they match yours. also apply the flag "auto apply" for this exist node network route.

this simple way of adding an exit node worked for me (for routing only, without masquerading)

<!-- gh-comment-id:4532221714 --> @mohammedsalameh-spec commented on GitHub (May 25, 2026): Hello, I also am having simialr issue, on linux ubuntu even when I manually setup netowrk, the traffic is passing through the peer set as exist node, but it is not masquerading. meaning I cannot access blocked sites from my pc even if the peer can access them and it is set as exit node. https://github.com/netbirdio/netbird/discussions/6187 but as your scenrio just to route traffic without masquerading, it was done and applied through network routes and I have the same setup. try assigning the exit node by clicking the little green shape near the peer name in peer dashboard, check the configurations generated if they match yours. also apply the flag "auto apply" for this exist node network route. this simple way of adding an exit node worked for me (for routing only, without masquerading)
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#12567