[GH-ISSUE #6020] Netbird Firewall is broken on OPNSense #12678

Open
opened 2026-08-05 02:06:26 -04:00 by saavagebueno · 7 comments
Owner

Originally created by @Cryotize on GitHub (Apr 28, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/6020

First of all, thanks for this great Software! I love the spirit, motivation and ideas that go into this. You're doing a really, really good job, Thanks! :)

Describe the problem

I want to use my Netbird Plugin on OPNSense as a Routing Peer for my VLANs, which are on the OPNSense.
But i also want to use it as a traditional VPN to access the Internet via OPNSense (Exit-Node)

Problem is, some users need both, some only need Internet access, without access to VLAN resources.
Now, when i enable the Netbird Firewall under the OPNsense GUI, nothing works, at all. No Internet, no VLAN resource access. I have tried it with All <-> All ACLs, no luck.

As soon as i disable this Firewall, everything seems to work. Problem is, the user group, where the OPNsense is assigned only as a exit node (no networks!), can also access my internal VLAN resources, even tho there is no ACL for it. This is because the Netbird Firewall on OPNSense is set to off (my guess at least), and my OPNSense obviously cannot know if the user should only see the internet, or also my VLAN resources.

To Reproduce

Steps to reproduce the behavior:

  1. Setup a Test "All <-> All" ACL in Netbird
  2. On the OPNsense, go to VPN -> Netbird -> Settings
  3. Enable the checkbox for "Enable Firewall"
  4. Restart Netbird
  5. Connect with a client
  6. Try to access a internal resouce that is assigned to the group, or try to access the internet.
    Expected behavior

Even with the Firewall enabled, i should be able to access the internet and local resources, depending on the ACL configured. If a client has a ACL only for the exit node, it should not be able to access internal resources.

Are you using NetBird Cloud?

No, Selfhosted.

NetBird version

OPNsense: 0.66.3
Client: 0.69.0

Is any other VPN software installed?

No

Screenshots

Image

Additional context

None

Have you tried these troubleshooting steps?

  • Reviewed client troubleshooting (if applicable)
  • Checked for newer NetBird versions
  • Searched for similar issues on GitHub (including closed ones)
  • Restarted the NetBird client
  • Disabled other VPN software
  • Checked firewall settings
Originally created by @Cryotize on GitHub (Apr 28, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/6020 First of all, thanks for this great Software! I love the spirit, motivation and ideas that go into this. You're doing a really, really good job, Thanks! :) **Describe the problem** I want to use my Netbird Plugin on OPNSense as a Routing Peer for my VLANs, which are on the OPNSense. But i also want to use it as a traditional VPN to access the Internet via OPNSense (Exit-Node) Problem is, some users need both, some only need Internet access, without access to VLAN resources. Now, when i enable the Netbird Firewall under the OPNsense GUI, nothing works, at all. No Internet, no VLAN resource access. I have tried it with All <-> All ACLs, no luck. As soon as i disable this Firewall, everything seems to work. Problem is, the user group, where the OPNsense is assigned **only** as a exit node (no networks!), can also access my internal VLAN resources, even tho there is no ACL for it. This is because the Netbird Firewall on OPNSense is set to off (my guess at least), and my OPNSense obviously cannot know if the user should only see the internet, or also my VLAN resources. **To Reproduce** Steps to reproduce the behavior: 1. Setup a Test "All <-> All" ACL in Netbird 2. On the OPNsense, go to VPN -> Netbird -> Settings 3. Enable the checkbox for "Enable Firewall" 4. Restart Netbird 5. Connect with a client 6. Try to access a internal resouce that is assigned to the group, or try to access the internet. **Expected behavior** Even with the Firewall enabled, i should be able to access the internet and local resources, depending on the ACL configured. If a client has a ACL only for the exit node, it should not be able to access internal resources. **Are you using NetBird Cloud?** No, Selfhosted. **NetBird version** OPNsense: 0.66.3 Client: 0.69.0 **Is any other VPN software installed?** No **Screenshots** <img width="965" height="971" alt="Image" src="https://github.com/user-attachments/assets/cf202255-db72-4e98-a59f-0d7a7ce995a8" /> **Additional context** None **Have you tried these troubleshooting steps?** - [x] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [x] Checked for newer NetBird versions - [x] Searched for similar issues on GitHub (including closed ones) - [x] Restarted the NetBird client - [x] Disabled other VPN software - [x] Checked firewall settings
saavagebueno added the triage-needed label 2026-08-05 02:06:26 -04:00
Author
Owner

@steeeeev0 commented on GitHub (Apr 28, 2026):

You need to create the Netbird interface within OPNsense, as well as the allow all rule in the firewall.

Go here and do the remaining steps:
https://docs.opnsense.org/manual/how-tos/netbird.html#assigning-the-interface

<!-- gh-comment-id:4340419546 --> @steeeeev0 commented on GitHub (Apr 28, 2026): You need to create the Netbird interface within OPNsense, as well as the allow all rule in the firewall. Go here and do the remaining steps: https://docs.opnsense.org/manual/how-tos/netbird.html#assigning-the-interface
Author
Owner

@Cryotize commented on GitHub (Apr 29, 2026):

I already followed the guide step by step that you have linked. So the Issue sadly persists.

<!-- gh-comment-id:4341258186 --> @Cryotize commented on GitHub (Apr 29, 2026): I already followed the guide step by step that you have linked. So the Issue sadly persists.
Author
Owner

@steeeeev0 commented on GitHub (Apr 29, 2026):

What does the OPNSense > VPN > Netbird > Status page say? Does it show any errors or connection details? Are networks listed as being advertised from the remote connections?

I have three OPNSense instances running and all works as expected:

macbook-steve.in.redacted.net: (showing as not connected)
NetBird IP: 100.69.33.12
Public key: redacted
Status: Connecting
-- detail --
Connection type: -
ICE candidate (Local/Remote): /
ICE candidate endpoints (Local/Remote): /
Relay server address:
Last connection update: 4 days, 20 hours ago
Last WireGuard handshake: 739734 days, 18 hours ago
Transfer status (received/sent): 0 B/0 B
Quantum resistance: false
Networks: -
Latency: 64.27 ms

opns201.in.redacted.net:
NetBird IP: 100.69.68.93
Public key: redacted
Status: Connected
-- detail --
Connection type: P2P
ICE candidate (Local/Remote): host/prflx
ICE candidate endpoints (Local/Remote): host/prflx
Relay server address: rels://redacted.net:443
Last connection update: 4 days, 20 hours ago
Last WireGuard handshake: 12 seconds ago
Transfer status (received/sent): 11.9 GiB/198.7 GiB
Quantum resistance: false
Networks: 10.2.1.0/27
Latency: 23.49 ms

opns301.in.redacted.net:
NetBird IP: 100.69.172.89
Public key: redacted
Status: Connected
-- detail --
Connection type: P2P
ICE candidate (Local/Remote): host/prflx
ICE candidate endpoints (Local/Remote): host/prflx
Relay server address: rels://redacted.net:443
Last connection update: 1 day, 19 hours ago
Last WireGuard handshake: 1 minute, 27 seconds ago
Transfer status (received/sent): 2.1 GiB/283.5 MiB
Quantum resistance: false
Networks: 10.3.1.0/27
Latency: 53.94 ms

Have you created a Gateway in OPNsense to the remote netbird IP and a corresponding static route to the remote subnet(s)?

Use the netbird IP of the remote peer:
Image

Create static routes to the new gateways and define the subnets or available IPs on the remote peer:
Image

It is possible ... hope this helps.

<!-- gh-comment-id:4346360403 --> @steeeeev0 commented on GitHub (Apr 29, 2026): What does the OPNSense > VPN > Netbird > Status page say? Does it show any errors or connection details? Are networks listed as being advertised from the remote connections? I have three OPNSense instances running and all works as expected: ``` macbook-steve.in.redacted.net: (showing as not connected) NetBird IP: 100.69.33.12 Public key: redacted Status: Connecting -- detail -- Connection type: - ICE candidate (Local/Remote): / ICE candidate endpoints (Local/Remote): / Relay server address: Last connection update: 4 days, 20 hours ago Last WireGuard handshake: 739734 days, 18 hours ago Transfer status (received/sent): 0 B/0 B Quantum resistance: false Networks: - Latency: 64.27 ms opns201.in.redacted.net: NetBird IP: 100.69.68.93 Public key: redacted Status: Connected -- detail -- Connection type: P2P ICE candidate (Local/Remote): host/prflx ICE candidate endpoints (Local/Remote): host/prflx Relay server address: rels://redacted.net:443 Last connection update: 4 days, 20 hours ago Last WireGuard handshake: 12 seconds ago Transfer status (received/sent): 11.9 GiB/198.7 GiB Quantum resistance: false Networks: 10.2.1.0/27 Latency: 23.49 ms opns301.in.redacted.net: NetBird IP: 100.69.172.89 Public key: redacted Status: Connected -- detail -- Connection type: P2P ICE candidate (Local/Remote): host/prflx ICE candidate endpoints (Local/Remote): host/prflx Relay server address: rels://redacted.net:443 Last connection update: 1 day, 19 hours ago Last WireGuard handshake: 1 minute, 27 seconds ago Transfer status (received/sent): 2.1 GiB/283.5 MiB Quantum resistance: false Networks: 10.3.1.0/27 Latency: 53.94 ms ``` Have you created a Gateway in OPNsense to the remote netbird IP and a corresponding static route to the remote subnet(s)? Use the netbird IP of the remote peer: <img width="924" height="581" alt="Image" src="https://github.com/user-attachments/assets/53aa1f11-3fda-43e4-a02d-44f585b71234" /> Create static routes to the new gateways and define the subnets or available IPs on the remote peer: <img width="937" height="345" alt="Image" src="https://github.com/user-attachments/assets/792b09a2-5d67-473c-9ede-bc465ef0f0ef" /> It is possible ... hope this helps.
Author
Owner

@Cryotize commented on GitHub (Apr 29, 2026):

Hmm, i think we're talking about different things here.

A Gateway won't help in my case - and like i've said, when i disable the Netbird Firewall, everything works.
I only have one OPNSense, and it Routes all Networks / Internet access for my remote devices (Phones, Laptops).

Here is my Status Page:

Daemon version: 0.66.3
CLI version: 0.66.3
Management: Connected to https://netbird.redacted.com:443
Signal: Connected to https://netbird.redacted.com:443
Relays: 
  [stun:netbird.redacted.com:3478] is Available
  [rels://netbird.redacted.com:443] is Available
Nameservers: 0/0 Available
FQDN: fw-redacted-01.nb.redacted.com
NetBird IP: 10.10.98.152/24
Interface type: Userspace
Quantum resistance: false
Lazy connection: false
Networks: 10.10.10.0/24, 10.10.100.0/24, 0.0.0.0/0
Forwarding rules: 0
Peers count: 1/8 Connected

and here is one of the Clients, as an example:

pixel-9-pro.nb.edacted.com:
  NetBird IP: 10.10.98.8
  Public key: redacted
  Status: Connected
  -- detail --
  Connection type: P2P
  ICE candidate (Local/Remote): host/prflx
  ICE candidate endpoints (Local/Remote): host/prflx
  Relay server address: rels://netbird.edacted.com:443
  Last connection update: 1 second ago
  Last WireGuard handshake: 2 seconds ago
  Transfer status (received/sent): 756 B/124 B
  Quantum resistance: false
  Networks: -
  Latency: 16.71 ms

Interesting thing i have observed: The Networks only show up on the status, when i have the Netbrid Firewall enabled.
Otherwise, nothing gets shown there.

I hope, this clarifies some things. If not, please tell me :)
I'm really thankful for your support!

<!-- gh-comment-id:4346798605 --> @Cryotize commented on GitHub (Apr 29, 2026): Hmm, i think we're talking about different things here. A Gateway won't help in my case - and like i've said, when i disable the Netbird Firewall, everything works. I only have one OPNSense, and it Routes all Networks / Internet access for my remote devices (Phones, Laptops). Here is my Status Page: ``` Daemon version: 0.66.3 CLI version: 0.66.3 Management: Connected to https://netbird.redacted.com:443 Signal: Connected to https://netbird.redacted.com:443 Relays: [stun:netbird.redacted.com:3478] is Available [rels://netbird.redacted.com:443] is Available Nameservers: 0/0 Available FQDN: fw-redacted-01.nb.redacted.com NetBird IP: 10.10.98.152/24 Interface type: Userspace Quantum resistance: false Lazy connection: false Networks: 10.10.10.0/24, 10.10.100.0/24, 0.0.0.0/0 Forwarding rules: 0 Peers count: 1/8 Connected ``` and here is one of the Clients, as an example: ``` pixel-9-pro.nb.edacted.com: NetBird IP: 10.10.98.8 Public key: redacted Status: Connected -- detail -- Connection type: P2P ICE candidate (Local/Remote): host/prflx ICE candidate endpoints (Local/Remote): host/prflx Relay server address: rels://netbird.edacted.com:443 Last connection update: 1 second ago Last WireGuard handshake: 2 seconds ago Transfer status (received/sent): 756 B/124 B Quantum resistance: false Networks: - Latency: 16.71 ms ``` Interesting thing i have observed: The Networks only show up on the status, when i have the Netbrid Firewall enabled. Otherwise, nothing gets shown there. I hope, this clarifies some things. If not, please tell me :) I'm really thankful for your support!
Author
Owner

@alfrede commented on GitHub (Apr 30, 2026):

When i look at the teoubleshooting guide, i see dns servers but in yout config there is no check by dns settings. You should have a look at that or try to make a tcpdump to see what are the differences by Firewall on and off.

<!-- gh-comment-id:4353232220 --> @alfrede commented on GitHub (Apr 30, 2026): When i look at the teoubleshooting guide, i see dns servers but in yout config there is no check by dns settings. You should have a look at that or try to make a tcpdump to see what are the differences by Firewall on and off.
Author
Owner

@crazifyngers commented on GitHub (May 30, 2026):

I had some issues with only my opnsense exit nodes or network routes. turns out when i use a quic relay it was sending packets that were too big for opnsense. 1414 after the tls encryption. This was not a problem with my linux exit nodes or network routes. i changed the mtu in the config.conf netbird file to 1100 on opnsense. this fixed the datagram too large issue.

<!-- gh-comment-id:4585532237 --> @crazifyngers commented on GitHub (May 30, 2026): I had some issues with only my opnsense exit nodes or network routes. turns out when i use a quic relay it was sending packets that were too big for opnsense. 1414 after the tls encryption. This was not a problem with my linux exit nodes or network routes. i changed the mtu in the config.conf netbird file to 1100 on opnsense. this fixed the datagram too large issue.
Author
Owner

@Cryotize commented on GitHub (Jun 4, 2026):

Thanks guys for the comments! Thing is, both ideas are unrelated to the problem i'm describing i think.
DNS can't be the issue because i'm not able to reach anything with a ping.
MTU size should also be no issue, because the behavior changes with different firewall rules... these don't affect the MTU.
I'm looking for someone who has managed to setup 2 access groups, one with internal network access via OPNSense, and one group which can only access internet via the OPNSense. I'm really starting to doubt that this is possible....

<!-- gh-comment-id:4625911615 --> @Cryotize commented on GitHub (Jun 4, 2026): Thanks guys for the comments! Thing is, both ideas are unrelated to the problem i'm describing i think. DNS can't be the issue because i'm not able to reach anything with a ping. MTU size should also be no issue, because the behavior changes with different firewall rules... these don't affect the MTU. I'm looking for someone who has managed to setup 2 access groups, one with internal network access via OPNSense, and one group which can only access internet via the OPNSense. I'm really starting to doubt that this is possible....
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#12678