mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-05 00:15:26 -04:00
[GH-ISSUE #6022] NetBird netbird-acl-forward-filter drops k3s/kube-router-forwarded VPN traffic due to mark-bit collision with kube-router netpol
#12684
Open
opened 2026-08-05 02:06:27 -04:00 by saavagebueno
·
3 comments
No Branch/Tag Specified
main
claude/agent-network-test-cases-p743vw
android/gui-integration
revert/component-types
feat-post_quantum_ml_kem
ice-stun-wg-demux
dependabot/npm_and_yarn/proxy/web/npm_and_yarn-b39864987c
agent-network-setup-poc
dependabot/go_modules/aws-sdk-8f849ebaed
dependabot/github_actions/actions-a940c7c866
dependabot/go_modules/otel-e34c790afd
dependabot/go_modules/testcontainers-de325c0dd6
dependabot/go_modules/wireguard-dbd6b95108
dependabot/go_modules/pion-5f703e1eca
dependabot/go_modules/gorm-2271c8195b
fix-login-needed-check
dependabot/go_modules/google.golang.org/grpc-1.82.1
fix/ui-gtk3-support
enterprise-traefik-and-migration-fixes
disambiguate_p2p_metrics
revert/component-types-hookup
embedded-vnc
feature/ios-ssh
docs/agent-network-docs-update
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.106.3
dependabot/go_modules/github.com/pion/stun/v3-3.1.5
fix-ssh-authorized-users-multi-rule
peer-acl-multi-source
reverse-proxy-crowdsec-appsec
reverse-proxy-allow-match-or
client-local-metrics
lazy-conn-per-peer
lazy-conn-rosenpass
dependabot/go_modules/github.com/gopacket/gopacket-1.7.0
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.6
dependabot/go_modules/github.com/pires/go-proxyproto-0.15.0
dependabot/go_modules/github.com/jackc/pgx/v5-5.10.0
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.4
dependabot/go_modules/github.com/pkg/sftp-1.13.11
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.20.0
ssh-windows-privilege-check
fix/explicit-cors-handling
fix/remove-math-rand
test/gui-memory-leak-fix
fix/ui-status-dispatch
install-script-ui-dependencies
fix/grpc-get-network-map
fix/subscribe-status-coalesce
fix/tray-menu-item-leak
fix/windows-tray-race
feature/changeset
worktree-dns-route-qtype-fallthrough
mdm_integration
mlsmaycon-patch-2
feat/agent-network-ollama
proxy-tunnel-cache-ttl-env
coderabbitai/utg/1e5b0a5
grpc-acl
test/battery-drain
components-impl-drop-indexes-use-xids-no-resource-policy-map
fix/nmap-relevant-groups
e2e-guardrail-blocks-unselected-model
fix/lazyconn-cold-start-allowed-ips
vertex-guardrails-model-access-e2e
add-atomic-cache-ops
refactor/relay-foreign-cache
ci/trigger-release-tests
feature/kimi-3-agent-networks-dns-warmup
feature/dns-lazy-conn-warmup
daemon-ipc-acl
feature/ui-translation-key-parity-check
refactor/relay-foreign-cache-tests
fix/lazyconn-idle-keep-wg-peer
dmitri-propagate-auth-grant-types-on-combined
0.74.7-branch
diagnose-empty-vs-corrupt-state
windows-sleep-detector
fix/cli-up-wait-for-daemon
rp_key_persistency
feature/native-grpc
0.74.6-branch
0.74.6-branch-sync
0.74.5-branch-sync
0.74.4-branch
fix/remove-stale-peers-removal
fix/remove-stale-proxy-logic
fix/nsis-preserve-autostart-on-upgrade
refactor/peer-event-bus
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3
dependabot/go_modules/github.com/pkg/sftp-1.13.10
components-impl-drop-indexes
fix-reset-aggregation-window-flake
dependabot/go_modules/github.com/pion/dtls/v3-3.1.5
0.74.x
fix/relay-states-lock
update-process-pkg
update-gopsutil-v4
fix/relay_states_lock
increase-sysinfo-timeout
dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
dependabot/go_modules/github.com/eko/gocache/store/redis/v4-4.2.6
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.3
fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
0.74.3-branch
fix/routeselector-atomic-exit-node
netmap_progressive_alignment
nmap/components-impl
dependabot/go_modules/github.com/jackc/pgx/v5-5.9.2
dependabot/go_modules/github.com/oapi-codegen/runtime-1.4.2
dependabot/go_modules/github.com/gopacket/gopacket-1.6.1
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0
dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0
fix/signal-watchdog-sync-stop
docs/agent-network
test/affected-logic
fix/revert-ice-filter
refactor/simplify-affected-peers
pascal-filter-policies-by-direction
claude/lock-contention-peer-connect-g8t6au
dmitri-filter-policies-by-direction
refactor/migrate-profiles-to-go
profile-bindings-ios
fix/skip-restart-unchanged-route
fix/mgmt-cache-async-resolve
refactor/wails-update-105
client_lifetime_serialization_refactor
fix/browser-ssh-2
fix/ipv6-and-netstack-accept-loop
fix/browser-ssh
profile-id-name-test
refactor/mgmt-bootstrap
feat/getting-started-unified-wizard
socket-grpc-permissions
fix/mysql-index-migration
windows-dns-firewall
tests/enable-race-on-tests
ui-refactor-gtk3
feature/affected-peers-grpc
profile-id
lazyconn-first-packet-fix-v2
claude/focused-gates-VMTgb
ui-tray-linux-leftclick
fix/ctx-enrichment
daemon-owner
feature/android-client-ssh
worktree-accept-ra-forwarding
nmap/combined-deploy
task/align_protobuff_toolset
feature/session-extend
add-json-yaml-flags
refactor/ephemeral-cleanup
claude/webtransport-relay-wasm-mUjY9
claude/vnc-udp-feasibility-6KB1U
fix/wgport-config
e2e-windows-dns-combined
fix/login-cmd-root-flags
feat/reseller-openapi-spec
github-issue-resolver
add-steamos-support
fix-darwin-uninstaller
flutter-test
ci/freebsd-pkg-bootstrap
cached-serial-check-on-sync
fix-mgmt-cache-bypass-overlay
revert-easyjson-5938
revert-ice-5820
revert-firewalld-5928
refactor/permissions-manager
revert-dns-5935-systemd-resolved
revert-dns-5935-5945
revert-dns-5945-mgmt-cache
feature/log-most-busy-peers
prototype/ui-wails
coderabbitai/utg/8ae8f20
feature/use-peer-fqdn-on-https
release/0.68.3
add-slack-channel
claude/rdp-token-passthrough-eNcqW
transparent-proxy
fix/macos-stale-route-eexist
crowdsec-selfhosted
fix/remove-otel-units
entire/checkpoints/v1
fix/getting-started
feat/static-connectors-combined-server
feature/use-local-keys-embedded
feature/fleetdm
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.76.1
v0.76.0
v0.75.1
v0.75.0
v0.74.7
v0.74.6
v0.74.5
v0.75.0-rc.6
v0.74.4
v0.74.3
v0.75.0-rc.5
v0.74.2
v0.74.1
v0.75.0-rc.4
v0.74.0
v0.74.0-rc.2
v0.74.0-rc.1
v0.73.2
v0.75.0-rc.3
v0.75.0-rc.2
v0.73.1
v0.75.0-rc.1
v0.73.0
v0.72.4
v0.72.3
v0.72.2
v0.72.1
v0.72.0
v0.71.4
v0.71.3
v0.71.2
v0.71.1
v0.71.0
v0.70.5
v0.70.4
v0.70.3
v0.70.2
v0.70.1
v0.70.0
v0.69.0
v0.68.3
v0.68.2
v0.68.1
v0.68.0
v0.67.4
v0.67.3
v0.67.2
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2021 Q4
2021 Q4
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
accessibility
accessibility
accessibility
acl
acl
acl
agent
agent
agent
agent
agent
agent
Android
Android
Android
Android
Android
Android
api
api
api
authentik
authentik
authentik
automation
automation
automation
azure
azure
azure
battery-usage
battery-usage
battery-usage
bug
cache
cache
cache
client
client
client
client-ui
client-ui
client-ui
cloud
cloud
cloud
cloud-only
cloud-only
cloud-only
cloudflare
cloudflare
cloudflare
community
community
community
compatibility
compatibility
compatibility
config-idp
config-idp
config-idp
config-issue
config-issue
config-issue
connection
connection
connection
contribution
contribution
contribution
coturn
coturn
coturn
cross-vpn
cross-vpn
cross-vpn
dashboard
dashboard
dashboard
data-usage
data-usage
data-usage
distribution
distribution
distribution
dns
dns
dns
docker
docker
docker
documentation
documentation
documentation
duplicate
duplicate
duplicate
enhancement
enhancement
event-stream
event-stream
event-stream
feature-request
feature-request
feature-request
freebsd
freebsd
freebsd
getting-started
getting-started
getting-started
go
go
go
good first issue
good first issue
good first issue
gui
gui
gui
help wanted
help wanted
help wanted
home-assistant
home-assistant
home-assistant
idp
idp
idp
inconsistency
inconsistency
inconsistency
integration
integration
integration
integrations
integrations
integrations
ios
ios
ios
ipv6
ipv6
ipv6
jwt
jwt
jwt
k8s
k8s
k8s
keycloak
keycloak
keycloak
linux
linux
linux
login
login
login
macos
macos
macos
management-service
management-service
management-service
Medium
Medium
Medium
missing-docs
missing-docs
missing-docs
mobile
mobile
mobile
moved-internal
moved-internal
moved-internal
needs-review
needs-review
needs-review
netbird-ui
netbird-ui
netbird-ui
networking
networking
networking
new-platform
new-platform
new-platform
nginx
nginx
nginx
notification
notification
notification
okta
okta
okta
openwrt
openwrt
openwrt
P2
P2
P2
packaging
packaging
packaging
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
performance
performance
performance
postgres
postgres
postgres
posture-checks
posture-checks
posture-checks
psk
psk
psk
pull-request
question
question
question
refactor
refactor
refactor
relay
relay
relay
release
release
release
rfc
rfc
rfc
routes
routes
routes
security
security
security
security-improvement
security-improvement
security-improvement
security-related
security-related
security-related
self-hosting
self-hosting
self-hosting
server
server
server
signal
signal
signal
sleep-issue
sleep-issue
sleep-issue
ssh
ssh
ssh
ssl
ssl
ssl
status
status
status
store
store
store
synology
synology
synology
system-compatibility-issue
system-compatibility-issue
system-compatibility-issue
test-suite
test-suite
test-suite
third-party-integration
third-party-integration
third-party-integration
triage
triage
triage
triage
triage
triage
triage-needed
triage-needed
triage-needed
troubleshooting
troubleshooting
troubleshooting
UX
UX
UX
waiting-feedback
waiting-feedback
waiting-feedback
windows
windows
windows
wontfix
wontfix
wontfix
zitadel
zitadel
zitadel
Mirrored from GitHub Pull Request
No Label
triage-needed
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: DYNR/netbird#12684
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @snowzach on GitHub (Apr 28, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/6022
NetBird
netbird-acl-forward-filterdrops k3s/kube-router-forwarded VPN traffic due to mark-bit collision with kube-router netpolI'm not gonna lie, the robots helped me figure it out but it does seem like k3s and netbird rules trample each other.
Version 0.70.0
TL;DR
NetBird's
netbird-acl-forward-filterchain identifies "VPN-peer → local-host" traffic by ameta mark 0x0001bd20set innetbird-mangle-prerouting. Bit0x10000is set inside that mark. kube-router's per-pod NetworkPolicy chain (KUBE-POD-FW-*) uses bit0x10000as its own "policy-permitted" flag and unconditionally clears it at the end of every per-pod evaluation. After kube-router's iptables FORWARD chain runs, the packet's mark is0x0002bd20instead of0x0001bd20, so NetBird'smeta mark 0x0001bd20 acceptrule no longer matches and the packet falls through to the chain's catch-alliifname "wt0" drop.The collision is silent — no rejects, no logs from either side.
NB_DISABLE_FIREWALL=trueworks around it by removing NetBird's nftables table entirely.Environment
0.70.0nf_tablesbackend; iptables binary is iptables-nft)traefik-37.1.0, imagedocker.io/traefik:v3.5.1, Servicetype: ClusterIP, Deployment withhostPort: 80 → 8080andhostPort: 443 → 8443declared on the container; reachable from outside via the CNI portmap plugin writingCNI-DN-…DNAT rules innattablePREROUTING/OUTPUTwt0,10.79.25.88/18, peer subnet10.79.0.0/1810.79.43.248, attemptingcurl https://api-prod-tyo3-01:443Symptom
<host-wt0-IP>:443arrives onwt0and times out (no SYN-ACK, no RST).localhostsucceed.systemctl restart netbird, VPN→host:443 works for ~60s then fails again. (Believed to coincide with kube-router's periodic iptables sync re-registering its base chains after NetBird's, flipping evaluation order at the same hook priority.)NB_DISABLE_FIREWALL=trueresolves the issue permanently.Diagnostic trace
1. Packet enters and is correctly marked + DNAT'd
dmesg LOGs added at every netfilter hook (
iptables -t … -I … 1 -j LOG) showed:So far so good. NetBird's mark is the post-DNAT value still
0x1bd20.2. Packet never reaches the egress interface
tcpdump -ni any 'host 10.79.43.248 or host 10.42.0.17'shows the packet onwt0 Inonly — never oncni0, never on anyveth*. The pod never receives the SYN.net.ipv4.ip_forward = 1,ip route get 10.42.0.17 → dev cni0, all interface-level forwarding sysctls = 1,rp_filter = 2(loose). Routing is fine.3. NetBird's nftables table
In isolation, the SYN's mark is
0x0001bd20when entering the FORWARD hook, someta mark 0x0001bd20 acceptshould match.4. Mark collision with kube-router
iptables FORWARD also runs at
hook forward priority filter(= 0) — same priority asnetbird-acl-forward-filter. Its first rule is:…which dispatches into per-pod chains (
KUBE-POD-FW-…). The traefik pod's chain ends with the standard kube-router epilogue:The collision:
So when control returns to
netbird-acl-forward-filter, the packet's mark is0x0002bd20, not0x0001bd20. NetBird'smeta mark 0x0001bd20 acceptno longer matches; the packet falls through toiifname "wt0" dropand is silently dropped.5. Why it works for ~60s after a restart
Both NetBird's
netbird-acl-forward-filterand the iptables-compatFORWARDchain hookforwardat the same priority. Order of evaluation between two base chains at the same hook+priority is determined by registration order.systemctl restart netbird, NetBird re-registers its chain after iptables — so iptables FORWARD evaluates first, kube-router clears bit0x10000, and NetBird's mark-accept rule misses. It should already be broken.iptables-restore, re-registers its base chain, and the eval order swaps. From that moment on the bit-clearing wins and NetBird drops the SYN.(That's the most consistent explanation for the timing; the root cause — bit collision — is the real bug, regardless of which chain wins the race.)
Reproduction
hostPort80/443 enabled).curl https://<host-wt0-IP>:443.systemctl restart netbird→ curl works briefly → fails within ~60s.Workaround
Disable NetBird's firewall management:
Verify:
sudo nft list table ip netbird→ "No such file or directory".Suggested fix
The bit collision is the design flaw. Two options:
Don't use bit
0x10000in NetBird's marks. It's effectively reserved by kube-router and possibly other CNIs (Calico uses similar bit-ranges). Pick a mark that doesn't share any low-bit space with0x00010000/0x00020000(e.g. anything in the upper 16 bits). At minimum, mask only the NetBird bits when checking — e.g. tag a connection with0x80000000and matchmeta mark & 0x80000000 == 0x80000000. I would suggest either picking a different bit or a config option that allows overriding a different bit.Match on
ct markinstead ofmeta markfor the forward-accept rule. NetBird already setsct mark 0x0001bd10on new connections innetbird-mangle-prerouting; that mark is stored in the conntrack entry, is not affected by kube-router's per-packetMARKops, and survives DNAT and chain hops. Rewriting the rule as:would make the accept independent of any other component touching the per-packet mark.
The same class of mark-stomp can affect any environment combining NetBird with another netfilter consumer that uses
--set-mark/--xset-markon the per-packet mark (kube-router, calico-felix, kube-proxyKUBE-MARK-MASQ, fwmark-based policy routing daemons, etc.). The conntrack-mark approach defends against all of them.Mark allocation reference
0x00010000KUBE-NWPLCY-DEFAULTrule 4MARK and 0xfffeffffat end ofKUBE-POD-FW-*0x00020000MARK or 0x20000at end ofKUBE-POD-FW-*mark 0x20000/0x20000 ACCEPT0x00004000KUBE-MARK-MASQ0x0001bd10netbird-mangle-prerouting(ct mark)0x0001bd11netbird-mangle-postrouting(ct mark)0x0001bd20netbird-mangle-prerouting(meta mark)0x10000of this mark while passing throughKUBE-POD-FW-*0x0001bd21/0x0001bd22The
0x0001bd20value contains bits 0x10000, 0x8000, 0x2000, 0x1000, 0x800, 0x100, 0x20 — the bit-16 overlap with kube-router's reserved bit is the failure mode.Files / commands used during diagnosis
iptables -L FORWARD -nv --line-numbers— confirmed kube-router'sKUBE-ROUTER-FORWARDis line 1 of FORWARD andACCEPT in wt0is line 3iptables -t nat -S CNI-HOSTPORT-DNAT,iptables -t nat -S CNI-DN-…— confirmed traefik's hostPort DNAT is in place and source-agnosticnft list table ip netbird— produced the rule set aboveiptables -L KUBE-NWPLCY-DEFAULT -nv— confirmed final rule isMARK or 0x10000for any traffic, i.e. the chain is permissive (no NetworkPolicy resource exists)raw/PREROUTING,mangle/PREROUTING,nat/PREROUTING,mangle/FORWARD,filter/FORWARD,nat/POSTROUTINGtcpdump -ni any 'host 10.79.43.248 or host 10.42.0.17'sysctl net.ipv4.{ip_forward,conf.{all,wt0,cni0}.{forwarding,rp_filter}}— all confirmed correctRelated upstream issues
nftablesusageclient/firewall/nftags/router.linux.goNotes
I'm willing to come up with a PR for changing the bits or overriding with a config option if you wish. I could also try to work on the connection mark one if that's the way you wanted to go. That seems possibly a lot more complicated though. Let me know which way you are leaning.
@alfadb commented on GitHub (May 30, 2026):
Hitting the same root cause from PR #5697 on a different stack — adding this as an additional reproducer in case it helps triage.
Environment
0.71.4(iptables-nft mode)192.168.50.0/24100.108.227.115) → wt0 on the routing-peer node → kube-proxy DNAT to envoy pod (10.98.0.127:10443) → dropKey difference from this issue as originally reported
The dropped packets carry mark
0x1bd21, not0x1bd20. There is no kube-router stomping a bit here — the mark0x1bd21is set by NetBird itself innetbird-mangle-prerouting:Then in mangle FORWARD the guard from PR #5697 fires:
0x1bd21≠0x1bd20→ SYN dropped. Counter increments cleanly with every retry ofnc -vz <LB_IP> 443from the remote peer.Verified with
iptables -t mangle -L FORWARD -nv:141 dropped packets before I even started testing — all routed-peer → LB-IP TCP SYNs over many days.
Root cause interpretation
PR #5697's guard whitelists only the
peer → local-hostmark (0x1bd20). Thepeer → routed-networkmark (0x1bd21, also set by NetBird) was not added to the whitelist. So any deployment where the NetBird routing peer is also a Kubernetes node that uses kube-proxy DNAT for Service traffic silently breaks — including single-node k3s/k8s with flannel/Cilium/Calico (any CNI), regardless of whether kube-router is involved.This is broader than the mark-bit-collision angle. The fix proposal in this issue to switch the guard to
ct markwould resolve both flavors. Alternatively, the simplest patch is to extend the whitelist:Workaround that preserves NetBird ACL
NB_DISABLE_FIREWALL=trueworks but disables the entire NetBird ACL surface, which is a regression for anyone using NetBird Policies. A more surgical workaround is a separate nftablesinettable at PREROUTING priority-101(between NetBird mangle at-150and kube-proxy nat at-100) that overwrites the meta mark to0x1bd20for the LB CIDR:NetBird daemon does not touch the
inetfamily, so this survivessystemctl restart netbirdand version upgrades. Tested working on 0.71.4. Posting it here in case it's useful for others hitting the same.Happy to test any candidate patch.
@alfadb commented on GitHub (Jun 2, 2026):
Follow-up to my previous comment with a refined workaround based on further investigation.
What I missed initially
My first proposed workaround was an
inettable at PREROUTING prioritydstnat - 1(-101) that pre-stamps mark0x1bd20. It worked for one peer (close to the routing peer, direct WireGuard tunnel) but broke for a cross-region peer hitting the same LB IPs. tcpdump+LOG instrumentation in mangle FORWARD revealed why:MARK=0x1fd20, not0x1bd20.The diff is bit
0x4000— kube-proxy'sKUBE-MARK-MASQbit. kube-proxy ORs it on top of any existing mark duringnat-preroutingfor LoadBalancer/ClusterIP traffic that needs POSTROUTING SNAT (externalTrafficPolicy: Cluster). So even though we set mark =0x1bd20at priority -101 (before kube-proxy's -100), kube-proxy then mutates it to0x1fd20, which fails NetBird's strict-equalitymeta mark != 0x1bd20check at mangle FORWARD priority -150.Net result: with the PREROUTING workaround in place, every LB-IP-bound flow from a remote NetBird peer routed through this node still gets silently dropped. We initially missed this because our first test peer happened to succeed (likely due to specific conntrack state on that machine at test time); a second peer added to the mesh exposed the regression immediately, with the LOG-instrumented dmesg evidence above.
Refined workaround (PREROUTING → FORWARD priority -151)
Move the rewrite to mangle FORWARD, one tick before NetBird's guard, after kube-proxy has finished touching the mark:
Properties of this hook position:
0x1bd2X | 0x4000 | …combination kube-proxy produces, we overwrite the whole word to0x1bd20. NetBird's strict-equality check then passes.ct status dnatprecisely scopes to kube-proxy DNAT'd flows. Non-DNAT'd plain LAN traffic (e.g.ping <a-LAN-host-that-NetBird-routes>) keeps its NetBird-assigned mark0x1bd21and gets normal NetBird LAN SNAT — important for return path of remote peers whose peer-to-peer tunnel is relayed/unreliable.ct status dnatmatters, not which CNI does the DNAT.inetfamily; NetBird only managesipfamily tables, so this survivessystemctl restart netbirdand version upgrades.Tested working on NetBird 0.71.4, kernel netfilter mixed-backend host (iptables-legacy for NetBird's own rules + native nftables for kube-proxy nft-mode), single-node k8s with flannel, MetalLB L2.
Acknowledged side effect
kube-proxy no longer sees its
0x4000bit after we overwrite the mark → it skips POSTROUTING SNAT for these connections. The pod (envoy in our case) sees the original NetBird overlay source IP100.108.x.xinstead of the node IP. Reply traffic returns via the routing peer's own100.108.0.0/16 dev wt0route, no SNAT needed.For most workloads (HTTP applications wanting real client IPs, audit/access logging) this is actually preferable. Workloads that rely on seeing node IPs would need a different fix.
Why a
ct markbased upstream fix is still the right directionsnowzach's earlier proposal in this issue (switch the FORWARD guard to a conntrack-mark check derived from
netbird-mangle-prerouting'sct mark 0x1bd10) would handle both:meta markper packetbecause
ct markis set once when the connection is created and not touched by per-packetMARKops downstream. Happy to test a candidate patch.Reproducer summary
For repro by maintainers, the minimal setup that triggers this:
externalTrafficPolicy: Clusteron a LoadBalancer Service)curl https://<LB-IP>:<port>→ times outiifname "wt0" ct status dnat mark != 0x1bd20counter increments per SYN attempt@head1328 commented on GitHub (Jul 1, 2026):
Confirming this on NetBird 0.73.2 (k3s, flannel CNI,
wt0as the NetBird interface, kube-proxy in nft mode), and that @alfadb's FORWARD-mark workaround (comment from 2026-06-02) resolves it for us as well.Same symptom: a mesh peer reaching a NodePort over
wt0is dropped bybecause kube-proxy DNATs the packet to the pod IP and NetBird's routing mark
0x1bd20is not present. Node-local access and non-DNAT'd443work.We applied @alfadb's approach (own nft table,
forwardhook before NetBird'smangle FORWARD, rewrite the mark forct status dnat). Our variant differs only in details:ipfamily instead ofinet, and priority-160instead ofmangle - 1.NetBird's reconcile manages only its own tables/chains and does not touch this separate table, so it survives policy/peer reconciles and restarts.
Applied idempotently by a systemd oneshot unit ordered after the NetBird service (re-created on boot; NetBird never removes it at runtime):
Validated with >20k connections / 0 failures from a mesh peer to a NodePort while repeatedly triggering NetBird policy reconciles; the table stayed in place throughout. The
ct mark-based upstream fix that snowzach and @alfadb describe is still theclean solution, since it also covers the per-packet mark mutations (kube-router bit-stomp, kube-proxy MASQ bit) without an external table.