[GH-ISSUE #2433] Granular control by NetBird #5124

Open
opened 2026-08-05 01:01:30 -04:00 by saavagebueno · 3 comments
Owner

Originally created by @Gifff69 on GitHub (Aug 15, 2024).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/2433

Hi,

For my understanding, NetBird support peer-to-peer access control.
https://docs.netbird.io/how-to/manage-network-access

For "Traffic to private networks" case, how to control the end device without installing agent? Can add new request to use policy to control end device by using ip address / domain? i.e. client PEER, window1 --> web server-01 (ALLOW); client PEER, window2 --> web server-02 (BLOCK).
https://docs.netbird.io/how-to/routing-traffic-to-private-networks
some cases do not allow for agent installation or can slow down migration from legacy systems:

  1. Side-by-side migrations where part of your network is already using NetBird but needs to access services that are not.
  2. Systems that have limited operating system access. e.g., IoT devices, printers, and managed services.
  3. Legacy networks where an administrator is unable to install the agent on all nodes.

Also, same request on internet web access control by using ip address / domain. i.e. client PEER, iOS --> www.google.com (action: BLOCK).

Originally created by @Gifff69 on GitHub (Aug 15, 2024). Original GitHub issue: https://github.com/netbirdio/netbird/issues/2433 Hi, For my understanding, NetBird support peer-to-peer access control. https://docs.netbird.io/how-to/manage-network-access For "Traffic to private networks" case, how to control the end device without installing agent? Can add new request to use policy to control end device by using ip address / domain? i.e. client PEER, window1 --> web server-01 (ALLOW); client PEER, window2 --> web server-02 (BLOCK). https://docs.netbird.io/how-to/routing-traffic-to-private-networks some cases do not allow for agent installation or can slow down migration from legacy systems: 1. Side-by-side migrations where part of your network is already using NetBird but needs to access services that are not. 2. Systems that have limited operating system access. e.g., IoT devices, printers, and managed services. 3. Legacy networks where an administrator is unable to install the agent on all nodes. Also, same request on internet web access control by using ip address / domain. i.e. client PEER, iOS --> www.google.com (action: BLOCK).
saavagebueno added the feature-request label 2026-08-05 01:01:30 -04:00
Author
Owner

@Gifff69 commented on GitHub (Aug 19, 2024):

Kindly share if any roadmap to add above feature. Thanks.

<!-- gh-comment-id:2296083870 --> @Gifff69 commented on GitHub (Aug 19, 2024): Kindly share if any roadmap to add above feature. Thanks.
Author
Owner

@Gifff69 commented on GitHub (Aug 22, 2024):

Kindly share if any roadmap to add above feature. Thanks.

UP

<!-- gh-comment-id:2304248742 --> @Gifff69 commented on GitHub (Aug 22, 2024): > Kindly share if any roadmap to add above feature. Thanks. UP
Author
Owner

@PizzaLovingNerd commented on GitHub (May 27, 2026):

Hello, we are closing this issue as it is stale and this should be covered by Networks / Network Resources. if you still want this feature to be added in the future please open a GitHub Discussion rather than an issue. Thanks!

<!-- gh-comment-id:4559866896 --> @PizzaLovingNerd commented on GitHub (May 27, 2026): Hello, we are closing this issue as it is stale and this should be covered by Networks / Network Resources. if you still want this feature to be added in the future please open a [GitHub Discussion](https://github.com/netbirdio/netbird/discussions) rather than an issue. Thanks!
Sign in to join this conversation.
No Label feature-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#5124