[GH-ISSUE #3325] Cannot get peer to peer connection on Linux behind fortigate #6794

Open
opened 2026-08-05 01:10:09 -04:00 by saavagebueno · 0 comments
Owner

Originally created by @Aurel004 on GitHub (Feb 14, 2025).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/3325

Describe the problem

Hi,

I am running self-hosted Netbird with all the services (dashboard, signal, relay, management and coturn). Everything seems to work well on this side

I have added 3 peers:

  • Windows Client working fine (home network)
  • iOS Client working fine (LTE)
  • Linux Client (to get it as a gateway) (running on the same IP as the Netbird services but in an other VM, so different local IP)

They are in the same group so they can communicate with each other.

When all 3 are connected, I get:

  • Windows <-> iOS: P2P (srflx/srflx)
  • Windows <-> Linux: Relay :33080
  • iOS <-> Linux: Relay :33080

It's been days I'm trying to get a peer to peer connection with the Linux Gateway but I cannot get it working and I'm running out of ideas

The Netbird-ui and Netbird gateway (same external IP), are running behind a Fortigate. I tried to open all ports mentionned in the documentation (TCP 80, 443, 33073, 10000, 33080, 3478 and UDP 3478, 49152-65535 redirected to Netbird-ui) and UDP 51820 redirected to Netbird GW but no client will connect in P2P to the gateway.

I guess the Netbird-ui ports are all good as I can get srflx/srflx from external peers

What I am doing wrong ?

If you need any log, ask me

Thank you for your help

Expected behavior

A P2P connection between Windows <-> Linux GW and iOS <-> Linux GW

Are you using NetBird Cloud?

Self-hosted

NetBird version

0.36.6

NetBird status -dA output:

iphone.vpn.local:
NetBird IP: 100.91.95.205
Public key: XXXXX
Status: Connected
-- detail --
Connection type: P2P
ICE candidate (Local/Remote): srflx/srflx
ICE candidate endpoints (Local/Remote): IP1:51820/IP2:51820
Relay server address: rel://vpn.mydomain.com:33080
Last connection update: 1 minute, 8 seconds ago
Last WireGuard handshake: 1 minute, 9 seconds ago
Transfer status (received/sent) 244 B/336 B
Quantum resistance: false
Routes: -
Networks: -
Latency: 65.354ms

netbird-gateway.vpn.local:
NetBird IP: 100.91.205.28
Public key: XXXXX
Status: Connected
-- detail --
Connection type: Relayed
ICE candidate (Local/Remote): -/-
ICE candidate endpoints (Local/Remote): -/-
Relay server address: rel://vpn.mydomain.com:33080
Last connection update: 57 seconds ago
Last WireGuard handshake: 1 minute, 4 seconds ago
Transfer status (received/sent) 272 B/484 B
Quantum resistance: false
Routes: -
Networks: -
Latency: 0s

OS: windows/amd64
Daemon version: 0.36.6
CLI version: 0.36.6
Management: Connected to https://vpn.mydomain.com:443
Signal: Connected to https://vpn.mydomain.com:443
Relays:
[stun:vpn.mydomain.com:3478] is Available
[turn:vpn.mydomain.com:3478?transport=udp] is Available
[rel://vpn.mydomain.com:33080] is Available
Nameservers:
FQDN: windowsPC.vpn.local
NetBird IP: 100.91.225.203/16
Interface type: Userspace
Quantum resistance: false
Routes: -
Networks: -
Peers count: 2/2 Connected

Do you face any (non-mobile) client issues?

Please provide the file created by netbird debug for 1m -AS.
We advise reviewing the anonymized files for any remaining PII.

Screenshots

If applicable, add screenshots to help explain your problem.

Additional context

Add any other context about the problem here.

Originally created by @Aurel004 on GitHub (Feb 14, 2025). Original GitHub issue: https://github.com/netbirdio/netbird/issues/3325 **Describe the problem** Hi, I am running self-hosted Netbird with all the services (dashboard, signal, relay, management and coturn). Everything seems to work well on this side I have added 3 peers: - Windows Client working fine (home network) - iOS Client working fine (LTE) - Linux Client (to get it as a gateway) (running on the same IP as the Netbird services but in an other VM, so different local IP) They are in the same group so they can communicate with each other. When all 3 are connected, I get: - Windows <-> iOS: P2P (srflx/srflx) - Windows <-> Linux: Relay :33080 - iOS <-> Linux: Relay :33080 It's been days I'm trying to get a peer to peer connection with the Linux Gateway but I cannot get it working and I'm running out of ideas The Netbird-ui and Netbird gateway (same external IP), are running behind a Fortigate. I tried to open all ports mentionned in the documentation (TCP 80, 443, 33073, 10000, 33080, 3478 and UDP 3478, 49152-65535 redirected to Netbird-ui) and UDP 51820 redirected to Netbird GW but no client will connect in P2P to the gateway. I guess the Netbird-ui ports are all good as I can get srflx/srflx from external peers What I am doing wrong ? If you need any log, ask me Thank you for your help **Expected behavior** A P2P connection between Windows <-> Linux GW and iOS <-> Linux GW **Are you using NetBird Cloud?** Self-hosted **NetBird version** 0.36.6 **NetBird status -dA output:** iphone.vpn.local: NetBird IP: 100.91.95.205 Public key: XXXXX Status: Connected -- detail -- Connection type: P2P ICE candidate (Local/Remote): srflx/srflx ICE candidate endpoints (Local/Remote): IP1:51820/IP2:51820 Relay server address: rel://vpn.mydomain.com:33080 Last connection update: 1 minute, 8 seconds ago Last WireGuard handshake: 1 minute, 9 seconds ago Transfer status (received/sent) 244 B/336 B Quantum resistance: false Routes: - Networks: - Latency: 65.354ms netbird-gateway.vpn.local: NetBird IP: 100.91.205.28 Public key: XXXXX Status: Connected -- detail -- Connection type: Relayed ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: rel://vpn.mydomain.com:33080 Last connection update: 57 seconds ago Last WireGuard handshake: 1 minute, 4 seconds ago Transfer status (received/sent) 272 B/484 B Quantum resistance: false Routes: - Networks: - Latency: 0s OS: windows/amd64 Daemon version: 0.36.6 CLI version: 0.36.6 Management: Connected to https://vpn.mydomain.com:443 Signal: Connected to https://vpn.mydomain.com:443 Relays: [stun:vpn.mydomain.com:3478] is Available [turn:vpn.mydomain.com:3478?transport=udp] is Available [rel://vpn.mydomain.com:33080] is Available Nameservers: FQDN: windowsPC.vpn.local NetBird IP: 100.91.225.203/16 Interface type: Userspace Quantum resistance: false Routes: - Networks: - Peers count: 2/2 Connected **Do you face any (non-mobile) client issues?** Please provide the file created by `netbird debug for 1m -AS`. We advise reviewing the anonymized files for any remaining PII. **Screenshots** If applicable, add screenshots to help explain your problem. **Additional context** Add any other context about the problem here.
saavagebueno added the triage-needed label 2026-08-05 01:10:09 -04:00
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#6794