[GH-ISSUE #3942] more than one exit node, no internet access #7705

Open
opened 2026-08-05 01:14:09 -04:00 by saavagebueno · 24 comments
Owner

Originally created by @Queestion on GitHub (Jun 8, 2025).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/3942

Describe the problem

no internet with two exit nodes added

To Reproduce

create two exit nodes with different metrics. leave both as active

Expected behavior

I expect that netbird will choose the exit node itself based on the metrics

Are you using NetBird Cloud?

Selfhosted

NetBird version

latest

Is any other VPN software installed?

No

Additional context

did anyone have this problem? when configuring more than one exit node with different metrics. traffic to the internet does not work. only remote networks advertised by netbird work. manually disabling one exit node solves the problem.

Have you tried these troubleshooting steps?

  • [ X] Reviewed client troubleshooting (if applicable)
  • [ X] Checked for newer NetBird versions
  • [X ] Searched for similar issues on GitHub (including closed ones)
  • [X ] Restarted the NetBird client
  • [ X] Disabled other VPN software
  • [ X] Checked firewall settings
Originally created by @Queestion on GitHub (Jun 8, 2025). Original GitHub issue: https://github.com/netbirdio/netbird/issues/3942 **Describe the problem** no internet with two exit nodes added **To Reproduce** create two exit nodes with different metrics. leave both as active **Expected behavior** I expect that netbird will choose the exit node itself based on the metrics **Are you using NetBird Cloud?** Selfhosted **NetBird version** latest **Is any other VPN software installed?** No **Additional context** did anyone have this problem? when configuring more than one exit node with different metrics. traffic to the internet does not work. only remote networks advertised by netbird work. manually disabling one exit node solves the problem. **Have you tried these troubleshooting steps?** - [ X] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [ X] Checked for newer NetBird versions - [X ] Searched for similar issues on GitHub (including closed ones) - [X ] Restarted the NetBird client - [ X] Disabled other VPN software - [ X] Checked firewall settings
saavagebueno added the triage-needed label 2026-08-05 01:14:09 -04:00
Author
Owner

@Marcus1Pierce commented on GitHub (Jun 8, 2025):

I’m curious why you need two exit nodes at the same time? What do you want to achieve with two exit nodes?

<!-- gh-comment-id:2954502583 --> @Marcus1Pierce commented on GitHub (Jun 8, 2025): I’m curious why you need two exit nodes at the same time? What do you want to achieve with two exit nodes?
Author
Owner

@Queestion commented on GitHub (Jun 9, 2025):

Hi, I would like my users to have two available exit nodes. Depending on what IP they want to exit to the Internet with, so they can switch in the Netbird client. This is also a kind of HA in case of an exit node failure in one of the locations.

I assume that's how it was designed. There's a reason for this ability to set metrics. Within each exit node.

<!-- gh-comment-id:2954783691 --> @Queestion commented on GitHub (Jun 9, 2025): Hi, I would like my users to have two available exit nodes. Depending on what IP they want to exit to the Internet with, so they can switch in the Netbird client. This is also a kind of HA in case of an exit node failure in one of the locations. I assume that's how it was designed. There's a reason for this ability to set metrics. Within each exit node.
Author
Owner

@kalipso-cyber commented on GitHub (Aug 7, 2025):

I have the same issue. Two different exit nodes and I can't reach the Internet via either. Internet access works fine when not routing via any exit node (VPN active but no node selected -> client's regular gateway is used).

<!-- gh-comment-id:3164934246 --> @kalipso-cyber commented on GitHub (Aug 7, 2025): I have the same issue. Two different exit nodes and I can't reach the Internet via either. Internet access works fine when not routing via any exit node (VPN active but no node selected -> client's regular gateway is used).
Author
Owner

@Queestion commented on GitHub (Aug 7, 2025):

@kalipso-cyber, You need to configure distribution groups. Unfortunately, it doesn't work on all. For me it solved the problem. Unfortunately, choosing an exit node from iOS application does not work properly. You need to turn off a given exit node in Dashboard. Or assign devices to dedicated distribution groups.

<!-- gh-comment-id:3165006257 --> @Queestion commented on GitHub (Aug 7, 2025): @kalipso-cyber, You need to configure distribution groups. Unfortunately, it doesn't work on all. For me it solved the problem. Unfortunately, choosing an exit node from iOS application does not work properly. You need to turn off a given exit node in Dashboard. Or assign devices to dedicated distribution groups.
Author
Owner

@kalipso-cyber commented on GitHub (Aug 8, 2025):

Thanks for your answer @Queestion! I actually already created distribution groups and assigned the resources to those groups, and the devices can see the two exit nodes they are allowed to see. I also already tried turning off one of the exit nodes, but that didn't help either.

Maybe my issue is unrelated to yours and we just share the same symptoms :) Did you ever get it properly working? I think I won't roll out Netbird in prod just yet after all though, as it doesn't seem to be stable yet. Looks very promising though and I'm curious to see what v1 will have in store!

<!-- gh-comment-id:3168368763 --> @kalipso-cyber commented on GitHub (Aug 8, 2025): Thanks for your answer @Queestion! I actually already created distribution groups and assigned the resources to those groups, and the devices can see the two exit nodes they are allowed to see. I also already tried turning off one of the exit nodes, but that didn't help either. Maybe my issue is unrelated to yours and we just share the same symptoms :) Did you ever get it properly working? I think I won't roll out Netbird in prod just yet after all though, as it doesn't seem to be stable yet. Looks very promising though and I'm curious to see what v1 will have in store!
Author
Owner

@Queestion commented on GitHub (Aug 8, 2025):

@kalipso-cyber Yes, Netbird works in production on my home networks. For three subnets and two exit nodes. It's also important to set different metrics for both the nodes and the subnets. The only thing that doesn't work correctly is selecting the exit node from the iOS app. If I want to access the world from the second exit node, I have to disable it from the dashboard.

<!-- gh-comment-id:3168477926 --> @Queestion commented on GitHub (Aug 8, 2025): @kalipso-cyber Yes, Netbird works in production on my home networks. For three subnets and two exit nodes. It's also important to set different metrics for both the nodes and the subnets. The only thing that doesn't work correctly is selecting the exit node from the iOS app. If I want to access the world from the second exit node, I have to disable it from the dashboard.
Author
Owner

@Queestion commented on GitHub (Aug 8, 2025):

@kalipso-cyber Send your configuration here. I'll compare it with mine and maybe we can find a solution.

<!-- gh-comment-id:3168501854 --> @Queestion commented on GitHub (Aug 8, 2025): @kalipso-cyber Send your configuration here. I'll compare it with mine and maybe we can find a solution.
Author
Owner

@kalipso-cyber commented on GitHub (Aug 8, 2025):

Oh I see, I must've missed the part in the documentation where it says that different metrics are obligatory! I also haven't defined any metrics for my subnets. Is that mandatory as well?

Regarding my configuration: My idea is to replace my existing plain WireGuard setup with netbird, because managing the config files is becoming increasingly complex and cumbersome and I'd like a nice UI to do it, along with advanced access controls.

My current configuration contains a few VLANs, some of which have third-party VPN endpoints as their designated Internet gateway for all non-RFC1918 traffic. The firewall manages the WireGuard tunnels to the VPN providers, as well as the local VLANs. It also provides DNS to all VLANs, though in some VLANs, traffic is first routed through a DNS filter. I also have DNS redirects for a couple of domains and wildcard subdomains, as these can be reached both via the Internet and locally, so I force my local clients to use the local route rather than going over the Internet.

On my personal devices, I have WireGuard tunnels connecting me to my firewall, from where traffic is routed identically to how it would be routed if I was at home, including DNS. This means that my public IP is that of the third-party VPN provider, and I have no DNS leaks. If I need my public IP to be that of my residential address, I simply switch to a different tunnel on my personal device, which lands me on a different interface on the firewall, which in turn is configured to be routed differently (via PPPoE instead of the third-party VPN).

I also have a WireGuard tunnel to a VPS that hosts a reverse proxy for a few of my semi-public (sub)domains. It accepts requests on its WAN interface and forwards them through the WireGuard tunnel to my firewall, where it is routed to the correct destination. A different VPS is furthermore in need of a service that I have in my local network, but I haven't set up

So in total, I have around a dozen WireGuard tunnels to and from personal devices, my firewall, and hosts outside on the Internet. My goal is to replicate the functionality of this setup with netbird.

For this, I have a self-hosted netbird setup with the controller on a VPS, and a number of clients (Linux and macOS) running the netbird client connected to this controller. One of the Linux clients is a dedicated netbird exit node running inside a Proxmox LXC container in my home network. The LXC's eth0 interface is connected to a VLAN with subnet 192.168.101.0/24. This VLAN is routed through my firewall, which itself maintains a WireGuard VPN tunnel to the third-party VPN, serving as the actual Internet exit point (as explained above).

Inside the LXC, the netbird virtual interface is wt0 with subnet 100.69.0.0/16. netbird clients connect successfully and can reach each other, but they cannot access the Internet through this exit node.

Key points and troubleshooting steps I've tried:

  • Confirmed that IP forwarding is enabled on the exit node (net.ipv4.ip_forward=1).

  • Verified that the routing table shows default route via eth0 (the VLAN interface).

  • Found no NAT rule masquerading netbird subnet (100.69.0.0/16) traffic out eth0.

  • Added iptables NAT rule on the exit node to masquerade netbird traffic going out eth0:

    iptables -t nat -A POSTROUTING -s 100.69.0.0/16 -o eth0 -j MASQUERADE
    
  • Added iptables forwarding rules to allow traffic between wt0 (netbird) and eth0:

    iptables -A FORWARD -i wt0 -o eth0 -j ACCEPT
    iptables -A FORWARD -i eth0 -o wt0 -m state --state RELATED,ESTABLISHED -j ACCEPT
    
  • Checked that the firewall routes traffic coming from the LXC's VLAN through the third-party WireGuard tunnel.

  • From the exit node, direct curl calls to external sites using wt0 fail to connect.

  • From the exit node, direct curl calls via eth0 succeed and show the third-party IP.

So I suspected routing and NAT were not correctly translating netbird subnet traffic for outbound Internet access, but using iptables didn't work. It was my understanding per the documentation that netbird itself would take care of all routing as long as you have it configured to do so (which I have), but since it didn't work, I tried a few things that seemed like likely culprits, but none of it made it work.

I'll try changing the metrics and disabling one of the exit nodes and see if that has any effect!

<!-- gh-comment-id:3169238465 --> @kalipso-cyber commented on GitHub (Aug 8, 2025): Oh I see, I must've missed the part in the documentation where it says that different metrics are obligatory! I also haven't defined any metrics for my subnets. Is that mandatory as well? Regarding my configuration: My idea is to replace my existing plain WireGuard setup with netbird, because managing the config files is becoming increasingly complex and cumbersome and I'd like a nice UI to do it, along with advanced access controls. My current configuration contains a few VLANs, some of which have third-party VPN endpoints as their designated Internet gateway for all non-RFC1918 traffic. The firewall manages the WireGuard tunnels to the VPN providers, as well as the local VLANs. It also provides DNS to all VLANs, though in some VLANs, traffic is first routed through a DNS filter. I also have DNS redirects for a couple of domains and wildcard subdomains, as these can be reached both via the Internet and locally, so I force my local clients to use the local route rather than going over the Internet. On my personal devices, I have WireGuard tunnels connecting me to my firewall, from where traffic is routed identically to how it would be routed if I was at home, including DNS. This means that my public IP is that of the third-party VPN provider, and I have no DNS leaks. If I need my public IP to be that of my residential address, I simply switch to a different tunnel on my personal device, which lands me on a different interface on the firewall, which in turn is configured to be routed differently (via PPPoE instead of the third-party VPN). I also have a WireGuard tunnel to a VPS that hosts a reverse proxy for a few of my semi-public (sub)domains. It accepts requests on its WAN interface and forwards them through the WireGuard tunnel to my firewall, where it is routed to the correct destination. A different VPS is furthermore in need of a service that I have in my local network, but I haven't set up So in total, I have around a dozen WireGuard tunnels to and from personal devices, my firewall, and hosts outside on the Internet. My goal is to replicate the functionality of this setup with netbird. For this, I have a self-hosted netbird setup with the controller on a VPS, and a number of clients (Linux and macOS) running the netbird client connected to this controller. One of the Linux clients is a dedicated netbird exit node running inside a Proxmox LXC container in my home network. The LXC's `eth0` interface is connected to a VLAN with subnet `192.168.101.0/24`. This VLAN is routed through my firewall, which itself maintains a WireGuard VPN tunnel to the third-party VPN, serving as the actual Internet exit point (as explained above). Inside the LXC, the netbird virtual interface is `wt0` with subnet `100.69.0.0/16`. netbird clients connect successfully and can reach each other, but they cannot access the Internet through this exit node. Key points and troubleshooting steps I've tried: - Confirmed that IP forwarding is enabled on the exit node (`net.ipv4.ip_forward=1`). - Verified that the routing table shows default route via `eth0` (the VLAN interface). - Found no NAT rule masquerading netbird subnet (`100.69.0.0/16`) traffic out `eth0`. - Added iptables NAT rule on the exit node to masquerade netbird traffic going out `eth0`: ``` iptables -t nat -A POSTROUTING -s 100.69.0.0/16 -o eth0 -j MASQUERADE ``` - Added iptables forwarding rules to allow traffic between `wt0` (netbird) and `eth0`: ``` iptables -A FORWARD -i wt0 -o eth0 -j ACCEPT iptables -A FORWARD -i eth0 -o wt0 -m state --state RELATED,ESTABLISHED -j ACCEPT ``` - Checked that the firewall routes traffic coming from the LXC's VLAN through the third-party WireGuard tunnel. - From the exit node, direct `curl` calls to external sites using `wt0` fail to connect. - From the exit node, direct `curl` calls via `eth0` succeed and show the third-party IP. So I suspected routing and NAT were not correctly translating netbird subnet traffic for outbound Internet access, but using iptables didn't work. It was my understanding per the documentation that netbird itself would take care of all routing as long as you have it configured to do so (which I have), but since it didn't work, I tried a few things that seemed like likely culprits, but none of it made it work. I'll try changing the metrics and disabling one of the exit nodes and see if that has any effect!
Author
Owner

@kalipso-cyber commented on GitHub (Aug 11, 2025):

I tried changing the metrics and disabling one of the exit nodes, but unfortunately, that did not change anything. I still can't reach the Internet through either exit node on either of my clients.

<!-- gh-comment-id:3175656554 --> @kalipso-cyber commented on GitHub (Aug 11, 2025): I tried changing the metrics and disabling one of the exit nodes, but unfortunately, that did not change anything. I still can't reach the Internet through either exit node on either of my clients.
Author
Owner

@Queestion commented on GitHub (Aug 11, 2025):

I don't know if I can help you. My Netbird instance only contains two subnets, one for each location and one exit node in each location. I also have several mobile clients and computers. My travel router with Gli.Net also connects through Netbird, and I have a third subnet.

<!-- gh-comment-id:3176059054 --> @Queestion commented on GitHub (Aug 11, 2025): I don't know if I can help you. My Netbird instance only contains two subnets, one for each location and one exit node in each location. I also have several mobile clients and computers. My travel router with Gli.Net also connects through Netbird, and I have a third subnet.
Author
Owner

@kalipso-cyber commented on GitHub (Aug 11, 2025):

No worries, thanks for looking into it! Out of curiosity, how did you install it on the GL.iNet router? And do your clients exclusively use the exit node of their own network/subnet/location, or can they (at least in theory) use whichever exit node they prefer?

<!-- gh-comment-id:3176646588 --> @kalipso-cyber commented on GitHub (Aug 11, 2025): No worries, thanks for looking into it! Out of curiosity, how did you install it on the GL.iNet router? And do your clients exclusively use the exit node of their own network/subnet/location, or can they (at least in theory) use whichever exit node they prefer?
Author
Owner

@Queestion commented on GitHub (Aug 11, 2025):

When it comes to installing it on a Gli.Net router, OpenWRT is available, so there's a dedicated package to install. Here's a tutorial on how to do it step-by-step on a Beryl AX: https://www.youtube.com/watch?v=fZNwUNnpr08&t=3869s&pp=ygUVYWRtaW5ha2FkZW1pYSBuZXRiaXJk

When you ask about my clients, do you mean those who use the network on Gli.Net?

<!-- gh-comment-id:3177134881 --> @Queestion commented on GitHub (Aug 11, 2025): When it comes to installing it on a Gli.Net router, OpenWRT is available, so there's a dedicated package to install. Here's a tutorial on how to do it step-by-step on a Beryl AX: https://www.youtube.com/watch?v=fZNwUNnpr08&t=3869s&pp=ygUVYWRtaW5ha2FkZW1pYSBuZXRiaXJk When you ask about my clients, do you mean those who use the network on Gli.Net?
Author
Owner

@kalipso-cyber commented on GitHub (Aug 12, 2025):

Nice :) My OpenWRT devices aren't in use right now, and first I need to figure out this exit node thing anyway, but it's good to know Netbird can run on OpenWRT!

Yeah whichever clients basically - I'm just trying to figure out if I'm correctly understanding the way exit nodes should work. Are they dedicated nodes you set up specifically for routing traffic from other netbird peers to the Internet, or are they "regular" clients/peers that are usually used for other purposes, and you simply designated them as exit nodes?

<!-- gh-comment-id:3180524448 --> @kalipso-cyber commented on GitHub (Aug 12, 2025): Nice :) My OpenWRT devices aren't in use right now, and first I need to figure out this exit node thing anyway, but it's good to know Netbird can run on OpenWRT! Yeah whichever clients basically - I'm just trying to figure out if I'm correctly understanding the way exit nodes should work. Are they dedicated nodes you set up specifically for routing traffic from other netbird peers to the Internet, or are they "regular" clients/peers that are usually used for other purposes, and you simply designated them as exit nodes?
Author
Owner

@Queestion commented on GitHub (Aug 12, 2025):

For me, the exit node is the same as the Netbird network router for the specific subnet I want to access using this mesh VPN. But you can separate these functions. Generally, the exit node is your device through which you want to access the internet while connected to the Netbird network. It's the equivalent of a full tunnel in a standard VPN.

<!-- gh-comment-id:3180917135 --> @Queestion commented on GitHub (Aug 12, 2025): For me, the exit node is the same as the Netbird network router for the specific subnet I want to access using this mesh VPN. But you can separate these functions. Generally, the exit node is your device through which you want to access the internet while connected to the Netbird network. It's the equivalent of a full tunnel in a standard VPN.
Author
Owner

@Queestion commented on GitHub (Aug 12, 2025):

https://www.youtube.com/watch?v=Ad7D2pkFNdA Here's more information about the exit node feature. This video uses another mesh VPN, Tailscale, as an example. However, it works the same way in Netbird.

<!-- gh-comment-id:3180923633 --> @Queestion commented on GitHub (Aug 12, 2025): https://www.youtube.com/watch?v=Ad7D2pkFNdA Here's more information about the exit node feature. This video uses another mesh VPN, Tailscale, as an example. However, it works the same way in Netbird.
Author
Owner

@kalipso-cyber commented on GitHub (Aug 16, 2025):

Thanks for explaining! My understanding was correct then; and my setup should work.

I guess maybe I'll tear down the entire installation and start from scratch, but my assumption is that it's either an issue with the two exit nodes being up simultaneously (as you have the same issue) and/or some other bug preventing me from using Netbird. Looking at the open issues, there are a lot, as it's under heavy active development.

If I can't get it work in the next try, I'll just keep my current setup until Netbird has matured a little into, say, 1.0 or so.

Again, thanks for looking into this with me! And fingers crossed the two exit nodes issue gets fixed soon 🤞

<!-- gh-comment-id:3193449704 --> @kalipso-cyber commented on GitHub (Aug 16, 2025): Thanks for explaining! My understanding was correct then; and my setup _should_ work. I guess maybe I'll tear down the entire installation and start from scratch, but my assumption is that it's either an issue with the two exit nodes being up simultaneously (as you have the same issue) and/or some other bug preventing me from using Netbird. Looking at the open issues, there are a _lot_, as it's under heavy active development. If I can't get it work in the next try, I'll just keep my current setup until Netbird has matured a little into, say, 1.0 or so. Again, thanks for looking into this with me! And fingers crossed the two exit nodes issue gets fixed soon 🤞
Author
Owner

@m7mdcc commented on GitHub (Aug 20, 2025):

Hmmm, I have the same exact issue: 2 exit nodes. They both appear on the Windows client. On Tailscale, it was working well; choosing one of the exit nodes makes the internet go through it. but in NetBird, it seems not to working like Tailscale.

adding both peers to same exit node route , then changing the metrics, is my current workthrough.

<!-- gh-comment-id:3208304432 --> @m7mdcc commented on GitHub (Aug 20, 2025): Hmmm, I have the same exact issue: 2 exit nodes. They both appear on the Windows client. On Tailscale, it was working well; choosing one of the exit nodes makes the internet go through it. but in NetBird, it seems not to working like Tailscale. adding both peers to same exit node route , then changing the metrics, is my current workthrough.
Author
Owner

@Queestion commented on GitHub (Aug 21, 2025):

@m7mdcc Can you describe your solution to this problem in detail? I have different metrics and devices assigned to separate groups for each exit node.

<!-- gh-comment-id:3209675712 --> @Queestion commented on GitHub (Aug 21, 2025): @m7mdcc Can you describe your solution to this problem in detail? I have different metrics and devices assigned to separate groups for each exit node.
Author
Owner

@m7mdcc commented on GitHub (Aug 21, 2025):

@Queestion you need to put both peers on the same exit node route "HA Route" . with different metric .. then if you need to go through the other exit node you need to change metric , note metrics work if there is two or more peers for same route .

<!-- gh-comment-id:3209695728 --> @m7mdcc commented on GitHub (Aug 21, 2025): @Queestion you need to put both peers on the same exit node route "HA Route" . with different metric .. then if you need to go through the other exit node you need to change metric , note metrics work if there is two or more peers for same route .
Author
Owner

@Queestion commented on GitHub (Aug 21, 2025):

This is a workaround, but it's weak in terms of HA. Changing metrics in the event of a peer failure within the exit node must be done manually.

<!-- gh-comment-id:3209798397 --> @Queestion commented on GitHub (Aug 21, 2025): This is a workaround, but it's weak in terms of HA. Changing metrics in the event of a peer failure within the exit node must be done manually.
Author
Owner

@Queestion commented on GitHub (Aug 21, 2025):

OK, HA works fine, but if one of the peers fails, you need to reconnect to the Netbird network.

<!-- gh-comment-id:3209886784 --> @Queestion commented on GitHub (Aug 21, 2025): OK, HA works fine, but if one of the peers fails, you need to reconnect to the Netbird network.
Author
Owner

@m7mdcc commented on GitHub (Aug 21, 2025):

OK, HA works fine, but if one of the peers fails, you need to reconnect to the Netbird network.

For me, it works without needing to reconnect — I’ve tried it many times. The only drawback is when you need to switch the user to a different exit node by changing the route metric within the HA route, which is done through the API. The user communicates with the bot (handled internally), and then the bot updates the metric.

I just wish there was an option for the client to change the exit node directly, similar to how the Tailscale client works.

<!-- gh-comment-id:3209928110 --> @m7mdcc commented on GitHub (Aug 21, 2025): > OK, HA works fine, but if one of the peers fails, you need to reconnect to the Netbird network. For me, it works without needing to reconnect — I’ve tried it many times. The only drawback is when you need to switch the user to a different exit node by changing the route metric within the HA route, which is done through the API. The user communicates with the bot (handled internally), and then the bot updates the metric. I just wish there was an option for the client to change the exit node directly, similar to how the Tailscale client works.
Author
Owner

@Queestion commented on GitHub (Aug 21, 2025):

@m7mdcc Yes, I'd also like to be able to choose which exit node I want to connect to the internet at the client level. HA actually works without reconnecting, but in the iOS app, I had to go to Networks and click the "refresh" button. The iOS app hasn't been updated in a while. Maybe that's why.

<!-- gh-comment-id:3210062763 --> @Queestion commented on GitHub (Aug 21, 2025): @m7mdcc Yes, I'd also like to be able to choose which exit node I want to connect to the internet at the client level. HA actually works without reconnecting, but in the iOS app, I had to go to Networks and click the "refresh" button. The iOS app hasn't been updated in a while. Maybe that's why.
Author
Owner

@zimpower commented on GitHub (Jan 12, 2026):

👋 Adding a data point that I’m seeing the same behavior.
I’m running a self-hosted NetBird setup (v 0.62.1) with two OPNsense peers configured as exit nodes (each advertising 0.0.0.0/0). Both exit nodes are active and visible to clients, but traffic always flows through only one, regardless of which exit node is selected in the client UI.
Switching the exit node in the client UI does not successfully change the exit node used — traffic continues to flow through the originally selected one. This is reproducible on:

  • iOS

  • iPadOS

  • macOS (MacBook Air M2)

Subnet routing and DNS are working well. When only one exit node is active in the dashboard, traffic is routed correctly through that node. The issue seems isolated to exit node selection/switching when multiple exit nodes are active.

I’d also like to see this use case supported correctly, as the ability to switch between exit nodes would be very useful.
Thanks for all the work on NetBird!

<!-- gh-comment-id:3740814842 --> @zimpower commented on GitHub (Jan 12, 2026): 👋 Adding a data point that I’m seeing the same behavior. I’m running a self-hosted NetBird setup (v 0.62.1) with two OPNsense peers configured as exit nodes (each advertising 0.0.0.0/0). Both exit nodes are active and visible to clients, but traffic always flows through only one, regardless of which exit node is selected in the client UI. Switching the exit node in the client UI does not successfully change the exit node used — traffic continues to flow through the originally selected one. This is reproducible on: - iOS - iPadOS - macOS (MacBook Air M2) Subnet routing and DNS are working well. When only one exit node is active in the dashboard, traffic is routed correctly through that node. The issue seems isolated to exit node selection/switching when multiple exit nodes are active. I’d also like to see this use case supported correctly, as the ability to switch between exit nodes would be very useful. Thanks for all the work on NetBird!
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#7705