mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-07 02:29:06 -04:00
Open
opened 2026-08-05 01:16:16 -04:00 by saavagebueno
·
24 comments
No Branch/Tag Specified
main
fix/wails-go-vendor
fix/update-wails-fork-ref
add-atomic-cache-ops
feat/agent-network-per-account-serving
feat-post_quantum_ml_kem
revert/component-types
wins_nrpt_dns_delegation
embedded-vnc
dependabot/github_actions/actions-a940c7c866
fix/quickstart-subnet-and-domain-alias
notification-localization
ssh-settings-elevation
refactor/peer-event-bus
fix/relay-proxy-redirect-when-ice-active
disambiguate_p2p_metrics
claude/agent-network-test-cases-p743vw
android/gui-integration
ice-stun-wg-demux
dependabot/npm_and_yarn/proxy/web/npm_and_yarn-b39864987c
agent-network-setup-poc
dependabot/go_modules/aws-sdk-8f849ebaed
dependabot/go_modules/otel-e34c790afd
dependabot/go_modules/testcontainers-de325c0dd6
dependabot/go_modules/wireguard-dbd6b95108
dependabot/go_modules/pion-5f703e1eca
dependabot/go_modules/gorm-2271c8195b
fix-login-needed-check
dependabot/go_modules/google.golang.org/grpc-1.82.1
revert/component-types-hookup
feature/ios-ssh
docs/agent-network-docs-update
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.106.3
dependabot/go_modules/github.com/pion/stun/v3-3.1.5
fix-ssh-authorized-users-multi-rule
peer-acl-multi-source
reverse-proxy-crowdsec-appsec
reverse-proxy-allow-match-or
client-local-metrics
lazy-conn-per-peer
lazy-conn-rosenpass
dependabot/go_modules/github.com/gopacket/gopacket-1.7.0
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.6
dependabot/go_modules/github.com/pires/go-proxyproto-0.15.0
dependabot/go_modules/github.com/jackc/pgx/v5-5.10.0
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.4
dependabot/go_modules/github.com/pkg/sftp-1.13.11
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.20.0
ssh-windows-privilege-check
fix/explicit-cors-handling
fix/remove-math-rand
test/gui-memory-leak-fix
fix/ui-status-dispatch
install-script-ui-dependencies
fix/grpc-get-network-map
fix/subscribe-status-coalesce
fix/tray-menu-item-leak
fix/windows-tray-race
feature/changeset
worktree-dns-route-qtype-fallthrough
mdm_integration
mlsmaycon-patch-2
feat/agent-network-ollama
proxy-tunnel-cache-ttl-env
coderabbitai/utg/1e5b0a5
grpc-acl
test/battery-drain
components-impl-drop-indexes-use-xids-no-resource-policy-map
fix/nmap-relevant-groups
e2e-guardrail-blocks-unselected-model
fix/lazyconn-cold-start-allowed-ips
vertex-guardrails-model-access-e2e
refactor/relay-foreign-cache
ci/trigger-release-tests
feature/kimi-3-agent-networks-dns-warmup
feature/dns-lazy-conn-warmup
daemon-ipc-acl
feature/ui-translation-key-parity-check
refactor/relay-foreign-cache-tests
fix/lazyconn-idle-keep-wg-peer
dmitri-propagate-auth-grant-types-on-combined
0.74.7-branch
diagnose-empty-vs-corrupt-state
windows-sleep-detector
fix/cli-up-wait-for-daemon
rp_key_persistency
feature/native-grpc
0.74.6-branch
0.74.6-branch-sync
0.74.5-branch-sync
0.74.4-branch
fix/remove-stale-peers-removal
fix/remove-stale-proxy-logic
fix/nsis-preserve-autostart-on-upgrade
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3
dependabot/go_modules/github.com/pkg/sftp-1.13.10
components-impl-drop-indexes
fix-reset-aggregation-window-flake
dependabot/go_modules/github.com/pion/dtls/v3-3.1.5
0.74.x
fix/relay-states-lock
update-process-pkg
update-gopsutil-v4
fix/relay_states_lock
increase-sysinfo-timeout
dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
dependabot/go_modules/github.com/eko/gocache/store/redis/v4-4.2.6
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.3
fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
0.74.3-branch
fix/routeselector-atomic-exit-node
netmap_progressive_alignment
nmap/components-impl
dependabot/go_modules/github.com/jackc/pgx/v5-5.9.2
dependabot/go_modules/github.com/oapi-codegen/runtime-1.4.2
dependabot/go_modules/github.com/gopacket/gopacket-1.6.1
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0
dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0
fix/signal-watchdog-sync-stop
docs/agent-network
test/affected-logic
fix/revert-ice-filter
refactor/simplify-affected-peers
pascal-filter-policies-by-direction
claude/lock-contention-peer-connect-g8t6au
dmitri-filter-policies-by-direction
refactor/migrate-profiles-to-go
profile-bindings-ios
fix/skip-restart-unchanged-route
fix/mgmt-cache-async-resolve
refactor/wails-update-105
client_lifetime_serialization_refactor
fix/browser-ssh-2
fix/ipv6-and-netstack-accept-loop
fix/browser-ssh
profile-id-name-test
refactor/mgmt-bootstrap
feat/getting-started-unified-wizard
socket-grpc-permissions
fix/mysql-index-migration
windows-dns-firewall
tests/enable-race-on-tests
ui-refactor-gtk3
feature/affected-peers-grpc
profile-id
lazyconn-first-packet-fix-v2
claude/focused-gates-VMTgb
ui-tray-linux-leftclick
fix/ctx-enrichment
daemon-owner
feature/android-client-ssh
worktree-accept-ra-forwarding
nmap/combined-deploy
task/align_protobuff_toolset
feature/session-extend
add-json-yaml-flags
refactor/ephemeral-cleanup
claude/webtransport-relay-wasm-mUjY9
claude/vnc-udp-feasibility-6KB1U
fix/wgport-config
e2e-windows-dns-combined
fix/login-cmd-root-flags
feat/reseller-openapi-spec
github-issue-resolver
add-steamos-support
fix-darwin-uninstaller
flutter-test
ci/freebsd-pkg-bootstrap
cached-serial-check-on-sync
fix-mgmt-cache-bypass-overlay
revert-easyjson-5938
revert-ice-5820
revert-firewalld-5928
refactor/permissions-manager
revert-dns-5935-systemd-resolved
revert-dns-5935-5945
revert-dns-5945-mgmt-cache
feature/log-most-busy-peers
prototype/ui-wails
coderabbitai/utg/8ae8f20
feature/use-peer-fqdn-on-https
release/0.68.3
add-slack-channel
claude/rdp-token-passthrough-eNcqW
transparent-proxy
fix/macos-stale-route-eexist
crowdsec-selfhosted
fix/remove-otel-units
entire/checkpoints/v1
fix/getting-started
feat/static-connectors-combined-server
feature/use-local-keys-embedded
feature/fleetdm
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.76.1
v0.76.0
v0.75.1
v0.75.0
v0.74.7
v0.74.6
v0.74.5
v0.75.0-rc.6
v0.74.4
v0.74.3
v0.75.0-rc.5
v0.74.2
v0.74.1
v0.75.0-rc.4
v0.74.0
v0.74.0-rc.2
v0.74.0-rc.1
v0.73.2
v0.75.0-rc.3
v0.75.0-rc.2
v0.73.1
v0.75.0-rc.1
v0.73.0
v0.72.4
v0.72.3
v0.72.2
v0.72.1
v0.72.0
v0.71.4
v0.71.3
v0.71.2
v0.71.1
v0.71.0
v0.70.5
v0.70.4
v0.70.3
v0.70.2
v0.70.1
v0.70.0
v0.69.0
v0.68.3
v0.68.2
v0.68.1
v0.68.0
v0.67.4
v0.67.3
v0.67.2
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2021 Q4
2021 Q4
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
accessibility
accessibility
accessibility
acl
acl
acl
agent
agent
agent
agent
agent
agent
Android
Android
Android
Android
Android
Android
api
api
api
authentik
authentik
authentik
automation
automation
automation
azure
azure
azure
battery-usage
battery-usage
battery-usage
bug
cache
cache
cache
client
client
client
client-ui
client-ui
client-ui
cloud
cloud
cloud
cloud-only
cloud-only
cloud-only
cloudflare
cloudflare
cloudflare
community
community
community
compatibility
compatibility
compatibility
config-idp
config-idp
config-idp
config-issue
config-issue
config-issue
connection
connection
connection
contribution
contribution
contribution
coturn
coturn
coturn
cross-vpn
cross-vpn
cross-vpn
dashboard
dashboard
dashboard
data-usage
data-usage
data-usage
distribution
distribution
distribution
dns
dns
dns
docker
docker
docker
documentation
documentation
documentation
duplicate
duplicate
duplicate
enhancement
enhancement
event-stream
event-stream
event-stream
feature-request
feature-request
feature-request
freebsd
freebsd
freebsd
getting-started
getting-started
getting-started
go
go
go
good first issue
good first issue
good first issue
gui
gui
gui
help wanted
help wanted
help wanted
home-assistant
home-assistant
home-assistant
idp
idp
idp
inconsistency
inconsistency
inconsistency
integration
integration
integration
integrations
integrations
integrations
ios
ios
ios
ipv6
ipv6
ipv6
jwt
jwt
jwt
k8s
k8s
k8s
keycloak
keycloak
keycloak
linux
linux
linux
login
login
login
macos
macos
macos
management-service
management-service
management-service
Medium
Medium
Medium
missing-docs
missing-docs
missing-docs
mobile
mobile
mobile
moved-internal
moved-internal
moved-internal
needs-review
needs-review
needs-review
netbird-ui
netbird-ui
netbird-ui
networking
networking
networking
new-platform
new-platform
new-platform
nginx
nginx
nginx
notification
notification
notification
okta
okta
okta
openwrt
openwrt
openwrt
P2
P2
P2
packaging
packaging
packaging
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
performance
performance
performance
postgres
postgres
postgres
posture-checks
posture-checks
posture-checks
psk
psk
psk
pull-request
question
question
question
refactor
refactor
refactor
relay
relay
relay
release
release
release
rfc
rfc
rfc
routes
routes
routes
security
security
security
security-improvement
security-improvement
security-improvement
security-related
security-related
security-related
self-hosting
self-hosting
self-hosting
server
server
server
signal
signal
signal
sleep-issue
sleep-issue
sleep-issue
ssh
ssh
ssh
ssl
ssl
ssl
status
status
status
store
store
store
synology
synology
synology
system-compatibility-issue
system-compatibility-issue
system-compatibility-issue
test-suite
test-suite
test-suite
third-party-integration
third-party-integration
third-party-integration
triage
triage
triage
triage
triage
triage
triage-needed
triage-needed
triage-needed
troubleshooting
troubleshooting
troubleshooting
UX
UX
UX
waiting-feedback
waiting-feedback
waiting-feedback
windows
windows
windows
wontfix
wontfix
wontfix
zitadel
zitadel
zitadel
Mirrored from GitHub Pull Request
No Label
triage-needed
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: DYNR/netbird#8154
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Queestion on GitHub (Jun 8, 2025).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/3942
Describe the problem
no internet with two exit nodes added
To Reproduce
create two exit nodes with different metrics. leave both as active
Expected behavior
I expect that netbird will choose the exit node itself based on the metrics
Are you using NetBird Cloud?
Selfhosted
NetBird version
latest
Is any other VPN software installed?
No
Additional context
did anyone have this problem? when configuring more than one exit node with different metrics. traffic to the internet does not work. only remote networks advertised by netbird work. manually disabling one exit node solves the problem.
Have you tried these troubleshooting steps?
@Marcus1Pierce commented on GitHub (Jun 8, 2025):
I’m curious why you need two exit nodes at the same time? What do you want to achieve with two exit nodes?
@Queestion commented on GitHub (Jun 9, 2025):
Hi, I would like my users to have two available exit nodes. Depending on what IP they want to exit to the Internet with, so they can switch in the Netbird client. This is also a kind of HA in case of an exit node failure in one of the locations.
I assume that's how it was designed. There's a reason for this ability to set metrics. Within each exit node.
@kalipso-cyber commented on GitHub (Aug 7, 2025):
I have the same issue. Two different exit nodes and I can't reach the Internet via either. Internet access works fine when not routing via any exit node (VPN active but no node selected -> client's regular gateway is used).
@Queestion commented on GitHub (Aug 7, 2025):
@kalipso-cyber, You need to configure distribution groups. Unfortunately, it doesn't work on all. For me it solved the problem. Unfortunately, choosing an exit node from iOS application does not work properly. You need to turn off a given exit node in Dashboard. Or assign devices to dedicated distribution groups.
@kalipso-cyber commented on GitHub (Aug 8, 2025):
Thanks for your answer @Queestion! I actually already created distribution groups and assigned the resources to those groups, and the devices can see the two exit nodes they are allowed to see. I also already tried turning off one of the exit nodes, but that didn't help either.
Maybe my issue is unrelated to yours and we just share the same symptoms :) Did you ever get it properly working? I think I won't roll out Netbird in prod just yet after all though, as it doesn't seem to be stable yet. Looks very promising though and I'm curious to see what v1 will have in store!
@Queestion commented on GitHub (Aug 8, 2025):
@kalipso-cyber Yes, Netbird works in production on my home networks. For three subnets and two exit nodes. It's also important to set different metrics for both the nodes and the subnets. The only thing that doesn't work correctly is selecting the exit node from the iOS app. If I want to access the world from the second exit node, I have to disable it from the dashboard.
@Queestion commented on GitHub (Aug 8, 2025):
@kalipso-cyber Send your configuration here. I'll compare it with mine and maybe we can find a solution.
@kalipso-cyber commented on GitHub (Aug 8, 2025):
Oh I see, I must've missed the part in the documentation where it says that different metrics are obligatory! I also haven't defined any metrics for my subnets. Is that mandatory as well?
Regarding my configuration: My idea is to replace my existing plain WireGuard setup with netbird, because managing the config files is becoming increasingly complex and cumbersome and I'd like a nice UI to do it, along with advanced access controls.
My current configuration contains a few VLANs, some of which have third-party VPN endpoints as their designated Internet gateway for all non-RFC1918 traffic. The firewall manages the WireGuard tunnels to the VPN providers, as well as the local VLANs. It also provides DNS to all VLANs, though in some VLANs, traffic is first routed through a DNS filter. I also have DNS redirects for a couple of domains and wildcard subdomains, as these can be reached both via the Internet and locally, so I force my local clients to use the local route rather than going over the Internet.
On my personal devices, I have WireGuard tunnels connecting me to my firewall, from where traffic is routed identically to how it would be routed if I was at home, including DNS. This means that my public IP is that of the third-party VPN provider, and I have no DNS leaks. If I need my public IP to be that of my residential address, I simply switch to a different tunnel on my personal device, which lands me on a different interface on the firewall, which in turn is configured to be routed differently (via PPPoE instead of the third-party VPN).
I also have a WireGuard tunnel to a VPS that hosts a reverse proxy for a few of my semi-public (sub)domains. It accepts requests on its WAN interface and forwards them through the WireGuard tunnel to my firewall, where it is routed to the correct destination. A different VPS is furthermore in need of a service that I have in my local network, but I haven't set up
So in total, I have around a dozen WireGuard tunnels to and from personal devices, my firewall, and hosts outside on the Internet. My goal is to replicate the functionality of this setup with netbird.
For this, I have a self-hosted netbird setup with the controller on a VPS, and a number of clients (Linux and macOS) running the netbird client connected to this controller. One of the Linux clients is a dedicated netbird exit node running inside a Proxmox LXC container in my home network. The LXC's
eth0interface is connected to a VLAN with subnet192.168.101.0/24. This VLAN is routed through my firewall, which itself maintains a WireGuard VPN tunnel to the third-party VPN, serving as the actual Internet exit point (as explained above).Inside the LXC, the netbird virtual interface is
wt0with subnet100.69.0.0/16. netbird clients connect successfully and can reach each other, but they cannot access the Internet through this exit node.Key points and troubleshooting steps I've tried:
Confirmed that IP forwarding is enabled on the exit node (
net.ipv4.ip_forward=1).Verified that the routing table shows default route via
eth0(the VLAN interface).Found no NAT rule masquerading netbird subnet (
100.69.0.0/16) traffic outeth0.Added iptables NAT rule on the exit node to masquerade netbird traffic going out
eth0:Added iptables forwarding rules to allow traffic between
wt0(netbird) andeth0:Checked that the firewall routes traffic coming from the LXC's VLAN through the third-party WireGuard tunnel.
From the exit node, direct
curlcalls to external sites usingwt0fail to connect.From the exit node, direct
curlcalls viaeth0succeed and show the third-party IP.So I suspected routing and NAT were not correctly translating netbird subnet traffic for outbound Internet access, but using iptables didn't work. It was my understanding per the documentation that netbird itself would take care of all routing as long as you have it configured to do so (which I have), but since it didn't work, I tried a few things that seemed like likely culprits, but none of it made it work.
I'll try changing the metrics and disabling one of the exit nodes and see if that has any effect!
@kalipso-cyber commented on GitHub (Aug 11, 2025):
I tried changing the metrics and disabling one of the exit nodes, but unfortunately, that did not change anything. I still can't reach the Internet through either exit node on either of my clients.
@Queestion commented on GitHub (Aug 11, 2025):
I don't know if I can help you. My Netbird instance only contains two subnets, one for each location and one exit node in each location. I also have several mobile clients and computers. My travel router with Gli.Net also connects through Netbird, and I have a third subnet.
@kalipso-cyber commented on GitHub (Aug 11, 2025):
No worries, thanks for looking into it! Out of curiosity, how did you install it on the GL.iNet router? And do your clients exclusively use the exit node of their own network/subnet/location, or can they (at least in theory) use whichever exit node they prefer?
@Queestion commented on GitHub (Aug 11, 2025):
When it comes to installing it on a Gli.Net router, OpenWRT is available, so there's a dedicated package to install. Here's a tutorial on how to do it step-by-step on a Beryl AX: https://www.youtube.com/watch?v=fZNwUNnpr08&t=3869s&pp=ygUVYWRtaW5ha2FkZW1pYSBuZXRiaXJk
When you ask about my clients, do you mean those who use the network on Gli.Net?
@kalipso-cyber commented on GitHub (Aug 12, 2025):
Nice :) My OpenWRT devices aren't in use right now, and first I need to figure out this exit node thing anyway, but it's good to know Netbird can run on OpenWRT!
Yeah whichever clients basically - I'm just trying to figure out if I'm correctly understanding the way exit nodes should work. Are they dedicated nodes you set up specifically for routing traffic from other netbird peers to the Internet, or are they "regular" clients/peers that are usually used for other purposes, and you simply designated them as exit nodes?
@Queestion commented on GitHub (Aug 12, 2025):
For me, the exit node is the same as the Netbird network router for the specific subnet I want to access using this mesh VPN. But you can separate these functions. Generally, the exit node is your device through which you want to access the internet while connected to the Netbird network. It's the equivalent of a full tunnel in a standard VPN.
@Queestion commented on GitHub (Aug 12, 2025):
https://www.youtube.com/watch?v=Ad7D2pkFNdA Here's more information about the exit node feature. This video uses another mesh VPN, Tailscale, as an example. However, it works the same way in Netbird.
@kalipso-cyber commented on GitHub (Aug 16, 2025):
Thanks for explaining! My understanding was correct then; and my setup should work.
I guess maybe I'll tear down the entire installation and start from scratch, but my assumption is that it's either an issue with the two exit nodes being up simultaneously (as you have the same issue) and/or some other bug preventing me from using Netbird. Looking at the open issues, there are a lot, as it's under heavy active development.
If I can't get it work in the next try, I'll just keep my current setup until Netbird has matured a little into, say, 1.0 or so.
Again, thanks for looking into this with me! And fingers crossed the two exit nodes issue gets fixed soon 🤞
@m7mdcc commented on GitHub (Aug 20, 2025):
Hmmm, I have the same exact issue: 2 exit nodes. They both appear on the Windows client. On Tailscale, it was working well; choosing one of the exit nodes makes the internet go through it. but in NetBird, it seems not to working like Tailscale.
adding both peers to same exit node route , then changing the metrics, is my current workthrough.
@Queestion commented on GitHub (Aug 21, 2025):
@m7mdcc Can you describe your solution to this problem in detail? I have different metrics and devices assigned to separate groups for each exit node.
@m7mdcc commented on GitHub (Aug 21, 2025):
@Queestion you need to put both peers on the same exit node route "HA Route" . with different metric .. then if you need to go through the other exit node you need to change metric , note metrics work if there is two or more peers for same route .
@Queestion commented on GitHub (Aug 21, 2025):
This is a workaround, but it's weak in terms of HA. Changing metrics in the event of a peer failure within the exit node must be done manually.
@Queestion commented on GitHub (Aug 21, 2025):
OK, HA works fine, but if one of the peers fails, you need to reconnect to the Netbird network.
@m7mdcc commented on GitHub (Aug 21, 2025):
For me, it works without needing to reconnect — I’ve tried it many times. The only drawback is when you need to switch the user to a different exit node by changing the route metric within the HA route, which is done through the API. The user communicates with the bot (handled internally), and then the bot updates the metric.
I just wish there was an option for the client to change the exit node directly, similar to how the Tailscale client works.
@Queestion commented on GitHub (Aug 21, 2025):
@m7mdcc Yes, I'd also like to be able to choose which exit node I want to connect to the internet at the client level. HA actually works without reconnecting, but in the iOS app, I had to go to Networks and click the "refresh" button. The iOS app hasn't been updated in a while. Maybe that's why.
@zimpower commented on GitHub (Jan 12, 2026):
👋 Adding a data point that I’m seeing the same behavior.
I’m running a self-hosted NetBird setup (v 0.62.1) with two OPNsense peers configured as exit nodes (each advertising 0.0.0.0/0). Both exit nodes are active and visible to clients, but traffic always flows through only one, regardless of which exit node is selected in the client UI.
Switching the exit node in the client UI does not successfully change the exit node used — traffic continues to flow through the originally selected one. This is reproducible on:
iOS
iPadOS
macOS (MacBook Air M2)
Subnet routing and DNS are working well. When only one exit node is active in the dashboard, traffic is routed correctly through that node. The issue seems isolated to exit node selection/switching when multiple exit nodes are active.
I’d also like to see this use case supported correctly, as the ability to switch between exit nodes would be very useful.
Thanks for all the work on NetBird!