mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-05 00:15:26 -04:00
Closed
opened 2026-08-05 01:18:46 -04:00 by saavagebueno
·
27 comments
No Branch/Tag Specified
main
claude/agent-network-test-cases-p743vw
android/gui-integration
revert/component-types
feat-post_quantum_ml_kem
ice-stun-wg-demux
dependabot/npm_and_yarn/proxy/web/npm_and_yarn-b39864987c
agent-network-setup-poc
dependabot/go_modules/aws-sdk-8f849ebaed
dependabot/github_actions/actions-a940c7c866
dependabot/go_modules/otel-e34c790afd
dependabot/go_modules/testcontainers-de325c0dd6
dependabot/go_modules/wireguard-dbd6b95108
dependabot/go_modules/pion-5f703e1eca
dependabot/go_modules/gorm-2271c8195b
fix-login-needed-check
dependabot/go_modules/google.golang.org/grpc-1.82.1
fix/ui-gtk3-support
enterprise-traefik-and-migration-fixes
disambiguate_p2p_metrics
revert/component-types-hookup
embedded-vnc
feature/ios-ssh
docs/agent-network-docs-update
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.106.3
dependabot/go_modules/github.com/pion/stun/v3-3.1.5
fix-ssh-authorized-users-multi-rule
peer-acl-multi-source
reverse-proxy-crowdsec-appsec
reverse-proxy-allow-match-or
client-local-metrics
lazy-conn-per-peer
lazy-conn-rosenpass
dependabot/go_modules/github.com/gopacket/gopacket-1.7.0
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.6
dependabot/go_modules/github.com/pires/go-proxyproto-0.15.0
dependabot/go_modules/github.com/jackc/pgx/v5-5.10.0
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.4
dependabot/go_modules/github.com/pkg/sftp-1.13.11
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.20.0
ssh-windows-privilege-check
fix/explicit-cors-handling
fix/remove-math-rand
test/gui-memory-leak-fix
fix/ui-status-dispatch
install-script-ui-dependencies
fix/grpc-get-network-map
fix/subscribe-status-coalesce
fix/tray-menu-item-leak
fix/windows-tray-race
feature/changeset
worktree-dns-route-qtype-fallthrough
mdm_integration
mlsmaycon-patch-2
feat/agent-network-ollama
proxy-tunnel-cache-ttl-env
coderabbitai/utg/1e5b0a5
grpc-acl
test/battery-drain
components-impl-drop-indexes-use-xids-no-resource-policy-map
fix/nmap-relevant-groups
e2e-guardrail-blocks-unselected-model
fix/lazyconn-cold-start-allowed-ips
vertex-guardrails-model-access-e2e
add-atomic-cache-ops
refactor/relay-foreign-cache
ci/trigger-release-tests
feature/kimi-3-agent-networks-dns-warmup
feature/dns-lazy-conn-warmup
daemon-ipc-acl
feature/ui-translation-key-parity-check
refactor/relay-foreign-cache-tests
fix/lazyconn-idle-keep-wg-peer
dmitri-propagate-auth-grant-types-on-combined
0.74.7-branch
diagnose-empty-vs-corrupt-state
windows-sleep-detector
fix/cli-up-wait-for-daemon
rp_key_persistency
feature/native-grpc
0.74.6-branch
0.74.6-branch-sync
0.74.5-branch-sync
0.74.4-branch
fix/remove-stale-peers-removal
fix/remove-stale-proxy-logic
fix/nsis-preserve-autostart-on-upgrade
refactor/peer-event-bus
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3
dependabot/go_modules/github.com/pkg/sftp-1.13.10
components-impl-drop-indexes
fix-reset-aggregation-window-flake
dependabot/go_modules/github.com/pion/dtls/v3-3.1.5
0.74.x
fix/relay-states-lock
update-process-pkg
update-gopsutil-v4
fix/relay_states_lock
increase-sysinfo-timeout
dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
dependabot/go_modules/github.com/eko/gocache/store/redis/v4-4.2.6
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.3
fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
0.74.3-branch
fix/routeselector-atomic-exit-node
netmap_progressive_alignment
nmap/components-impl
dependabot/go_modules/github.com/jackc/pgx/v5-5.9.2
dependabot/go_modules/github.com/oapi-codegen/runtime-1.4.2
dependabot/go_modules/github.com/gopacket/gopacket-1.6.1
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0
dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0
fix/signal-watchdog-sync-stop
docs/agent-network
test/affected-logic
fix/revert-ice-filter
refactor/simplify-affected-peers
pascal-filter-policies-by-direction
claude/lock-contention-peer-connect-g8t6au
dmitri-filter-policies-by-direction
refactor/migrate-profiles-to-go
profile-bindings-ios
fix/skip-restart-unchanged-route
fix/mgmt-cache-async-resolve
refactor/wails-update-105
client_lifetime_serialization_refactor
fix/browser-ssh-2
fix/ipv6-and-netstack-accept-loop
fix/browser-ssh
profile-id-name-test
refactor/mgmt-bootstrap
feat/getting-started-unified-wizard
socket-grpc-permissions
fix/mysql-index-migration
windows-dns-firewall
tests/enable-race-on-tests
ui-refactor-gtk3
feature/affected-peers-grpc
profile-id
lazyconn-first-packet-fix-v2
claude/focused-gates-VMTgb
ui-tray-linux-leftclick
fix/ctx-enrichment
daemon-owner
feature/android-client-ssh
worktree-accept-ra-forwarding
nmap/combined-deploy
task/align_protobuff_toolset
feature/session-extend
add-json-yaml-flags
refactor/ephemeral-cleanup
claude/webtransport-relay-wasm-mUjY9
claude/vnc-udp-feasibility-6KB1U
fix/wgport-config
e2e-windows-dns-combined
fix/login-cmd-root-flags
feat/reseller-openapi-spec
github-issue-resolver
add-steamos-support
fix-darwin-uninstaller
flutter-test
ci/freebsd-pkg-bootstrap
cached-serial-check-on-sync
fix-mgmt-cache-bypass-overlay
revert-easyjson-5938
revert-ice-5820
revert-firewalld-5928
refactor/permissions-manager
revert-dns-5935-systemd-resolved
revert-dns-5935-5945
revert-dns-5945-mgmt-cache
feature/log-most-busy-peers
prototype/ui-wails
coderabbitai/utg/8ae8f20
feature/use-peer-fqdn-on-https
release/0.68.3
add-slack-channel
claude/rdp-token-passthrough-eNcqW
transparent-proxy
fix/macos-stale-route-eexist
crowdsec-selfhosted
fix/remove-otel-units
entire/checkpoints/v1
fix/getting-started
feat/static-connectors-combined-server
feature/use-local-keys-embedded
feature/fleetdm
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.76.1
v0.76.0
v0.75.1
v0.75.0
v0.74.7
v0.74.6
v0.74.5
v0.75.0-rc.6
v0.74.4
v0.74.3
v0.75.0-rc.5
v0.74.2
v0.74.1
v0.75.0-rc.4
v0.74.0
v0.74.0-rc.2
v0.74.0-rc.1
v0.73.2
v0.75.0-rc.3
v0.75.0-rc.2
v0.73.1
v0.75.0-rc.1
v0.73.0
v0.72.4
v0.72.3
v0.72.2
v0.72.1
v0.72.0
v0.71.4
v0.71.3
v0.71.2
v0.71.1
v0.71.0
v0.70.5
v0.70.4
v0.70.3
v0.70.2
v0.70.1
v0.70.0
v0.69.0
v0.68.3
v0.68.2
v0.68.1
v0.68.0
v0.67.4
v0.67.3
v0.67.2
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2021 Q4
2021 Q4
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
accessibility
accessibility
accessibility
acl
acl
acl
agent
agent
agent
agent
agent
agent
Android
Android
Android
Android
Android
Android
api
api
api
authentik
authentik
authentik
automation
automation
automation
azure
azure
azure
battery-usage
battery-usage
battery-usage
bug
cache
cache
cache
client
client
client
client-ui
client-ui
client-ui
cloud
cloud
cloud
cloud-only
cloud-only
cloud-only
cloudflare
cloudflare
cloudflare
community
community
community
compatibility
compatibility
compatibility
config-idp
config-idp
config-idp
config-issue
config-issue
config-issue
connection
connection
connection
contribution
contribution
contribution
coturn
coturn
coturn
cross-vpn
cross-vpn
cross-vpn
dashboard
dashboard
dashboard
data-usage
data-usage
data-usage
distribution
distribution
distribution
dns
dns
dns
docker
docker
docker
documentation
documentation
documentation
duplicate
duplicate
duplicate
enhancement
enhancement
event-stream
event-stream
event-stream
feature-request
feature-request
feature-request
freebsd
freebsd
freebsd
getting-started
getting-started
getting-started
go
go
go
good first issue
good first issue
good first issue
gui
gui
gui
help wanted
help wanted
help wanted
home-assistant
home-assistant
home-assistant
idp
idp
idp
inconsistency
inconsistency
inconsistency
integration
integration
integration
integrations
integrations
integrations
ios
ios
ios
ipv6
ipv6
ipv6
jwt
jwt
jwt
k8s
k8s
k8s
keycloak
keycloak
keycloak
linux
linux
linux
login
login
login
macos
macos
macos
management-service
management-service
management-service
Medium
Medium
Medium
missing-docs
missing-docs
missing-docs
mobile
mobile
mobile
moved-internal
moved-internal
moved-internal
needs-review
needs-review
needs-review
netbird-ui
netbird-ui
netbird-ui
networking
networking
networking
new-platform
new-platform
new-platform
nginx
nginx
nginx
notification
notification
notification
okta
okta
okta
openwrt
openwrt
openwrt
P2
P2
P2
packaging
packaging
packaging
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
performance
performance
performance
postgres
postgres
postgres
posture-checks
posture-checks
posture-checks
psk
psk
psk
pull-request
question
question
question
refactor
refactor
refactor
relay
relay
relay
release
release
release
rfc
rfc
rfc
routes
routes
routes
security
security
security
security-improvement
security-improvement
security-improvement
security-related
security-related
security-related
self-hosting
self-hosting
self-hosting
server
server
server
signal
signal
signal
sleep-issue
sleep-issue
sleep-issue
ssh
ssh
ssh
ssl
ssl
ssl
status
status
status
store
store
store
synology
synology
synology
system-compatibility-issue
system-compatibility-issue
system-compatibility-issue
test-suite
test-suite
test-suite
third-party-integration
third-party-integration
third-party-integration
triage
triage
triage
triage
triage
triage
triage-needed
triage-needed
triage-needed
troubleshooting
troubleshooting
troubleshooting
UX
UX
UX
waiting-feedback
waiting-feedback
waiting-feedback
windows
windows
windows
wontfix
wontfix
wontfix
zitadel
zitadel
zitadel
Mirrored from GitHub Pull Request
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: DYNR/netbird#8592
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @eveyraud on GitHub (Jun 25, 2025).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/4047
UPDATE
Thanks to @lepazca who identified the problem:
I have two machines. One is configured as a routing peer for the network 0.0.0.0/0 (similar to a deprecated exit node configuration). This network definition inherently includes the public IP address of the routing peer itself. Once the P2P connection is established, WireGuard attempts to route subsequent packets through the VPN tunnel to the routing peer (as its routing configuration dictates that traffic for 0.0.0.0/0 should be sent via this peer). This self-referential routing prevents packets from reaching the peer's public IP via the external network, causing the P2P connection to fail. Consequently, the fallback system is triggered, and all traffic is then relayed via TCP.
Describe the problem
After disabling Windows Firewall and EDR, I am currently not able to connect my Windows and Linux peers in P2P together (only relayed connection). When I create a Linux VM in the same network than my Windows, the two can connect perfectly in P2P.
I saw that NetBird wasn't UPnP and I created a rule to accept inbound and outbound connection on the UDP/51820 port (and even disabled FW as I said)
To Reproduce
Steps to reproduce the behavior:
Expected behavior
Connection to be P2P
Are you using NetBird Cloud?
I am using self-hosted NetBird
NetBird version
Linux : 0.49.0, Windows: 0.49.0
Is any other VPN software installed?
Yes, forticlient but it is disabled.
Debug output
To help us resolve the problem, please attach the following anonymized status output
Peers detail:
netbird-gateway.netbird.selfhosted:
NetBird IP: 100.71.125.247
Public key: bGGIji458wjUPLylAqBgv7+bIN8UDa/Ea3viipngPXE=
Status: Connected
-- detail --
Connection type: Relayed
ICE candidate (Local/Remote): -/-
ICE candidate endpoints (Local/Remote): -/-
Relay server address: rels://wg.anon-hcS0Z.domain:443
Last connection update: 3 minutes, 21 seconds ago
Last WireGuard handshake: 1 minute, 22 seconds ago
Transfer status (received/sent) 2.7 MiB/942.3 KiB
Quantum resistance: false
Networks: 0.0.0.0/0
Latency: 0s
Events:
[INFO] NETWORK (71cf2845-907b-45ea-a4ce-a0df5fec2b09)
Message: Default route added
Time: 5 minutes, 45 seconds ago
Metadata: id: ALL, network: 0.0.0.0/0, peer: bGGIji458wjUPLylAqBgv7+bIN8UDa/Ea3viipngPXE=
[INFO] SYSTEM (7ea9ca82-02a3-4826-b6a8-9c786d395be5)
Message: Network map updated
Time: 5 minutes, 45 seconds ago
[WARNING] DNS (2a772dbc-2669-4485-a193-7c6b89e6d583)
Message: All upstream servers failed (probe failed)
Time: 5 minutes, 28 seconds ago
Metadata: upstreams: 172.16.1.6:53, 172.16.1.7:53
[INFO] SYSTEM (2a49d777-679d-47de-9a87-fa688c491d08)
Message: Network map updated
Time: 5 minutes, 28 seconds ago
[INFO] NETWORK (4b72de14-7015-4bb4-968c-957d581240f1)
Message: Default route added
Time: 5 minutes, 28 seconds ago
Metadata: id: ALL, network: 0.0.0.0/0, peer: bGGIji458wjUPLylAqBgv7+bIN8UDa/Ea3viipngPXE=
[INFO] NETWORK (081172e9-65b9-4372-a371-08dcb7780e5a)
Message: Default route added
Time: 5 minutes, 28 seconds ago
Metadata: id: ALL, network: 0.0.0.0/0, peer: bGGIji458wjUPLylAqBgv7+bIN8UDa/Ea3viipngPXE=
[WARNING] DNS (c492914c-178f-4474-936e-c64a6ca8d278)
Message: All upstream servers failed (probe failed)
Time: 3 minutes, 21 seconds ago
Metadata: upstreams: 172.16.1.6:53, 172.16.1.7:53
[INFO] SYSTEM (ba935ef3-8259-4dcf-9f21-d0e24d34e1d7)
Message: Network map updated
Time: 3 minutes, 21 seconds ago
[INFO] NETWORK (1c786484-290f-42a7-b298-0119781d7c35)
Message: Default route added
Time: 3 minutes, 21 seconds ago
Metadata: id: ALL, network: 0.0.0.0/0, peer: bGGIji458wjUPLylAqBgv7+bIN8UDa/Ea3viipngPXE=
[INFO] NETWORK (cac1d46e-7915-4ffc-a282-e96ad2d2beba)
Message: Default route added
Time: 3 minutes, 21 seconds ago
Metadata: id: ALL, network: 0.0.0.0/0, peer: bGGIji458wjUPLylAqBgv7+bIN8UDa/Ea3viipngPXE=
OS: windows/amd64
Daemon version: 0.49.0
CLI version: 0.49.0
Management: Connected to https://wg.anon-hcS0Z.domain:443
Signal: Connected to https://wg.anon-hcS0Z.domain:443
Relays:
[stun:wg.anon-hcS0Z.domain:3478] is Available
[turn:wg.anon-hcS0Z.domain:3478?transport=udp] is Available
[rels://wg.anon-hcS0Z.domain:443] is Available
Nameservers:
[172.16.1.6:53, 172.16.1.7:53] for [.] is Available
FQDN: prt35.netbird.selfhosted
NetBird IP: 100.71.104.14/16
Interface type: Userspace
Quantum resistance: false
Lazy connection: false
Networks: -
Forwarding rules: 0
Peers count: 1/1 Connected
Create and upload a debug bundle, and share the returned file key:
0107b729c324c4562e1e10d3b5be55567aa55c08302d40e822c7a4ca939cd561/acb0b152-7f5a-4853-b36c-e846e625a513
Have you tried these troubleshooting steps?
@Silex commented on GitHub (Jun 25, 2025):
Have one of the peer allow inbound UDP port 51820
@eveyraud commented on GitHub (Jun 25, 2025):
Thanks for your reply,
Both of my peers allows UDP/51820 inbound and outbound. As I said in my ticket, I even tried to disable the firewall of my Windows and the EDR but the problem keeps unchanged. Regarding my Linux peer, it has been able to P2P with another Linux and an Android, only Windows isn't working.
@eveyraud commented on GitHub (Jun 25, 2025):
UPDATE
When I try to connect both of them on a cloud netbird, they can both connect in P2P. This issue seems to only concern self-hosted instances
@SasSam commented on GitHub (Jun 25, 2025):
It's maybe related to the issue that I've raised today: https://github.com/netbirdio/netbird/issues/4045
Try to downgrade the Windows client to 0.48.0
@eveyraud commented on GitHub (Jun 26, 2025):
Unfortunatly, no, I had the issue on 0.47.2, I then upgraded to 0.48.0, still had it and then finally upgraded to 0.49.0
@eveyraud commented on GitHub (Jun 26, 2025):
After reading some more docs I found this:
https://netbird.io/knowledge-hub/enhancing-network-visibility-with-traffic-events-logging
I then tried hopelessly to remove the Linux his role of exit node for the Windows peer, now I'm able to P2P between the two machines.
Now my questions are:
- Is that a normal behavior ?
- Is it possible to use UDP in such a context ?
@lepazca commented on GitHub (Jun 28, 2025):
I did some tests to compare how traffic behaves when using a traditional WireGuard client versus the NetBird client while routing all traffic through an exit node:
🔹 Test 1: Traditional WireGuard client
When connecting to a WireGuard server:
The default route (0.0.0.0/0) is set to go through the tunnel, and an explicit route is added for the WireGuard server’s public IP via the real interface, ensuring it is reachable outside the tunnel (avoiding loops or fallback to relayed mode).
🔹 Test 2: NetBird client using an exit node
With NetBird connected to an exit node:
The default route (0.0.0.0/0) is pushed through the NetBird tunnel (wt0), but no dedicated route is added for the exit node’s public IP. As a result, traffic to the exit node itself also goes through the tunnel interface, which leads to:
This behavior is consistent and happens only when using the peer as an exit node.
I only run these tests on Linux; both peers are using NetBird v0.49.0.
@lepazca commented on GitHub (Jun 28, 2025):
I just tested it on Windows and it behaved in the same way. The Netbird client does not add a static route for the public IP address of the exit node. I assume this is the only way to avoid interfering with the P2P connection between the client and the exit node. Please correct me if I am wrong.
@eveyraud commented on GitHub (Jun 30, 2025):
I thought about it but tbh I didn't search further. You are absolutely right, that's what I notice too. I'm not sure this behavior is wanted by the devs but just in case, I created a feature request: #4069
@nazarewk commented on GitHub (Jun 30, 2025):
@lepazca thanks for the analysis! Turns out the dev team was disussing this some time in the past, but didn't pursue the implementation, we will definitely look at it sooner than later
@nazarewk commented on GitHub (Jun 30, 2025):
@lepazca actually after further clarification this (routing of IPs) is something we are doing either in a separate routing table (linux) or on-demand upon detecting outbound connection (most other systems) so it should not be an issue.
Would it be possible for you to provide a
netbird debug for 1m -SUfor the affected devices? We would like to investigate this further@nazarewk commented on GitHub (Jun 30, 2025):
@eveyraud Could you also send us a debug bundle from
netbird-gateway.netbird.selfhostedPeer? We have noticed a suspicious candidate from within NetBird networking range which should not be there and want to learn more about it:@lepazca commented on GitHub (Jun 30, 2025):
@nazarewk Thanks for the clarification and for looking into this.
I've performed the tests as requested and uploaded the debug data.
Here is the upload file key:
Let me know if you need anything else from my side.
@eveyraud commented on GitHub (Jun 30, 2025):
IP addresses changed as I removed and added back some machines, but the IP your pointing was the peer "netbird-gateway". Just in case it can help you, here are the files from both peers:
Upload file key from NetBird-Gateway:
0107b729c324c4562e1e10d3b5be55567aa55c08302d40e822c7a4ca939cd561/2c406be5-8009-4208-9db0-19c88ccf3c9dUpload file key from Windows peer:
0107b729c324c4562e1e10d3b5be55567aa55c08302d40e822c7a4ca939cd561/0eb3d2b5-c8ed-418b-a468-8f8d92d46c91file keys updated I gave wrong ones
@eveyraud commented on GitHub (Jul 15, 2025):
Could you please let me know if there have been any updates on this topic?
Regarding the warning you mentioned, do you think it's something concerning, or is it simply log noise?
Thanks for your help and answers
@stevo11811 commented on GitHub (Jul 15, 2025):
Ah, thanks for the detailed post, I just ran into the same issue during testing and was beating my head against a wall.
@nazarewk commented on GitHub (Jul 15, 2025):
@eveyraud The part about trying to use NetBird IP as an ICE candidate is suspicious. We have found some additional information there, but we will need additional ICE logs (enabled separately) to get to the bottom of this issue.
Could you enable PION logs on your Windows client and gather a debug bundle for 1 minute again? https://docs.netbird.io/how-to/troubleshooting-client#debugging-ice-connections
PS: It would help if the debug bundle wasn't anonymized for more easily determining the exact IP address <> domain correlations. The logs are only accessible by developers through the internal storage system and are deleted after 30 days if you have any concerns about it.
@eveyraud commented on GitHub (Jul 16, 2025):
Of course, I can give you the logs. However due to cybersecurity policy I am only able to provide you the anonymized version. Giving you non-anonymized IPs or domains just isn't something we can do.
Also, the doc you gave me concerns linux commands, I tried to manually set the environment variable:
[Environment]::SetEnvironmentVariable("PIONS_LOG_DEBUG", "all", "Machine")[Environment]::SetEnvironmentVariable("NB_LOG_LEVEL", "debug", "Machine")netbird up -F --log-level debug > C:\Temp\netbird.log 2>&1But the given logs seems not to be very different from those I gave you. Am I wrong somewhere between the commands used and the returned logs ?
@nazarewk commented on GitHub (Jul 17, 2025):
@eveyraud I have checked this myself and indeed it looks like the logs aren't redirected to the expected places (the ICE library uses different logger implementation), on a fresh Ubuntu instance I found the PION logs at
/var/log/netbird/netbird.out. I'll try to find out how to access those in other environments and get back to you.For the future, you don't really need to run NetBird in the foreground; just restarting a service should suffice.
@lixmal commented on GitHub (Jul 22, 2025):
Hey folks, can you please test https://github.com/netbirdio/netbird/releases/tag/v0.51.2 and report whether the problem has been fixed for you.
@eveyraud commented on GitHub (Jul 22, 2025):
Issue fixed on my side. Still have the log spam @nazarewk mentionned though.
Thank you a lot for the fix !
@stevo11811 commented on GitHub (Jul 22, 2025):
This is working for me! Thanks everyone.
@maxideus85 commented on GitHub (Jul 24, 2025):
I'm not sure if this is the correct place to ask this, but I am having this issue even on 0.51.2. Please let me know if I need to spin up my own thread. I have some details below in case I can write my issue here.
I have a test environment with an Ubuntu VM running Docker CE and the Netbird containers deployed following the advanced guide. I also deployed a container for the Netbird agent on the same host to act as an exit node that's using host networking.
In the prior version of 0.51.1 for all containers, I was able to get P2P connections between my Windows endpoint and the exit node. However, in the latest release of 0.51.2, I am now only able to get relayed connections. I have ensured all ports are accessible so I don't think it's a firewall or NAT issue.
Can I get some help?
@lixmal commented on GitHub (Jul 25, 2025):
@maxideus85
please do
@lepazca commented on GitHub (Jul 27, 2025):
Hi, sorry for the delay in providing feedback.
I'm still experiencing the same issue even after updating to version 0.51.2. When I enable the exit node, the connection switches to relayed. I understand some users have reported this issue as resolved, but perhaps the root cause in my case is different.
As before I captured the logs in case they help identify the issue.
c04854b95ffd40870e1dff93227236c1cce3c359fdeb83899a046975941e66e7/fab17525-9dba-463d-988d-7e94f1ae548aThank you
@lixmal commented on GitHub (Jul 27, 2025):
@lepazca, this is a Linux machine; Linux is not affected by this bug.
You have a block rule in the
OUTPUTchain. Could that be the issue?@lepazca commented on GitHub (Jul 27, 2025):
Thank you for the follow-up.
These rules were added by ExpressVPN, which I had previously installed on the machine. I have now stopped the ExpressVPN service and confirmed that all related evpn.* chains have been removed. I also flushed all iptables rules to ensure a clean environment.
After that, I repeated the test using netbird debug with the same setup, and unfortunately the issue still persists. Here is the new debug log ID:
c04854b95ffd40870e1dff93227236c1cce3c359fdeb83899a046975941e66e7/6ad1b43d-ee50-46a4-a4e7-1b45178ac9d2Thanks again for the guidance!