[GH-ISSUE #4908] Remote-SSH (VS Code & Cursor) fails when NetBird SSH is enabled #9507

Open
opened 2026-08-05 01:22:24 -04:00 by saavagebueno · 1 comment
Owner

Originally created by @aliberts on GitHub (Dec 3, 2025).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/4908

Describe the problem

When NetBird SSH is enabled on a peer (--allow-server-ssh + dashboard toggle), both VS Code Remote-SSH and Cursor fail to connect to that machine.

VS Code and Cursor bootstrap their remote environment using:

ssh -v -T -D <port> <host>

When connecting to a peer with NetBird SSH enabled, the SSH connection authenticates but terminates immediately with:

Authenticated using "none".
no command specified and Pty not requested
ssh child died, shutting down

This prevents VS Code/Cursor from starting their remote server.

If I disable NetBird SSH on that same peer, the connection works perfectly again.
The traffic still goes through the NetBird network (100.x.x.x IP), but since the system’s OpenSSH server handles port 22 instead of the embedded NetBird SSH server, the -T -D forwarding mode works normally.

This appears to match the issue reported here:
https://forum.netbird.io/t/vscode-ssh-on-v0-60-0/344

To Reproduce

  1. On a Linux peer, enable NetBird SSH:
    • Start client with:
      netbird up --allow-server-ssh
      
    • Enable SSH for that peer in the NetBird Cloud dashboard.
  2. From another machine, attempt to connect via VS Code Remote-SSH or Cursor
    (or manually reproduce the connection they use):
ssh -v -T -D 60111 <peer-name>
  1. Observe that the SSH connection authenticates but then terminates with:
no command specified and Pty not requested
  1. Disable NetBird SSH for that peer and retry the same command.
    → SSH stays open and VS Code/Cursor connect normally.

Expected behavior

VS Code and Cursor should be able to establish SSH sessions even when NetBird SSH is enabled.
Specifically, the NetBird SSH server should support (or properly proxy) sessions using:

  • dynamic port forwarding (-D <port>),
  • no PTY (-T),
  • no remote command.

These are required by Remote-SSH during initialization.

Are you using NetBird Cloud?

Yes (Team plan)

NetBird version

v0.60.4 (on all peers)

Is any other VPN software installed?

No

Debug output

From the remote machine I'm trying to connect to:

$ netbird status -dA
Peers detail:
 mickael-mbp.netbird.cloud:
  NetBird IP: 100.99.63.190/32
  Public key: B2IDmO/OKtu0BVza0Nz1bhfWTBIKrcH1vdePs53QWCI=
  Status: Idle
  -- detail --
  Connection type: -
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: 
  Last connection update: 43 seconds ago
  Last WireGuard handshake: -
  Transfer status (received/sent) 0 B/0 B
  Quantum resistance: false
  Networks: -
  Latency: 0s

 leo-mpb.netbird.cloud:
  NetBird IP: 100.99.114.80/32
  Public key: RUqv3QduI/cvxqxAn0GPNFu5XFvVaWqeIOnNumJ13Rc=
  Status: Idle
  -- detail --
  Connection type: -
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: 
  Last connection update: 43 seconds ago
  Last WireGuard handshake: -
  Transfer status (received/sent) 0 B/0 B
  Quantum resistance: false
  Networks: -
  Latency: 0s

 simon-mbp.netbird.cloud:
  NetBird IP: 100.99.78.41/32
  Public key: kbO/XudwwjIIo1LpwMgto2vfiDz8DYbXDs5I1Ed+Vkc=
  Status: Idle
  -- detail --
  Connection type: -
  ICE candidate (Local/Remote): -/-
  ICE candidate endpoints (Local/Remote): -/-
  Relay server address: 
  Last connection update: 43 seconds ago
  Last WireGuard handshake: -
  Transfer status (received/sent) 0 B/0 B
  Quantum resistance: false
  Networks: -
  Latency: 0s

 mustafa-mbp-25-39.netbird.cloud:
  NetBird IP: 100.99.25.39
  Public key: HbIVNyvprpm7tDZhU74AM83op/su+/33CVhuVCMO7VM=
  Status: Connected
  -- detail --
  Connection type: P2P
  ICE candidate (Local/Remote): host/host
  ICE candidate endpoints (Local/Remote): 192.168.4.120:51820/192.168.4.79:51820
  Relay server address: rels://streamline-es-mad1-1.relay.netbird.io:443
  Last connection update: 42 seconds ago
  Last WireGuard handshake: 38 seconds ago
  Transfer status (received/sent) 108.9 KiB/90.9 KiB
  Quantum resistance: false
  Networks: -
  Latency: 4.053025ms

 simon-mbpu.netbird.cloud:
  NetBird IP: 100.99.240.62
  Public key: yMkkUUFFeiwHoSafNpvEWB3Lu05DA/DWbAr6vege318=
  Status: Connected
  -- detail --
  Connection type: P2P
  ICE candidate (Local/Remote): host/host
  ICE candidate endpoints (Local/Remote): 192.168.4.120:51820/192.168.4.208:51820
  Relay server address: rels://streamline-es-mad1-0.relay.netbird.io:443
  Last connection update: 42 seconds ago
  Last WireGuard handshake: 43 seconds ago
  Transfer status (received/sent) 212 B/156 B
  Quantum resistance: false
  Networks: -
  Latency: 6.41323ms

Events:
  [INFO] SYSTEM (ae8dc1fa-ae9d-457b-ba15-478d366a5d0e)
    Message: Network map updated
    Time: 23 hours, 42 minutes ago
  [INFO] SYSTEM (32030ab6-edfb-4e15-87e9-f097d952faae)
    Message: Network map updated
    Time: 23 hours, 42 minutes ago
  [INFO] SYSTEM (548b2577-7234-4401-a791-9bc16586e709)
    Message: Network map updated
    Time: 23 hours, 26 minutes ago
  [INFO] SYSTEM (ce55a26c-d97d-4c4a-a653-cc2dcb2e4896)
    Message: Network map updated
    Time: 11 hours, 42 minutes ago
  [INFO] SYSTEM (a9460f57-cb6a-43cf-90d1-4c77463a1c45)
    Message: Network map updated
    Time: 7 hours ago
  [INFO] SYSTEM (f8457c59-eb8d-4db2-89a6-5e15e33fc28a)
    Message: Network map updated
    Time: 7 hours ago
  [INFO] SYSTEM (bd034f46-ebdc-453c-b45f-fa9b7f348cb4)
    Message: Network map updated
    Time: 2 hours, 12 minutes ago
  [INFO] SYSTEM (efd41ace-9dc2-4a1b-807e-42141e469419)
    Message: Network map updated
    Time: 2 hours, 12 minutes ago
  [INFO] SYSTEM (cda48b45-7dc2-4ae2-bbf8-1c08a474ef39)
    Message: Network map updated
    Time: 2 hours, 11 minutes ago
  [INFO] SYSTEM (de206ef4-c0b5-49e7-a30a-e3cb652f7f59)
    Message: Network map updated
    Time: 43 seconds ago
OS: linux/amd64
Daemon version: 0.60.4
CLI version: 0.60.4
Profile: default
Management: Connected to https://api.netbird.io:443
Signal: Connected to https://signal.netbird.io:443
Relays: 
  [stun:stun.netbird.io:443] is Available
  [stun:stun.netbird.io:5555] is Available
  [turns:turn.netbird.io:443?transport=tcp] is Available
  [rels://streamline-es-mad1-1.relay.netbird.io:443] is Available
Nameservers: 
FQDN: umachine-2.netbird.cloud
NetBird IP: 100.99.55.70/16
Interface type: Kernel
Quantum resistance: false
Lazy connection: false
SSH Server: Disabled
Networks: -
Forwarding rules: 0
Peers count: 2/5 Connected

Debug key after disabling ssh on the dashboard and successfully connecting to the peer with VSCode:

netbird debug for 10s -AS -U

Upload file key:
f79e391890ab27fb37c88b3b4be7011e22aa2e5ca6f38ffa9c4481884941f726/2e143895-4db6-475e-bb33-a3bfb59d1c22

Debug key after enabling ssh on the dashboard and failing to connect to the peer with VSCode:

netbird debug for 10s -AS -U

Upload file key:
f79e391890ab27fb37c88b3b4be7011e22aa2e5ca6f38ffa9c4481884941f726/95af4307-378c-4823-b513-dd16781a1e59

Screenshots

N/A — the relevant output is in the SSH logs.

Additional context

  • Using VS Code 1.106.3 and Cursor 2.1.46, both exhibit the same failure.
  • Issue is reproducible across multiple machines.
  • Normal SSH works fine to the same NetBird IP both with and without NetBird SSH enabled.
  • The issue occurs only when the embedded NetBird SSH server intercepts port 22.
  • Disabling NetBird SSH immediately restores compatibility.

Have you tried these troubleshooting steps?

  • Reviewed client troubleshooting (if applicable)
  • Checked for newer NetBird versions
  • Searched for similar issues on GitHub (including closed ones)
  • Restarted the NetBird client
  • Disabled other VPN software
  • Checked firewall settings

Happy to test patches, development builds, or configuration suggestions.

Originally created by @aliberts on GitHub (Dec 3, 2025). Original GitHub issue: https://github.com/netbirdio/netbird/issues/4908 **Describe the problem** When **NetBird SSH** is enabled on a peer (`--allow-server-ssh` + dashboard toggle), both **VS Code Remote-SSH** and **Cursor** fail to connect to that machine. VS Code and Cursor bootstrap their remote environment using: ```shell ssh -v -T -D <port> <host> ``` When connecting to a peer with **NetBird SSH enabled**, the SSH connection authenticates but terminates immediately with: ``` Authenticated using "none". no command specified and Pty not requested ssh child died, shutting down ``` This prevents VS Code/Cursor from starting their remote server. If I **disable NetBird SSH** on that same peer, the connection works perfectly again. The traffic still goes through the NetBird network (100.x.x.x IP), but since the system’s OpenSSH server handles port 22 instead of the embedded NetBird SSH server, the `-T -D` forwarding mode works normally. This appears to match the issue reported here: https://forum.netbird.io/t/vscode-ssh-on-v0-60-0/344 **To Reproduce** 1. On a Linux peer, enable NetBird SSH: - Start client with: ``` netbird up --allow-server-ssh ``` - Enable SSH for that peer in the NetBird Cloud dashboard. 2. From another machine, attempt to connect via VS Code Remote-SSH or Cursor (or manually reproduce the connection they use): ```shell ssh -v -T -D 60111 <peer-name> ``` 3. Observe that the SSH connection authenticates but then terminates with: ``` no command specified and Pty not requested ``` 4. Disable NetBird SSH for that peer and retry the same command. → SSH stays open and VS Code/Cursor connect normally. **Expected behavior** VS Code and Cursor should be able to establish SSH sessions even when NetBird SSH is enabled. Specifically, the NetBird SSH server should support (or properly proxy) sessions using: - dynamic port forwarding (`-D <port>`), - no PTY (`-T`), - no remote command. These are required by Remote-SSH during initialization. **Are you using NetBird Cloud?** Yes (Team plan) **NetBird version** `v0.60.4` (on all peers) **Is any other VPN software installed?** No **Debug output** From the remote machine I'm trying to connect to: ```shell $ netbird status -dA Peers detail: mickael-mbp.netbird.cloud: NetBird IP: 100.99.63.190/32 Public key: B2IDmO/OKtu0BVza0Nz1bhfWTBIKrcH1vdePs53QWCI= Status: Idle -- detail -- Connection type: - ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: Last connection update: 43 seconds ago Last WireGuard handshake: - Transfer status (received/sent) 0 B/0 B Quantum resistance: false Networks: - Latency: 0s leo-mpb.netbird.cloud: NetBird IP: 100.99.114.80/32 Public key: RUqv3QduI/cvxqxAn0GPNFu5XFvVaWqeIOnNumJ13Rc= Status: Idle -- detail -- Connection type: - ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: Last connection update: 43 seconds ago Last WireGuard handshake: - Transfer status (received/sent) 0 B/0 B Quantum resistance: false Networks: - Latency: 0s simon-mbp.netbird.cloud: NetBird IP: 100.99.78.41/32 Public key: kbO/XudwwjIIo1LpwMgto2vfiDz8DYbXDs5I1Ed+Vkc= Status: Idle -- detail -- Connection type: - ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: Last connection update: 43 seconds ago Last WireGuard handshake: - Transfer status (received/sent) 0 B/0 B Quantum resistance: false Networks: - Latency: 0s mustafa-mbp-25-39.netbird.cloud: NetBird IP: 100.99.25.39 Public key: HbIVNyvprpm7tDZhU74AM83op/su+/33CVhuVCMO7VM= Status: Connected -- detail -- Connection type: P2P ICE candidate (Local/Remote): host/host ICE candidate endpoints (Local/Remote): 192.168.4.120:51820/192.168.4.79:51820 Relay server address: rels://streamline-es-mad1-1.relay.netbird.io:443 Last connection update: 42 seconds ago Last WireGuard handshake: 38 seconds ago Transfer status (received/sent) 108.9 KiB/90.9 KiB Quantum resistance: false Networks: - Latency: 4.053025ms simon-mbpu.netbird.cloud: NetBird IP: 100.99.240.62 Public key: yMkkUUFFeiwHoSafNpvEWB3Lu05DA/DWbAr6vege318= Status: Connected -- detail -- Connection type: P2P ICE candidate (Local/Remote): host/host ICE candidate endpoints (Local/Remote): 192.168.4.120:51820/192.168.4.208:51820 Relay server address: rels://streamline-es-mad1-0.relay.netbird.io:443 Last connection update: 42 seconds ago Last WireGuard handshake: 43 seconds ago Transfer status (received/sent) 212 B/156 B Quantum resistance: false Networks: - Latency: 6.41323ms Events: [INFO] SYSTEM (ae8dc1fa-ae9d-457b-ba15-478d366a5d0e) Message: Network map updated Time: 23 hours, 42 minutes ago [INFO] SYSTEM (32030ab6-edfb-4e15-87e9-f097d952faae) Message: Network map updated Time: 23 hours, 42 minutes ago [INFO] SYSTEM (548b2577-7234-4401-a791-9bc16586e709) Message: Network map updated Time: 23 hours, 26 minutes ago [INFO] SYSTEM (ce55a26c-d97d-4c4a-a653-cc2dcb2e4896) Message: Network map updated Time: 11 hours, 42 minutes ago [INFO] SYSTEM (a9460f57-cb6a-43cf-90d1-4c77463a1c45) Message: Network map updated Time: 7 hours ago [INFO] SYSTEM (f8457c59-eb8d-4db2-89a6-5e15e33fc28a) Message: Network map updated Time: 7 hours ago [INFO] SYSTEM (bd034f46-ebdc-453c-b45f-fa9b7f348cb4) Message: Network map updated Time: 2 hours, 12 minutes ago [INFO] SYSTEM (efd41ace-9dc2-4a1b-807e-42141e469419) Message: Network map updated Time: 2 hours, 12 minutes ago [INFO] SYSTEM (cda48b45-7dc2-4ae2-bbf8-1c08a474ef39) Message: Network map updated Time: 2 hours, 11 minutes ago [INFO] SYSTEM (de206ef4-c0b5-49e7-a30a-e3cb652f7f59) Message: Network map updated Time: 43 seconds ago OS: linux/amd64 Daemon version: 0.60.4 CLI version: 0.60.4 Profile: default Management: Connected to https://api.netbird.io:443 Signal: Connected to https://signal.netbird.io:443 Relays: [stun:stun.netbird.io:443] is Available [stun:stun.netbird.io:5555] is Available [turns:turn.netbird.io:443?transport=tcp] is Available [rels://streamline-es-mad1-1.relay.netbird.io:443] is Available Nameservers: FQDN: umachine-2.netbird.cloud NetBird IP: 100.99.55.70/16 Interface type: Kernel Quantum resistance: false Lazy connection: false SSH Server: Disabled Networks: - Forwarding rules: 0 Peers count: 2/5 Connected ``` Debug key after **disabling ssh** on the dashboard and successfully connecting to the peer with VSCode: ```shell netbird debug for 10s -AS -U Upload file key: f79e391890ab27fb37c88b3b4be7011e22aa2e5ca6f38ffa9c4481884941f726/2e143895-4db6-475e-bb33-a3bfb59d1c22 ``` Debug key after **enabling ssh** on the dashboard and failing to connect to the peer with VSCode: ```shell netbird debug for 10s -AS -U Upload file key: f79e391890ab27fb37c88b3b4be7011e22aa2e5ca6f38ffa9c4481884941f726/95af4307-378c-4823-b513-dd16781a1e59 ``` **Screenshots** N/A — the relevant output is in the SSH logs. **Additional context** - Using VS Code 1.106.3 and Cursor 2.1.46, both exhibit the same failure. - Issue is reproducible across multiple machines. - Normal SSH works fine to the same NetBird IP both with and without NetBird SSH enabled. - The issue occurs only when the embedded NetBird SSH server intercepts port 22. - Disabling NetBird SSH immediately restores compatibility. **Have you tried these troubleshooting steps?** - [x] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [x] Checked for newer NetBird versions - [x] Searched for similar issues on GitHub (including closed ones) - [x] Restarted the NetBird client - [x] Disabled other VPN software - [x] Checked firewall settings Happy to test patches, development builds, or configuration suggestions.
saavagebueno added the triage-needed label 2026-08-05 01:22:24 -04:00
Author
Owner

@maubrunn commented on GitHub (Feb 25, 2026):

I had the same problem, but with the newest version and by adding the --allow-server-ssh --disable-ssh-auth --enable-ssh-sftp --enable-ssh-local-port-forwarding --enable-ssh-remote-port-forwarding flags I was able to solve it. Maybe this also solves it for you.

<!-- gh-comment-id:3957552635 --> @maubrunn commented on GitHub (Feb 25, 2026): I had the same problem, but with the newest version and by adding the `--allow-server-ssh --disable-ssh-auth --enable-ssh-sftp --enable-ssh-local-port-forwarding --enable-ssh-remote-port-forwarding` flags I was able to solve it. Maybe this also solves it for you.
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#9507