Posture checks peer network range failed on iphone #1962

Open
opened 2025-11-20 06:10:17 -05:00 by saavagebueno · 2 comments
Owner

Originally created by @mannguyen0107 on GitHub (Jun 12, 2025).

Describe the problem

I have setup policy for my personal group (which my iPhone peer is apart of) to connect to my homelab server group with posture checks peer network range for my home server subnets so if I'm connecting to my wifi the policy doesnt apply. However even if I'm on 5G or any wifi that the subnet is not apart of the subnets defined in the posture check the policy still block my iPhone because I do not see my home lab peers when I'm supposed to. The policy works if I'm on my MacBook connecting to a different wifi with subnet not in the posture check

To Reproduce

Steps to reproduce the behavior:

  1. Assign 2 peers (1 iPhone and another peer) to 2 different groups A and B
  2. Create Posture check peer network range (blocked) and put in the subnet of home wifi for example 192.168.1.0/24
  3. Create a policy that allow group A (iPhone peer apart of) to connect to group B if posture check is satisfy
  4. Connect iPhone to 5G and connect to netbird
  5. Do not see peer(s) in group B in the list of connected peers

Expected behavior

Expect to see peer(s) in group B in the list of connected peers on netbird iPhone App

Are you using NetBird Cloud?

I'm using self-host NetBird's control plane.

NetBird version

netbird server version: 0.46.0
iphone netbird agent version: 0.36.4-dev

Is any other VPN software installed?

no

Debug output

To help us resolve the problem, please attach the following anonymized status output

netbird status -dA

Create and upload a debug bundle, and share the returned file key:

netbird debug for 1m -AS -U

Uploaded files are automatically deleted after 30 days.

Alternatively, create the file only and attach it here manually:

netbird debug for 1m -AS

Not relevant with iPhone app?

Screenshots

If applicable, add screenshots to help explain your problem.

Additional context

Add any other context about the problem here.

Have you tried these troubleshooting steps?

  • Reviewed client troubleshooting (if applicable)
  • Checked for newer NetBird versions
  • Searched for similar issues on GitHub (including closed ones)
  • Restarted the NetBird client
  • Disabled other VPN software
  • Checked firewall settings
Originally created by @mannguyen0107 on GitHub (Jun 12, 2025). **Describe the problem** I have setup policy for my personal group (which my iPhone peer is apart of) to connect to my homelab server group with posture checks peer network range for my home server subnets so if I'm connecting to my wifi the policy doesnt apply. However even if I'm on 5G or any wifi that the subnet is not apart of the subnets defined in the posture check the policy still block my iPhone because I do not see my home lab peers when I'm supposed to. The policy works if I'm on my MacBook connecting to a different wifi with subnet not in the posture check **To Reproduce** Steps to reproduce the behavior: 1. Assign 2 peers (1 iPhone and another peer) to 2 different groups A and B 2. Create Posture check peer network range (blocked) and put in the subnet of home wifi for example 192.168.1.0/24 3. Create a policy that allow group A (iPhone peer apart of) to connect to group B if posture check is satisfy 4. Connect iPhone to 5G and connect to netbird 5. Do not see peer(s) in group B in the list of connected peers **Expected behavior** Expect to see peer(s) in group B in the list of connected peers on netbird iPhone App **Are you using NetBird Cloud?** I'm using self-host NetBird's control plane. **NetBird version** netbird server version: 0.46.0 iphone netbird agent version: 0.36.4-dev **Is any other VPN software installed?** no **Debug output** To help us resolve the problem, please attach the following anonymized status output netbird status -dA Create and upload a debug bundle, and share the returned file key: netbird debug for 1m -AS -U *Uploaded files are automatically deleted after 30 days.* Alternatively, create the file only and attach it here manually: netbird debug for 1m -AS Not relevant with iPhone app? **Screenshots** If applicable, add screenshots to help explain your problem. **Additional context** Add any other context about the problem here. **Have you tried these troubleshooting steps?** - [x] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [x] Checked for newer NetBird versions - [x] Searched for similar issues on GitHub (including closed ones) - [x] Restarted the NetBird client - [x] Disabled other VPN software - [x] Checked firewall settings
saavagebueno added the triage-needed label 2025-11-20 06:10:17 -05:00
Author
Owner

@citgot commented on GitHub (Sep 8, 2025):

I have the same problem on Android, so you are not alone.

@citgot commented on GitHub (Sep 8, 2025): I have the same problem on Android, so you are not alone.
Author
Owner

@robotkid450 commented on GitHub (Oct 28, 2025):

Also having the same issue on Android. The peer network range posture check seems to always deny access.

@robotkid450 commented on GitHub (Oct 28, 2025): Also having the same issue on Android. The peer network range posture check seems to always deny access.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SVI/netbird#1962