Allow Access Policy to Refer to Peer instead of group #2040

Open
opened 2025-11-20 06:11:41 -05:00 by saavagebueno · 0 comments
Owner

Originally created by @Blackclaws on GitHub (Jul 4, 2025).

Is your feature request related to a problem? Please describe.
We have a lot of cases where we want to have individual point to point connections set up. Right now (if you're not talking about resources where this works) we can only do this via groups. This leads to lots of groups with single members that clog the group list.

Describe the solution you'd like
Ability to similar as with resources select individual peers as targets for both the Source and Destination parts of an access policy

Describe alternatives you've considered
None really, we are currently adding individual groups for peers to do this and this leads to an explosion in access policies

Additional context
The reason we are doing this is because we have set up vnc sessions on servers with fixed screen numbers (mapping to ports). As an additional security measure we only want certain devices (depending on policy) of users to be able to access certain ports. Since this is a per user mapping this then leads to the aforementioned problem.

Originally created by @Blackclaws on GitHub (Jul 4, 2025). **Is your feature request related to a problem? Please describe.** We have a lot of cases where we want to have individual point to point connections set up. Right now (if you're not talking about resources where this works) we can only do this via groups. This leads to lots of groups with single members that clog the group list. **Describe the solution you'd like** Ability to similar as with resources select individual peers as targets for both the Source and Destination parts of an access policy **Describe alternatives you've considered** None really, we are currently adding individual groups for peers to do this and this leads to an explosion in access policies **Additional context** The reason we are doing this is because we have set up vnc sessions on servers with fixed screen numbers (mapping to ports). As an additional security measure we only want certain devices (depending on policy) of users to be able to access certain ports. Since this is a per user mapping this then leads to the aforementioned problem.
saavagebueno added the feature-request label 2025-11-20 06:11:41 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SVI/netbird#2040