Posture block Client notification #2228

Open
opened 2025-11-20 07:06:13 -05:00 by saavagebueno · 4 comments
Owner

Originally created by @i-am-ez76 on GitHub (Aug 26, 2025).

Hello.
the posture checks on policies is a great feature but creates a major IT headache.
when a client is blocked from accessing a resource due to policy posture check, he is just blocked without knowing why he can't access the resource he needs.
that means that IT needs to check group membership, policy configurations and client agent (at least this is the cause on the self hosted version).

It would be great if the client can get a gui notification that he cannot reach the resource he needs because of a failed posture check.

"The resource you need is blocked due to out-of-date OS / Out-of-date AV / geolocation restrictions and etc"
if you want to make this more IT friendly, notify the Netbird admins via email / gui pop-up (or maybe even webhook configurations so we can configure the block notification via slack).

Originally created by @i-am-ez76 on GitHub (Aug 26, 2025). Hello. the posture checks on policies is a great feature but creates a major IT headache. when a client is blocked from accessing a resource due to policy posture check, he is just blocked without knowing why he can't access the resource he needs. that means that IT needs to check group membership, policy configurations and client agent (at least this is the cause on the self hosted version). It would be great if the client can get a gui notification that he cannot reach the resource he needs because of a failed posture check. "The resource you need is blocked due to out-of-date OS / Out-of-date AV / geolocation restrictions and etc" if you want to make this more IT friendly, notify the Netbird admins via email / gui pop-up (or maybe even webhook configurations so we can configure the block notification via slack).
saavagebueno added the peer-managementfeature-requestUXposture-checks labels 2025-11-20 07:06:13 -05:00
Author
Owner

@1nerdyguy commented on GitHub (Aug 26, 2025):

If this was to be added, I'd want to be able to turn it off.

last thing I want is to be able to have a malicious actor who gained access to a machine know exactly what they need to 'fix' to gain access to another one.

@1nerdyguy commented on GitHub (Aug 26, 2025): If this was to be added, I'd want to be able to turn it off. last thing I want is to be able to have a malicious actor who gained access to a machine know exactly what they need to 'fix' to gain access to another one.
Author
Owner

@mlsmaycon commented on GitHub (Aug 26, 2025):

@i-am-ez76 @1nerdyguy would a generic message help?

@mlsmaycon commented on GitHub (Aug 26, 2025): @i-am-ez76 @1nerdyguy would a generic message help?
Author
Owner

@i-am-ez76 commented on GitHub (Aug 26, 2025):

Well a genetic message can produce an event id so they can forward to IT
and then IT can check the logs to see what was the restrictions.
But the dashboard need to be able to search for these id.
Or notify the admins via email about the block so we can proactively
contact the user

On Tue, Aug 26, 2025, 22:36 Maycon Santos @.***> wrote:

mlsmaycon left a comment (netbirdio/netbird#4402)
https://github.com/netbirdio/netbird/issues/4402#issuecomment-3225809342

@i-am-ez76 https://github.com/i-am-ez76 @1nerdyguy
https://github.com/1nerdyguy would a generic message help?


Reply to this email directly, view it on GitHub
https://github.com/netbirdio/netbird/issues/4402#issuecomment-3225809342,
or unsubscribe
https://github.com/notifications/unsubscribe-auth/BVKKSERH7BWGXWMH3LARRFL3PTHPVAVCNFSM6AAAAACE2ZRWD6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZTEMRVHAYDSMZUGI
.
You are receiving this because you were mentioned.Message ID:
@.***>

@i-am-ez76 commented on GitHub (Aug 26, 2025): Well a genetic message can produce an event id so they can forward to IT and then IT can check the logs to see what was the restrictions. But the dashboard need to be able to search for these id. Or notify the admins via email about the block so we can proactively contact the user On Tue, Aug 26, 2025, 22:36 Maycon Santos ***@***.***> wrote: > *mlsmaycon* left a comment (netbirdio/netbird#4402) > <https://github.com/netbirdio/netbird/issues/4402#issuecomment-3225809342> > > @i-am-ez76 <https://github.com/i-am-ez76> @1nerdyguy > <https://github.com/1nerdyguy> would a generic message help? > > — > Reply to this email directly, view it on GitHub > <https://github.com/netbirdio/netbird/issues/4402#issuecomment-3225809342>, > or unsubscribe > <https://github.com/notifications/unsubscribe-auth/BVKKSERH7BWGXWMH3LARRFL3PTHPVAVCNFSM6AAAAACE2ZRWD6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZTEMRVHAYDSMZUGI> > . > You are receiving this because you were mentioned.Message ID: > ***@***.***> >
Author
Owner

@1nerdyguy commented on GitHub (Aug 26, 2025):

@i-am-ez76 @1nerdyguy would a generic message help?

Yes, generic response would be ok

@1nerdyguy commented on GitHub (Aug 26, 2025): > [@i-am-ez76](https://github.com/i-am-ez76) [@1nerdyguy](https://github.com/1nerdyguy) would a generic message help? Yes, generic response would be ok
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SVI/netbird#2228