mirror of
https://github.com/netbirdio/netbird.git
synced 2026-07-24 15:03:59 -04:00
Windows DNS isues on AD DC and AD joined Windows machines #383
Open
opened 2025-11-20 05:10:34 -05:00 by saavagebueno
·
23 comments
No Branch/Tag Specified
main
reverse-proxy-allow-match-or
components-impl-drop-indexes-use-xids-no-resource-policy-map
fix-pgx-service-column-parity
grpc-acl
revert/component-types
fix/nmap-relevant-groups
claude/model-cost-calculation-bug-9hic1n
agent-network-per-policy-model-allowlist
fix/ios-common-tunnel-notifier
fix/ui-windows-endsession-shutdown
force-routing-peer-dns-reverse-proxy
dependabot/go_modules/aws-sdk-8f849ebaed
dependabot/github_actions/actions-a940c7c866
dependabot/go_modules/otel-e34c790afd
dependabot/go_modules/gorm-2271c8195b
dependabot/go_modules/pion-5f703e1eca
dependabot/go_modules/testcontainers-de325c0dd6
dependabot/go_modules/wireguard-dbd6b95108
e2e-guardrail-blocks-unselected-model
fix/lazyconn-cold-start-allowed-ips
vertex-guardrails-model-access-e2e
add-atomic-cache-ops
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.106.0
refactor/relay-foreign-cache
ci/trigger-release-tests
claude/netbird-pr-6767-comments-c0qkci
feature/kimi-3-agent-networks-dns-warmup
feature/dns-lazy-conn-warmup
daemon-ipc-acl
feature/ui-translation-key-parity-check
refactor/relay-foreign-cache-tests
claude/kimi-3-agent-networks-3rpqnv
fix/remove-math-rand
fix/lazyconn-idle-keep-wg-peer
dmitri-propagate-auth-grant-types-on-combined
0.74.7-branch
diagnose-empty-vs-corrupt-state
windows-sleep-detector
fix/cli-up-wait-for-daemon
lazy-conn-rosenpass
lazy-conn-per-peer
rp_key_persistency
fix/routes_not_updated
feature/native-grpc
client-local-metrics
fix-ssh-authorized-users-multi-rule
0.74.6-branch
0.74.6-branch-sync
0.74.5-branch-sync
0.74.4-branch
fix/remove-stale-peers-removal
fix/remove-stale-proxy-logic
embedded-vnc
fix/nsis-preserve-autostart-on-upgrade
refactor/peer-event-bus
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3
dependabot/go_modules/github.com/pkg/sftp-1.13.10
components-impl-drop-indexes
fix-reset-aggregation-window-flake
dependabot/go_modules/github.com/pion/dtls/v3-3.1.5
peer-acl-multi-source
0.74.x
fix/relay-states-lock
update-process-pkg
update-gopsutil-v4
fix/relay_states_lock
increase-sysinfo-timeout
dependabot/npm_and_yarn/client/ui/frontend/npm_and_yarn-88714b13d0
dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
dependabot/go_modules/github.com/eko/gocache/store/redis/v4-4.2.6
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.3
fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
0.74.3-branch
fix/routeselector-atomic-exit-node
netmap_progressive_alignment
nmap/components-impl
dependabot/go_modules/github.com/jackc/pgx/v5-5.9.2
dependabot/go_modules/github.com/oapi-codegen/runtime-1.4.2
dependabot/go_modules/github.com/gopacket/gopacket-1.6.1
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0
dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0
fix/signal-watchdog-sync-stop
docs/agent-network
feature/ios-ssh
test/affected-logic
fix/revert-ice-filter
refactor/simplify-affected-peers
pascal-filter-policies-by-direction
claude/lock-contention-peer-connect-g8t6au
dmitri-filter-policies-by-direction
refactor/migrate-profiles-to-go
profile-bindings-ios
fix/skip-restart-unchanged-route
fix/mgmt-cache-async-resolve
refactor/wails-update-105
client_lifetime_serialization_refactor
fix/browser-ssh-2
fix/ipv6-and-netstack-accept-loop
fix/browser-ssh
profile-id-name-test
refactor/mgmt-bootstrap
mdm_integration
feat/getting-started-unified-wizard
socket-grpc-permissions
fix/mysql-index-migration
windows-dns-firewall
tests/enable-race-on-tests
ui-refactor-gtk3
feature/affected-peers-grpc
profile-id
lazyconn-first-packet-fix-v2
claude/focused-gates-VMTgb
ui-tray-linux-leftclick
fix/ctx-enrichment
daemon-owner
feature/android-client-ssh
worktree-accept-ra-forwarding
nmap/combined-deploy
task/align_protobuff_toolset
feature/session-extend
add-json-yaml-flags
refactor/ephemeral-cleanup
claude/webtransport-relay-wasm-mUjY9
claude/vnc-udp-feasibility-6KB1U
fix/wgport-config
e2e-windows-dns-combined
fix/login-cmd-root-flags
feat/reseller-openapi-spec
github-issue-resolver
add-steamos-support
fix-darwin-uninstaller
flutter-test
ci/freebsd-pkg-bootstrap
cached-serial-check-on-sync
fix-mgmt-cache-bypass-overlay
revert-easyjson-5938
revert-ice-5820
revert-firewalld-5928
refactor/permissions-manager
revert-dns-5935-systemd-resolved
revert-dns-5935-5945
revert-dns-5945-mgmt-cache
feature/log-most-busy-peers
prototype/ui-wails
coderabbitai/utg/8ae8f20
feature/use-peer-fqdn-on-https
release/0.68.3
add-slack-channel
claude/rdp-token-passthrough-eNcqW
transparent-proxy
fix/macos-stale-route-eexist
crowdsec-selfhosted
fix/remove-otel-units
entire/checkpoints/v1
fix/getting-started
feat/static-connectors-combined-server
feature/use-local-keys-embedded
feature/fleetdm
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
feature/changeset
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.75.0
v0.74.7
v0.74.6
v0.74.5
v0.75.0-rc.6
v0.74.4
v0.74.3
v0.75.0-rc.5
v0.74.2
v0.74.1
v0.75.0-rc.4
v0.74.0
v0.74.0-rc.2
v0.74.0-rc.1
v0.73.2
v0.75.0-rc.3
v0.75.0-rc.2
v0.73.1
v0.75.0-rc.1
v0.73.0
v0.72.4
v0.72.3
v0.72.2
v0.72.1
v0.72.0
v0.71.4
v0.71.3
v0.71.2
v0.71.1
v0.71.0
v0.70.5
v0.70.4
v0.70.3
v0.70.2
v0.70.1
v0.70.0
v0.69.0
v0.68.3
v0.68.2
v0.68.1
v0.68.0
v0.67.4
v0.67.3
v0.67.2
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2022 Q1
2022 Q1
accessibility
acl
agent
agent
Android
Android
api
authentik
automation
azure
battery-usage
bug
cache
client
client-ui
cloud
cloud-only
cloudflare
community
compatibility
config-idp
config-issue
connection
contribution
coturn
cross-vpn
dashboard
data-usage
distribution
dns
docker
documentation
duplicate
enhancement
enhancement
event-stream
feature-request
freebsd
getting-started
go
good first issue
gui
help wanted
home-assistant
idp
inconsistency
integration
integrations
ios
ipv6
jwt
k8s
keycloak
linux
login
macos
management-service
missing-docs
mobile
moved-internal
needs-review
netbird-ui
networking
new-platform
nginx
notification
okta
openwrt
packaging
peer-management
peer-management
peer-management
performance
postgres
posture-checks
psk
pull-request
question
refactor
relay
release
rfc
routes
security
security-related
self-hosting
server
signal
sleep-issue
ssh
ssl
status
store
synology
system-compatibility-issue
test-suite
third-party-integration
triage
triage-needed
troubleshooting
UX
waiting-feedback
windows
wontfix
zitadel
Mirrored from GitHub Pull Request
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
saavagebueno
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: SVI/netbird#383
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @bbaumgartl on GitHub (Jun 26, 2023).
It seems like that the netbird search domain is ignored on a Windows Server Active Directory Domain Controller.
After connecting netbird the log states that the search domain was added:
But it does not show up in
ipconfig /allunderDNS Suffix Search ListorConnection-specific DNS Suffix:And DNS queries with only the hostname fail:
Using the FQDN does work though:
@bbaumgartl commented on GitHub (Jun 27, 2023):
I tried the same configuration on an AD joined Windows 10 machine. DNS resolution for netbird works, but the local AD domain doesn't resolve anymore. It looks like netbird changes the DNS configuration (in the adapter properties) from
Append primary and connection specific DNS suffixestoAppend these DNS suffixes (in order)(like it is described here https://answers.uillinois.edu/illinois/page.php?id=114224). This somehow means that Windows is only using the suffixes from this list and on a Windows AD DC this seems to have no effect at all (after changing the setting manually while testing it somehow worked but reconnecting netbird broke it again).I tried two different manual dns configurations with netbird connected:
Append primary and connection specific DNS suffixesand settingDNS suffix for this connectionon thewt0adapter tonetbird.cloud. This appendsnetbird.cloudto theDNS Suffix Search Listinipconfig /all.domain.localtoAppend these DNS suffixes (in order)after netbird addednetbird.cloudto the list.Both seem to work (local AD domain and netbird domain are added to the search list and can be resolved) on the Windows AD DC and Windows 10 machine. Maybe one could be a possible solution?
@bbaumgartl commented on GitHub (Jul 4, 2023):
Another thing i noticed is that connecting netbird registers the netbird IP address in the local DNS server. This causes local network clients to sometimes get the netbird IP instead of the local IP and thus can't connect to the server. There is an option in the adapter properties (
Register this connection's addresses in DNS) which should avoid this. Maybe this is something that can be set after the adapter is created?@MobileManiC commented on GitHub (Oct 9, 2023):
Yes, waiting for that fix as well... This makes NetBird effectively unusable in AD environment, because short names are usually heavily utilized in avarage business usecases (seems that even some Win10/11 domain communication itself expects AD servers to be accessible by their short name).
@MobileManiC commented on GitHub (Oct 9, 2023):
Btw. I think the solution 1. (
"Append primary and connection specific DNS suffixes") is proper one@hesshaus commented on GitHub (May 3, 2024):
Can confirm this is an issue in AD environments. The suggestions above did fix these issues, however, they are temporary (upon reboot or restarting the netbird client). Would love to roll this solution out but this is a major hurdle.
@MobileManiC commented on GitHub (May 4, 2024):
I think this is already resolved for a long time. Have you tried to install current version and configure DNS properly on the server side?
@bbaumgartl commented on GitHub (May 10, 2024):
I just briefly checked it and it seems that the first two points (windows server netbird dns resolution, ad joined windows machine local dns resolution) seem to work now.
The third point (netbird ip is registered in the local domain as ip address) seems to be still an issue.
@florian-obradovic commented on GitHub (Oct 12, 2024):
"The third point (netbird ip is registered in the local domain as ip address) seems to be still an issue."
This is standard behaviour for windows: https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/enable-disable-dns-dynamic-registration
"Windows supports Domain Name System (DNS) updates per RFC 2136. By default, this behavior is enabled for Windows DNS clients."
You could disable this via GPO:

Computer Configuration > Administrative Templates > Network > DNS Client > Dynamic Update
Set it to disabled:
@florian-obradovic commented on GitHub (Oct 12, 2024):
I came across this issue and have the same issue on all AD joined machines (Windows 10/11, Server OS).
All Netbird specific DNS settings are ignored on AD joined or Entra-ID hybrid joined machines. WORKGROUP or Entra-ID only joined machines work fine.
Looks like the NRPT Rules are ignored:

Get-DnsClientNrptRulethe default dns search domain, in my case onetpg (Example: server01.onetpg) isn't working
Added nameservers like this:

nslookup or Resolve-DnsName work if you specify the Netbird default DNS IP:

It works on machines without domain join:

@florian-obradovic commented on GitHub (Oct 12, 2024):
I found some hints in a Tailscale issue.
The Nrpt-Rule Netbird creates, is ignored if this key exists which is the default in every Active Directory domain, even without any DNS client specific GPOs applied (I tested it...)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfigFrom the documentation:
"<4> Section 2.2.2.1: The Name key specification is Software\Policies\Microsoft\WindowsNT\DNSClient\DnsPolicyConfig{Name}.
In the presence of both specified keys, Windows ignores the System\CurrentControlSet\services\Dnscache\Parameters key."
So, the NrptRule is ignored:

(Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\DnsPolicyConfig\NetBird-Match)
Steps to test:
Restart-Service Netbirdor reboot the machinePossible solution
Creating DNS Client NRPT Rule like this doesn't work ❌:
I think we need a DnsClientNrptPolicy I think but I'm unsure how to create them correctly... there is no Add-DnsClientNrptPolicy commandlet
I created registry key manually and it works :)
My Nebird domain suffix is onetpg (Example: server01.onetpg so it's:
_Name=hex(7):2e,00,6f,00,6e,00,65,00,74,00,70,00,67,00,00,00,00,00 = **.onetpg**_GPO - Group Policy

Proposed fix
@mlsmaycon:
4d0d4e0b69 (diff-f0aeef11af128394e1c4468f5139e97885e2078b620b94640e7a1030721bddc8R21)4d0d4e0b69 (diff-a3c40a24112fd7205c9cf7de4f44d040b2e7f50db1496f778c09931df7a425e1R41)Infos
In the presence of both specified keys, Windows ignores the System\CurrentControlSet\services\Dnscache\Parameters key."
4d0d4e0b69@florian-obradovic commented on GitHub (Oct 29, 2024):
@mlsmaycon did you have a chance to look at this?
I bet this could block a rollout for many corps with Windows environments.
@the-project-group commented on GitHub (Jan 5, 2025):
I just spent a few hours with this topic.
Currently on 0.35.2 and Windows 11 24h2 december 2024 update.
@mlsmaycon: did something change here since my last post?
If I remember correctly, there where no NRPT policies (Get-DnsClientNrptPolicy), only NRTP rules (Get-DnsClientNrptRule) which were ignored if the reg-key mentioned above is present! Now I have both!
I think there is something broken:
The NRTP policies & rule created by the Netbird client don't match the name servers settings configured in the dashboard.
Example:
As you can see, all NRPT policies have 100.116.255.254 as DNS server and not the configured DNS server .177.244
It's normal for the Netbird Domain / default match domain like selfhosted.
@lixmal commented on GitHub (Jan 5, 2025):
100.116.255.254is correct. It's netbird's fake dns IP, the configured dns servers will be set as upstream internally. Seenetbird status -d@florian-obradovic commented on GitHub (Jan 5, 2025):
Thanks @lixmal !
@jackmusick commented on GitHub (Jan 22, 2025):
Bumping this, though I'm still experimenting. I've tried a lot of these suggestions. Basically what I'm experiencing is that I can't ping by name once joined to the domain. Is there a recommended setup here to avoid setting up a routing peer, or is this still an issue?
@the-project-group commented on GitHub (Jan 23, 2025):
The only "work-around" I tried and had "some kind of name resolution" working was by defining the same DNS server twice:
@lixmal commented on GitHub (Feb 13, 2025):
Hey folks, can you please try with
v0.36.7and if any issues remain get the logs plus the following in powershell when netbird is running:Feel free to mask sensitive info.
thanks for the research @florian-obradovic
@flotpg commented on GitHub (Feb 13, 2025):
@lixmal awesome work ❤️❤️❤️
Unfortunately it's not yet working for me:
MS Edge:

From a domain / hybrid joined machine:
On another machine which is not domain joined, it doesn't set the policy but a rule < is this intended?
@jbford1919 commented on GitHub (Feb 19, 2025):
I'm using Netbird to connect domain joined windows PC to our domain controllers through a routing peer with success. The latest version works for me as long as I have a namserver group that as "ALL" domains captured. Previously I just had one nameserver group that matched our local domain but DNS to local domain stopped working. However, after adding a second nameserver group to capture ALL domains the issue was resolved. Now my domain joined windows PC work as expected resolving DNS.
To be clear, I don't have netbird on my DC's. I use routing peer and have DC's listed as resources in Networks.
@saule1508 commented on GitHub (Feb 24, 2025):
Not working for me and my colleagues, it is broken since 0.36.7
https://github.com/netbirdio/netbird/issues/3332
PS C:\Windows\System32\WindowsPowerShell\v1.0> ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : WL-BFVVDL3
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : elisa.net
fr01.awl.mycorporate.net
deac.awl.mycorporate.net
wl.corp-group.net
Ethernet adapter Ethernet:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) Ethernet Connection (13) I219-LM
Physical Address. . . . . . . . . : 00-BE-43-21-ED-ED
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Ethernet adapter Ethernet 8:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek USB GbE Family Controller #2
Physical Address. . . . . . . . . : 00-BE-43-21-ED-EE
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Unknown adapter wt0:
Connection-specific DNS Suffix . : netbird.giservices
Description . . . . . . . . . . . : WireGuard Tunnel
Physical Address. . . . . . . . . :
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 100.67.175.125(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . :
NetBIOS over Tcpip. . . . . . . . : Enabled
Connection-specific DNS Suffix Search List :
netbird.giservices
Wireless LAN adapter Local Area Connection* 1:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
Physical Address. . . . . . . . . : F0-57-A6-7C-54-67
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Wireless LAN adapter Local Area Connection* 2:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter #2
Physical Address. . . . . . . . . : F2-57-A6-7C-54-66
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Ethernet adapter Ethernet 2:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Fortinet Virtual Ethernet Adapter (NDIS 6.30)
Physical Address. . . . . . . . . : 00-09-0F-FE-00-01
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Wireless LAN adapter Wi-Fi:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) Wi-Fi 6 AX201 160MHz
Physical Address. . . . . . . . . : F0-57-A6-7C-54-66
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::b2e5:c493:5d45:af3a%20(Preferred)
IPv4 Address. . . . . . . . . . . : 10.171.81.29(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Tuesday, 25 February 2025 09:23:57
Lease Expires . . . . . . . . . . : Wednesday, 26 February 2025 09:23:57
Default Gateway . . . . . . . . . : 10.171.81.1
DHCP Server . . . . . . . . . . . : 10.171.81.1
DHCPv6 IAID . . . . . . . . . . . : 133191590
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-29-A0-72-A9-00-BE-43-21-ED-ED
DNS Servers . . . . . . . . . . . : 10.173.173.173
NetBIOS over Tcpip. . . . . . . . : Enabled
Ethernet adapter Bluetooth Network Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network)
Physical Address. . . . . . . . . : F0-57-A6-7C-54-6A
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
PS C:\Windows\System32\WindowsPowerShell\v1.0> Get-DnsClientGlobalSetting
UseSuffixSearchList : True
SuffixSearchList : {elisa.net, fr01.xxx.mycorporate.net, deac.xxx.mycorporate.net, xx.xxx.net}
UseDevolution : True
DevolutionLevel : 0
PS C:\Windows\System32\WindowsPowerShell\v1.0> Get-DnsClientNrptGlobal
EnableDAForAllNetworks QueryPolicy SecureNameQueryFallback
Disable Disable Disable
PS C:\Windows\System32\WindowsPowerShell\v1.0> Get-DnsClientNrptRule
PS C:\Windows\System32\WindowsPowerShell\v1.0> Get-DnsClientNrptPolicy
PS C:\Windows\System32\WindowsPowerShell\v1.0> Get-ChildItem -Path "HKLM:\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\DnsPolicyConfig"
PS C:\Windows\System32\WindowsPowerShell\v1.0> Get-ChildItem -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig"
Name Property
NetBird-Match Version : 2
Name : {.corp.net, .corporarw.com, .nyservices.io, .netbird.giservices}
GenericDNSServers : 100.67.255.254
ConfigOptions : 8
@tobiasplagge commented on GitHub (Jul 19, 2025):
Can you tell me how you solved the problem?
My DCs are accessible via a routing peer.
DNS is actually running fine, but domain availability is not there.
However, domain join does not allow user login.
For some reason my DNS is being routed incorrectly.
In order for it to work at all, I had to manually make DNS entries in the main network card.
What approach should actually work?
Thank you.
@al-dubois commented on GitHub (Sep 23, 2025):
Any luck on your side since July 19th ? @tobiasplagge
@flotpg commented on GitHub (Oct 28, 2025):
Today I tried it on a Windows 11 25H2 machine (which is only Entra ID joined, no local onprem AD join) and suddenly it's also broken there as well.
I only get DNS if I set the DNS server to match ALL domains but I don't want to push every DNS query through the tunnel.
@lixmal / @mlsmaycon do you want a debugging session?