r/netbird

Netbird does NOT work on iOS

I don’t know if it’s just me, but I’ve been having trouble with Netbird disconnecting and asking me to connect over and over again. Even when I have session expiry disabled.

Often I only notice when my internet connection suddenly drops, and when I reconnect Netbird, most of the time I just have to click Connect, or disconnect and connect again. Doesn’t even prompt for a login. Just a - seemingly - pointless manual interaction prompt for clicking a button.

Is anyone else experiencing this? I keep searching, but see no other complaints. I even switched from selfhosted to their own server recently, thinking it would solve it. But hasn’t.

It works perfectly on all other clients. Including MacOS.

Am I missing some documented limitation here?

reddit.com
u/_ParanoidGoose_ — 3 days ago
▲ 14 r/netbird

How do I access my whole local network using a peer? Can't understand the docs

🤗 Solved (Thank you all guys for the help)

.................. I'm a totally noob, plz help me guys 😊

So here's what I wanna do. Access my whole network under my router through the windows pc (pc is the netbird routing peer)

I'm using netbird in the cloud. Installed Netbird in my Windows pc and added it as a Network routing peer.

Now I want something like this - I'll connect my router to that Windows pc via lan. Let's say its 192.168.1.0/24

My router got 192.168.1.1 and the windows pc got 192.168.1.2

My router doesn't got netbird installed inside it. I wanna access it via my Windows pc.

Now, when I'm gonna add a new network route - to access my local router, should I add the whole 192.168.1.0/24 subnet or I can just add the routers local ip 192.168.1.1

Everything going over my head 😭😭

u/Fardin_Shahriar — 4 days ago

Maintain Mullvad connection while using Netbird

Netbird desktop app will not say connected on macOS when mullvad is active. This may be a mullvad question but was wondering if there was a solution or adjustment I need to make in my self hosted netbird in docker instance.

What solution do others use when remote?

reddit.com
u/Jfishie5 — 5 days ago

Netbird Reverse Proxy

Hello does anyone uses Netbird Reverse Proxy for streaming using Jellyfin? I wonder how it performs and if there are any buffering issue when playing a movie or shows with decent bitrate. I am pretty new with Netbird so i have no idea how it works as I've only used Tailscale before. Thanks for the response looking forward on reading them all.

reddit.com
u/Jazper08 — 8 days ago
▲ 7 r/netbird+1 crossposts

Podman NetBird server quadlet?

Hi,

I'm trying to set up a NetBird quadlet, especially the server-variant where you host the things yourself and are not dependent on an external auth-service.

However, since I'm pretty new to containerization in general and quadlets, I have tried to ask Google AI for a quadlet-file (it worked pretty well to have a starting point for things like caddy, pihole, nextcloud and immich, so I gave it a try), but it's pretty useless for NetBird... it gave me many different answers and at some point just went in circles.

So I hoped that any of you already have a quadlet/container with NetBird server (and maybe even caddy instead of traefik) set up or can help me get this to work.

I don't have the quadlet-configs google gave me anymore tho since I wanted to start fresh.

reddit.com
u/green1t — 6 days ago

Self hosted Netbird on vps keeps making containers from the same images

I have this weird issue and I don´t know what to do.

When I used the installation script from Netbird on my Netcup vps it works great without issues but after a while (can be hours, sometimes days) it´ll make a load of containers of all the images I use on docker causing it to crash. It´ll also use around 150mbps of my bandwith.

I don´t know if I did something wrong but I (maybe stupidly) removed everything and didn´t look at the logs.

Did anybody encounter the same issue? Or maybe someone can help me?

I also tried out Pangolin but that had the same effect and tbh I like Netbird more.

Thanks

u/MaddDoggMendoza — 6 days ago

I tried netbird, but netbird wasn't enough

Positives:

  • Login by email+password
  • EU
  • Open source

Negatives:

  • No local only direct (no proxy) equivalent to tailscale serve
  • Dependence on proxying everything over netbird servers
  • Selfhosting a proxy would still incure double traffic
  • Device domain but no service domain (server2.netbird.cloud but no git.netbird.cloud)
reddit.com
u/Broccoli-Machine — 7 days ago

Trusted Network Detection

Does Netbird have the ability to not activate the tunnel when at home or other trusted locations? For example, with Wireguard, I have it configured today to automatically turn the tunnel on for all traffic when I leave my trusted WiFi networks. Soon as my home disconnects from any wifi or connects to any WiFi that's not my home SSIDs, it turns on. Turns off when I'm at home.

reddit.com
u/GreedyInformation171 — 7 days ago

Network just died?

I run netbird for my team. This morning I have been getting reports that no one can SSH to hosts that they could yesterday. I am testing also and I can SSH to like 7 of the 85 hosts that are online (and showing as online) all of them I could hit just yesterday.

Now I can sometimes hit 443 on the hosts then it dies, port 22 times out almost constantly. I don't have lazy connections on, they all show as available on the in the dashboard. I have rebooter hosts and the server, I just updated the server and I am seeing no issues in logs. Anyone have experience with this?

reddit.com
u/KingAroan — 9 days ago

Conceptual validation

Every time I look at Netbird there is something I like but getting it self-hosted is a complete different beast. I am not sure how many videos and documentation pages, github issues I have read - seems never to work.

I currently run Pangolin, on a VM in Proxmox on one of my vlans, expose services via its reverse proxy, open as well as authenticated via an idp.

I am thinking netbird should be able to do the same but all attempts fail.

Last 2 nights I have tried to getting it installed, ubuntu 24.04 as a base, the getting_started script does not complete - it claims "Waiting for NetBird server to become ready" but you can clearly see it just seems to hang, despite from not even downloading the proxy container or altering the proxy.env file as intended (using docker compose at a later stage to tear down and restart, pulls the container however) - so manual work is required but it seems the documentation may not be where development is, so it becomes a constant struggle and you need to find different bits across github issues, forum posts etc. Anyhow, it failed again 3 times, hence this post.

My idea:

management netbird.my-domain.com

proxy: my-domain.com (allowing wildcard use of proxy exposed services)

either dedicated routing peers (exit nodes) per vlans, I cannot seem to find a solution to allow the netbird server itself to host a routing peer, though again I dont see any issues with the idea, doing that for other similar solutions as well.

my proxmox sits behind a firewall that forwards 80/443/3478 to the VM just fine, I can access the managementUI after a few tweaks, even can register a peer but I am not sure if I am missing anything here from a conceptual perspective.

Pangolin hosts everything on a single VM, reverse proxy can literally act as a standalone, additional vpns are optional.

Could someone clarify if any of my ideas are flawed or confirm that conceptually this shouldn't cause any issues? and if it shouldn't maybe provide some pointers why it does?

thanks

reddit.com
u/_ezi0n_ — 7 days ago
▲ 18 r/netbird

Lowering battery usage on phones with data

Hello again!

Last week I asked about why netbird suddenly started to melt my Android's phone battery like butter in the Sahara sun. And because I really wanted to use Netbird, I dug into it. When I say "I", I mean Claude, because let's be honest, I'm no veteran programmer! But hold on, the findings (and results) are worth reading this page.

Original post: https://www.reddit.com/r/netbird/comments/1vffj0x/real_issue_with_battery_drain_on_android/

------------ LONG POST AHEAD ------------

DISCLAIMER: Claude was used to troubleshoot fast and efficiently. I don't have the time nor the knowledge to do all this myself, but I do have enough brain cells and push back to challenge every findings and carefully follow what's happening. If you think this voids everything below this disclaime, feel free to skip. This post was written by me entirely though, no AI summary!

DISCLAIMER 2: I am in no way trying to undermine or criticize Netbird here. I hope this will show as a post from a dedicated fan of the project more than a criticism. I really believe this is a great software and intend on using it for the foreseable future, and donate once my infra relies on it.

I'll try to give context and organize this post, feel free to jump wherever you want. TLDR at the end.

A little context

I used to be on Tailscale. Great service, 3 users, 1 server (NAS) to share with outside users. Really solid service with no more than 4-5% battery usage when I had big photo upload days.

Recently I decided to move away from NAS hosted services and build a real home server. I have now 2 machines (a mini pc and a SFF) that are supposed to host pletora of services for data soreignety purposes (I have TB of photos I took and I want to share, notes on creative ideas I want to write down, music I want to listen to without paying a subscription on top of buying the music itself :/).

Since I wanted to own more of my data and infra, I saw netbird as a good self hosted replacement of Tailscale. More users, I own the instance, and that's fantastic. So I set it up on a VPS (cause I don't like opening my ports) and starting to setup all the services. When I had issues, claude code helped read logs 100x faster than me, propose a fix and test it.

In the matter of a few weeks I had something I could start really testing in real life, and I switched off Tailscale to use Netbird full time. And that's when it went wrong.

My topology

In netbird, I had the following:

  • VPS
    • Netbird server with proxy container for external sharing
    • Authentik for Authentication (mesh only, not used for netbird itself)
  • NUC (netbird on host and as routing peer)
    • Treafik for internal redirections
    • Technitium for DNS
  • SFF server has 3 VMs with netbird in them)
    • 1 multimedia VM with GPU passthrough for Immich and the likes
    • 1 service VM for things like stirling pdf and others (as routing peer)
    • 1 for monitoring services
  • 1 subnet route that fed all my services on my Server VLAN through the available routing peers.

Maybe not the best, but I'm learning and it fit my needs so far :)

The issue

After investigating, the main culprit seems to be related to this lonely Github issue https://github.com/netbirdio/netbird/issues/5373 that mentions the fact that PersistentKeepalive is set to 25s for every connected tunnels.

What seemed to happen is that in order to use the DNS resolver on my NUC + being able to redirect trafic to immich, my phone was constantly connected to 3 or 4 tunnels (if we include the server that sometimes acted as a relay) which means that my phone radio, on data mode, was waking up to send a few bytes of data ever 25s for each service, not being able to fall asleep in between. Because the routing peers need to stay up all the time, this was just draining my battery by keeping my data flowing even when my phone was idle.

This is a main architectural difference with Tailscale and Wireguard in general (as stated in the issue above) that makes Netbird drain more battery. On wifi it's negligeable, but on data it's deadly. And Lazy Connection is one cure for it.

The solution & results

I changed my approach completely in the end. My goal was to drop as many live connections as possible, and only wake them up when a service is used. Claude helped a lot here, so here is a summary of what was done:

  • My Traefik container got Netbird as a sidecar container, becoming a peer on the mesh so that services get served at a peer address, not via a subnet router
  • My internal DNS moved from Technitium to the native Netbird system so that peers resolve DNS instead of querying my Technitium all the time (it only had to resolve on domain name after all, I'm not serving my peers with exit routes)
  • A policy allows users to access Traefik
    • Unidirectional. Traefik cannot initiate back toward phones
    • TCP 80/443 only so nothing else on that host is exposed over the mesh
    • It targets a peer group, not a resource. Granting a peer creates no routing relationship, so it doesn't pin a tunnel open and lazy connections can tear it down, unlike when it was a subnet resource
  • A posture check excluded Android (who has a hard time making P2P connections) from using the direct intranet to access my services, because otherwise it keeps a route up all the time, draining the battery.
  • Enabled Lazy Connections

The goal of achieving 0 active connections worked. The price is that some services can take some time to wake up and load. Some take 2-3s, some take a full reload of the app. For now this didn't bother me much but we'll see how it goes when other users join.

At the end, I tested it on 2 consecutive days and I had a consumpton of less than 1% when idling for many hours, and it grew once to 6% when I did a big batch of photo upload and viewing on Ente. I'm also running Dawarich full time uploading my location to the server on the fly while I was testing this and had a office day that day. So pretty solid results imo.

TL;DR

Reduce number of always connected peers, because each of them pings the other every 25s and your phone's radio doesn't like that:

  • If you use DNS on a netbird (routing) peer, it needs constant connection to resolve your domain name => move it to Netbird (if you can)
  • If you use routing peers => try to replace those with something else
  • Enable Lazy Connections and hope it doesn't slow you down too much, I think for a punctual usage it is fine.

PS: Netbird team, if you read this, maybe having the option to disable keepalive or to fine tune it would be great :) I'm sure not only self-hoster suffer from that.

PPS: Extra bonus for people afraid to move their DNS: Netbird actually supports wildcards, so I didn't have to create 25 entries ;)

u/Manwe66 — 9 days ago

Is it overkill to install this mainly for magic DNS type names?

I just want to refer to my computers on the network by a common name instead of ip addresses and not have to open anything up externally. Is that possible with Netbird? Is Netbird overkill for this?

This is mainly what I use tailscake for and I’m trying to move away from it

reddit.com
u/Worldly-Wind-1632 — 11 days ago
▲ 8 r/netbird+1 crossposts

Вопрос про Netbird.

Всем привет. Тут будет достаточно важный вопрос для меня. Работает ли self-hosted Netbird в России между клиентом и сервером, который находится в России?

Буду благодарен за фидбэк.

reddit.com
u/No-Fly-1847 — 10 days ago

Why do network resources not have port?

I am currently using netbird to manage access to my homelab network. I have a few services that I have deployed using coolify, which my family uses. However, I don't want to give them access to the coolify dashboard itself. Currently, I am doing this by using he reverse proxy and netbird only authentication and made it users can access the services but not the dashboard. However, it has been very annoying that when we create resources on the network, we cannot put in the port have to put the port in separately in the "Add Target" section of the reverse proxy. Why do I have to put in resource and port separately? With this, I need to take a look at 2 places to get the whole ip address + port combo.

No option to put in port

Is there any reason why port is not part of the resource? Am I missing something here? Would really appreciate if we can introduce this to netbird or if someone can educate my why this is the way it is.

P.S. I already had a setup previously where instead of using independent resources, I'd point all off my reverse proxy services into my network's nginx proxy manager just so that I don't have to put in ports manually and I can take a look at my services at a glance.

Edit : I should probably also explain that I am hosting everything on proxmox which by default hosts different services on different IP. I would understand if the above setup if I was using something like docker where different services have the same address but different port

reddit.com
u/ArgentSeven — 13 days ago
▲ 13 r/netbird

Anyone using NetBird in an industrial / OT setting?

Hi all,

I work in the energy sector in Germany and we're currently evaluating NetBird as a remote access layer for distributed sites. Typical setup: a handful of control and gateway devices per location, some industrial protocols, plus the usual on site IT. Today it's the classic jump host and site VPN approach, and we're looking for something less painful to operate.

Some things I'd like to hear real world experience on:

  1. Has anyone run this in actual production OT, not just a homelab or a dev team? Especially where downtime has real consequences.
  2. Stability on poor links. A lot of our sites are on mobile connections or behind CGNAT. Does relay fallback behave sensibly, and do peers recover cleanly after a link drops for a while?
  3. Headless peers on Linux that have to come back automatically after a power cycle, with nobody on site. Any surprises there?
  4. Are ACLs and posture checks granular enough for tight per site and per vendor segmentation? We need "this external party reaches exactly these devices at this one location" and nothing more.
  5. Self hosted vs. cloud in a regulated context. How much operational effort is self hosting realistically?

Compliance is a big factor for us. NIS2 applies, and depending on how things develop, KRITIS requirements may come on top. That means audit trails, crypto choices that line up with BSI TR-02102, documented access control, and being able to put something coherent in front of an auditor. Has anyone gone through an audit or a customer security review with NetBird in the stack?

And the honest question: mature enough for this, or still rough edges that would bite us in a 24/7 asset? I'd rather hear the annoying parts now than during commissioning.

Any war stories welcome, good or bad.

reddit.com
u/Tenosiey — 13 days ago