惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
量子位
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
U
Unit 42
IT之家
IT之家
F
Fortinet All Blogs
GbyAI
GbyAI
MongoDB | Blog
MongoDB | Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
大猫的无限游戏
大猫的无限游戏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The Register - Security
The Register - Security
NISL@THU
NISL@THU
Webroot Blog
Webroot Blog
A
Arctic Wolf
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
Recent Announcements
Recent Announcements
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Blog — PlanetScale
Blog — PlanetScale
L
LangChain Blog
P
Palo Alto Networks Blog
Y
Y Combinator Blog
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AWS News Blog
AWS News Blog
有赞技术团队
有赞技术团队
Engineering at Meta
Engineering at Meta
C
Cybersecurity and Infrastructure Security Agency CISA
aimingoo的专栏
aimingoo的专栏
Know Your Adversary
Know Your Adversary
Cyberwarzone
Cyberwarzone
Martin Fowler
Martin Fowler
The Hacker News
The Hacker News
P
Privacy International News Feed
T
Threat Research - Cisco Blogs
G
GRAHAM CLULEY
宝玉的分享
宝玉的分享
博客园 - 聂微东
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The GitHub Blog
The GitHub Blog
S
Securelist
T
The Exploit Database - CXSecurity.com
T
Threatpost
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
F
Full Disclosure

NetBird - Networking Knowledge Hub - RSS Feed

NetBird Is Now on the Vultr Marketplace Native NetBird on the GL.iNet Comet Pro (GL-RM10) NetBird v0.71 - IPv6 Overlay Addressing NetBird Exit Nodes - Appear at Home, or Anywhere Else Reporting Bugs and Requesting Features in NetBird Setup and Use Local AdGuard Home Anywhere with NetBird DNS How to Set Up NetBird on PiKVM for Secure Remote KVM Access NetBird v0.69 - CrowdSec IP Reputation for the Reverse Proxy Cloudflare Mesh vs NetBird vs Tailscale: Performance Compared Self-Hosting Nextcloud with Docker and NetBird Implementing Zero Trust with NetBird NetBird v0.67 - Layer 4 Proxy Support for TCP, UDP, and TLS Solwr Enhances Remote Connectivity with NetBird Self-Hosting NetBird with Authentik Jellyfin Media Server - Self-Host Your Movies, TV, and Music Cloudflare Tunnels vs. NetBird Reverse Proxy INFITX Builds Zero-Touch Kubernetes Networking with NetBird NetBird v0.66 - Expose Local Services to the Internet from the CLI Pangolin vs. NetBird Home Assistant Setup Guide with EASY Remote Access Docker for Beginners - Everything You Need to Get Started NetBird for SOC 2 Compliance NetBird v0.63 - Custom DNS Zones for Private Network Resolution Vibecode This in a Weekend and Take 5% of the Company NetBird v0.62 - Built-in Local Users with Optional IdP Integration NetBird v0.61.0 - Granular SSH Access Control and Automatic Updates Top 5 Alternatives to OpenVPN Top 5 Open Source Alternatives to Tailscale Top 5 Alternatives to ZeroTier How to Set Up ZeroByte and REST Server for Backups with NetBird How to Install n8n v2.0 with NPM and PM2 ZeroTier vs. NetBird The Ultimate Immich Guide - Ditch Google and Amazon Photos for Good NetBird as Your Help with ISO 27001 Compliance NetBird and Huntress - Secure Network Access for MSPs How to Access Windows Shares from Anywhere with NetBird netgo Relies on Modern ZTNA with NetBird Connect to Your Homelab from Anywhere with a Raspberry Pi NetBird SSH - A New, Identity-Aware Approach The AI Mega Mesh: How to Connect 30+ GPU Cloud Providers Connect Multiple Ollama GPUs to OpenWebUI with NetBird Top 5 Tailscale Alternatives SSH and RDP, now in your browser NetBird–Acronis Integration: Empowering MSPs for Advanced Ransomware and Threat Defense Introducing the Control Center - Remote Access, Beautifully Visualized NetBird at MSP Global 2025 Understanding Overlay Networks - The Basics NetBird and SentinelOne Singularity™ - Automate Threat Response NetBird and Microsoft Intune - Enforcing Device Compliance for Zero Trust Rethinking Zero Trust Security with NetBird and pfSense Improving Unidirectional Access Control Proxmox VE for Beginners Guide with NetBird LXC Stronger Security: NetBird + GitHub Secure Open Source Fund NetBird's MSP Partner Program Signicat Enhances Cross-Cloud Accessibility with NetBird SonicWall SSL VPN NetExtender vs. NetBird NetBird Is Embracing the AGPLv3 License NetBird Profiles Have Landed - Manage Multiple Accounts Effortlessly Rethinking Access Control to Secure Your On-Premises SharePoint Servers Sport Alliance Increases Efficiency with Zero Trust Networking at Scale Rethinking Network Access: qwertiko Goes Zero Trust with NetBird Optimizing Network Efficiency with NetBird's Lazy Connections Use Port Ranges in Access Control Policies Generic HTTP Endpoint for Network Events Streaming NetBird’s Response to Spear-Phishing Campaign Targeting Financial Executives Zero-Trust Access to Internal Resources Without Installing Agents Enhance Network Visibility with NetBird’s Traffic Events Logging TrueNAS Made Easy - Install, Set Up, and Access From Anywhere Top 5 Alternatives for WireGuard Jump Hosts. Gateways for Remote Access NetBird Network Routes and Exit Nodes Security for All - SSO and MFA for Free Enhancing Network Access Control with NetBird's Identity Provider Feature Twingate vs. NetBird Limit Network Access Based on Running Applications FortiClient ZTNA vs. NetBird OpenVPN vs. NetBird Tailscale vs. NetBird Getting Started with an Azure Site-to-Site VPN Getting Started with an On-premise-to-AWS Site-to-Site VPN Secure Remote Access to VPCs, LANs, and Offices regreSSHion - A New OpenSSH Server Remote Code Execution Vulnerability Evolve Bank & Trust Data Breach. What Happened? What Is a Site-to-Site VPN? IPSec Tunneling Demystified. Enhancing Data Security Across Networks Understanding IPSec Tunnel and Transport Modes Understanding the Differences Between IKEv1 and IKEv2 Understanding the IKEv1 Protocol in IPSec ZeroTier versus NetBird - Which Should You Choose? AWS Lambda Serverless Security. Mistakes, Oversights, and Potential Vulnerabilities Using NetBird for Kubernetes Access Serverless Security Vulnerabilities and Best Practices to Mitigate Them Security Best Practices for Serverless Azure Functions A Guide to Remote Access Security for SMEs IoT Security Essentials. How to Achieve Secure Remote Access Open Source Zero Trust Networking Using SSH for Secure Remote Access How We Integrated Rosenpass in NetBird The First Quantum-Resistant Mesh VPN Using eBPF and XDP to Share Default DNS Port Between Multiple Resolvers
NetBird v0.65 - Built-in Reverse Proxy with Custom Domains
Written byBrandon Hopkins · 2026-02-18 · via NetBird - Networking Knowledge Hub - RSS Feed

If you're self-hosting anything right now, you've probably dealt with the headache of making your services accessible from outside your network. Port forwarding, reverse proxy configs, Cloudflare Tunnels. It works, but it comes with trade-offs. Either you're managing TLS certificates and security hardening yourself, or you're handing your traffic to a third party.

With NetBird v0.65, that's no longer the trade-off. We've built a reverse proxy directly into the management server. Point a custom domain at your NetBird server, configure the proxy in the dashboard, and your internal services are securely accessible from any browser. No VPN client required for end users. TLS, authentication, and routing are all handled by NetBird through encrypted WireGuard tunnels, fully self-hosted and fully under your control.

Why Not Just Use Cloudflare Tunnels?

Cloudflare Tunnels is free, easy to set up, and popular for good reason. But there's a fundamental trade-off most people overlook: all of your traffic flows through Cloudflare's infrastructure. They're terminating your TLS. They can see your traffic. That's a man-in-the-middle by design.

On top of that, Cloudflare's free plan has data transfer limits that make it a non-starter for media streaming or large file transfers. Services like Plex, Jellyfin, or Nextcloud can hit those limits fast. With a self-hosted NetBird deployment, there are no bandwidth restrictions beyond what your own infrastructure can handle. You own the proxy, you own the limits.

You also get something Cloudflare doesn't offer: built-in authentication at the proxy layer. SSO through your existing identity provider, shared passwords, PIN codes, or a combination of all three. No extra services to bolt on, no additional configuration.

Add a Service

Expose any internal service by selecting a subdomain and adding one or more backend targets. Each target points to a peer or resource on your network.

Add a reverse proxy service

From the Reverse Proxy section in the dashboard, click Add Service and configure the subdomain and target. You can add multiple targets to a single service and use path-based routing to send different URL paths to different backend services. For example, to your web app, to a separate backend, and to a documentation server, all under a single domain.

Add a target

Custom Domains

Bring your own domain by adding a CNAME record pointing to your NetBird proxy cluster. NetBird handles TLS certificate provisioning automatically.

Add a custom domain

To add a custom domain:

  1. Navigate to Reverse ProxyCustom Domains
  2. Click Add Domain
  3. Enter your domain name
  4. Add a CNAME record at your DNS provider pointing to your NetBird proxy
  5. NetBird validates the CNAME and provisions a TLS certificate automatically

Learn more in the Custom Domains documentation .

Authentication

Secure your exposed services with multiple authentication methods. Enable one or combine several for layered protection.

Authentication settings

  • SSO - Authenticate users through your configured identity provider. Optionally restrict access to specific user groups, so your dev team sees dev tools and your sales team sees their dashboards.
  • Password - Set a shared password for simple access to internal tools or for external collaborators who aren't in your IdP.
  • PIN Code - Protect services with a numeric PIN for quick, lightweight access control.
  • No authentication - Expose services publicly when needed (use with caution).

You can combine methods on the same service. For example, enable both SSO and a shared password so team members authenticate with SSO while external partners use the password. Sessions are managed using JWT tokens, so users authenticate once and stay connected without repeated prompts.

Learn more in the Authentication documentation .

Settings

Each service has additional options for controlling how the proxy handles requests.

Proxy settings

  • Host header passthrough - Forward the original Host header to your backend instead of the internal hostname. This is important for services that rely on the Host header for routing, virtual hosting, or WebAuthn validation.
  • Redirect rewriting - Rewrite redirect URLs in backend responses to use the public domain, preventing users from being sent to internal addresses they can't reach.

Self-Hosted Improvements

Version 0.65 also introduces a unified NetBird server binary that consolidates multiple services into a single container for self-hosted deployments. This means fewer containers to manage, simpler Docker Compose stacks, and faster setup. If you're running an existing deployment, the quick start script has been updated and we've published a migration guide to walk you through enabling the reverse proxy on your current installation.

We've also switched the default reverse proxy in the quick start script from Caddy to Traefik. Traefik is required for the reverse proxy feature because it supports TLS passthrough, which lets the NetBird proxy handle TLS termination directly.

Cloud Support Coming Soon

The reverse proxy is currently available for self-hosted deployments only. Cloud support with hosted reverse proxy nodes is on the way and should be available within the next couple of weeks. Follow us on X or join our Slack to get notified when it's ready.

Other Improvements

This release also includes enforced access control on the accessible peers endpoint, a cloud API spec added to the public OpenAPI definition, an early message buffer for the relay client to prevent message loss during connection establishment, and a refactored relay connection container for improved reliability. Full details are in the GitHub release notes .

Get Started

Join the community: