惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Palo Alto Networks Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
C
CERT Recently Published Vulnerability Notes
C
Cybersecurity and Infrastructure Security Agency CISA
S
Schneier on Security
S
Securelist
酷 壳 – CoolShell
酷 壳 – CoolShell
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cyberwarzone
Cyberwarzone
Apple Machine Learning Research
Apple Machine Learning Research
S
SegmentFault 最新的问题
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
GbyAI
GbyAI
Security Latest
Security Latest
Last Week in AI
Last Week in AI
Microsoft Security Blog
Microsoft Security Blog
云风的 BLOG
云风的 BLOG
Recorded Future
Recorded Future
Webroot Blog
Webroot Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
TaoSecurity Blog
TaoSecurity Blog
C
Cisco Blogs
博客园 - 【当耐特】
Blog — PlanetScale
Blog — PlanetScale
Hugging Face - Blog
Hugging Face - Blog
B
Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Attack and Defense Labs
Attack and Defense Labs
The Last Watchdog
The Last Watchdog
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
Project Zero
Project Zero
WordPress大学
WordPress大学
L
LINUX DO - 最新话题
F
Fortinet All Blogs
L
LINUX DO - 热门话题
PCI Perspectives
PCI Perspectives
Simon Willison's Weblog
Simon Willison's Weblog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
MongoDB | Blog
MongoDB | Blog
Latest news
Latest news
P
Proofpoint News Feed
T
Threat Research - Cisco Blogs
The Hacker News
The Hacker News
爱范儿
爱范儿
O
OpenAI News
J
Java Code Geeks
T
The Exploit Database - CXSecurity.com
H
Hackread – Cybersecurity News, Data Breaches, AI and More

NetBird - Networking Knowledge Hub - RSS Feed

NetBird Is Now on the Vultr Marketplace Native NetBird on the GL.iNet Comet Pro (GL-RM10) NetBird v0.71 - IPv6 Overlay Addressing NetBird Exit Nodes - Appear at Home, or Anywhere Else Reporting Bugs and Requesting Features in NetBird Setup and Use Local AdGuard Home Anywhere with NetBird DNS How to Set Up NetBird on PiKVM for Secure Remote KVM Access NetBird v0.69 - CrowdSec IP Reputation for the Reverse Proxy Cloudflare Mesh vs NetBird vs Tailscale: Performance Compared Self-Hosting Nextcloud with Docker and NetBird Implementing Zero Trust with NetBird NetBird v0.67 - Layer 4 Proxy Support for TCP, UDP, and TLS Solwr Enhances Remote Connectivity with NetBird Self-Hosting NetBird with Authentik Jellyfin Media Server - Self-Host Your Movies, TV, and Music Cloudflare Tunnels vs. NetBird Reverse Proxy INFITX Builds Zero-Touch Kubernetes Networking with NetBird NetBird v0.66 - Expose Local Services to the Internet from the CLI Pangolin vs. NetBird Home Assistant Setup Guide with EASY Remote Access NetBird v0.65 - Built-in Reverse Proxy with Custom Domains Docker for Beginners - Everything You Need to Get Started NetBird for SOC 2 Compliance NetBird v0.63 - Custom DNS Zones for Private Network Resolution Vibecode This in a Weekend and Take 5% of the Company NetBird v0.62 - Built-in Local Users with Optional IdP Integration NetBird v0.61.0 - Granular SSH Access Control and Automatic Updates Top 5 Alternatives to OpenVPN Top 5 Open Source Alternatives to Tailscale Top 5 Alternatives to ZeroTier How to Set Up ZeroByte and REST Server for Backups with NetBird How to Install n8n v2.0 with NPM and PM2 ZeroTier vs. NetBird The Ultimate Immich Guide - Ditch Google and Amazon Photos for Good NetBird as Your Help with ISO 27001 Compliance NetBird and Huntress - Secure Network Access for MSPs How to Access Windows Shares from Anywhere with NetBird netgo Relies on Modern ZTNA with NetBird Connect to Your Homelab from Anywhere with a Raspberry Pi NetBird SSH - A New, Identity-Aware Approach The AI Mega Mesh: How to Connect 30+ GPU Cloud Providers Connect Multiple Ollama GPUs to OpenWebUI with NetBird Top 5 Tailscale Alternatives SSH and RDP, now in your browser NetBird–Acronis Integration: Empowering MSPs for Advanced Ransomware and Threat Defense Introducing the Control Center - Remote Access, Beautifully Visualized NetBird at MSP Global 2025 Understanding Overlay Networks - The Basics NetBird and SentinelOne Singularity™ - Automate Threat Response NetBird and Microsoft Intune - Enforcing Device Compliance for Zero Trust Rethinking Zero Trust Security with NetBird and pfSense Improving Unidirectional Access Control Proxmox VE for Beginners Guide with NetBird LXC Stronger Security: NetBird + GitHub Secure Open Source Fund NetBird's MSP Partner Program Signicat Enhances Cross-Cloud Accessibility with NetBird SonicWall SSL VPN NetExtender vs. NetBird NetBird Is Embracing the AGPLv3 License NetBird Profiles Have Landed - Manage Multiple Accounts Effortlessly Rethinking Access Control to Secure Your On-Premises SharePoint Servers Sport Alliance Increases Efficiency with Zero Trust Networking at Scale Rethinking Network Access: qwertiko Goes Zero Trust with NetBird Optimizing Network Efficiency with NetBird's Lazy Connections Use Port Ranges in Access Control Policies Generic HTTP Endpoint for Network Events Streaming NetBird’s Response to Spear-Phishing Campaign Targeting Financial Executives Zero-Trust Access to Internal Resources Without Installing Agents Enhance Network Visibility with NetBird’s Traffic Events Logging TrueNAS Made Easy - Install, Set Up, and Access From Anywhere Top 5 Alternatives for WireGuard Jump Hosts. Gateways for Remote Access NetBird Network Routes and Exit Nodes Security for All - SSO and MFA for Free Enhancing Network Access Control with NetBird's Identity Provider Feature Twingate vs. NetBird Limit Network Access Based on Running Applications FortiClient ZTNA vs. NetBird OpenVPN vs. NetBird Tailscale vs. NetBird Getting Started with an Azure Site-to-Site VPN Getting Started with an On-premise-to-AWS Site-to-Site VPN regreSSHion - A New OpenSSH Server Remote Code Execution Vulnerability Evolve Bank & Trust Data Breach. What Happened? What Is a Site-to-Site VPN? IPSec Tunneling Demystified. Enhancing Data Security Across Networks Understanding IPSec Tunnel and Transport Modes Understanding the Differences Between IKEv1 and IKEv2 Understanding the IKEv1 Protocol in IPSec ZeroTier versus NetBird - Which Should You Choose? AWS Lambda Serverless Security. Mistakes, Oversights, and Potential Vulnerabilities Using NetBird for Kubernetes Access Serverless Security Vulnerabilities and Best Practices to Mitigate Them Security Best Practices for Serverless Azure Functions A Guide to Remote Access Security for SMEs IoT Security Essentials. How to Achieve Secure Remote Access Open Source Zero Trust Networking Using SSH for Secure Remote Access How We Integrated Rosenpass in NetBird The First Quantum-Resistant Mesh VPN Using eBPF and XDP to Share Default DNS Port Between Multiple Resolvers
Secure Remote Access to VPCs, LANs, and Offices
Written byMisha Bragin · 2024-07-22 · via NetBird - Networking Knowledge Hub - RSS Feed

NetBird offers a fast and secure peer-to-peer mesh network with end-to-end encryption where devices and machines run a NetBird agent and connect directly to each other. Using NetBird this way lets you precisely segment your network, isolate individual machines, and remotely access them securely without opening ports or exposing them to the internet. However, sometimes installing the agent on every machine isn't practical or hasn't been done yet, so access must be given to an entire LAN, office network, or cloud VPC.

NetBird's Network Routes feature allows you to do just that. By configuring routing peers, you can access networks like your office LAN or cloud VPC without installing a NetBird agent on every machine. Moreover, NetBird allows you to limit access to specific machines or services within that LAN or VPC, providing a secure and efficient zero-trust remote access solution.

In this article, you'll discover when and how to use NetBird's Network Routes feature to access LANs or cloud VPCs securely. You'll also learn how to configure high availability for reliable remote access to internal resources.

Why Accessing an Entire LAN or VPC?

Accessing an entire corporate LAN or VPC can be essential in various scenarios:

Side-by-side migrations: When part of your network is already using NetBird but needs to access services that are not yet migrated. Another scenario involves cloud migrations, where cloud services may need to access on-premises databases or vice versa. In this case, network administrators need to ensure that all parts of the network can communicate effectively during the transition period, minimizing disruptions.

Systems with limited operating system access: Certain devices, such as IoT devices and printers, may have limited capabilities to install additional software. Similarly, cloud-managed services have restrictions on installing software. Therefore, setting up remote access to managed services like Amazon Relational Database Service (AWS RDS) or Google Cloud SQL require an alternative to installing the NetBird agent.

Legacy networks: Administrators might encounter challenges installing the NetBird agent on all machines due to outdated hardware or software compatibility issues. Similar to the previous points, network administrators need to provide secure remote access to these legacy networks without extensive upgrades or modifications.

NetBird's Network Routes feature provides a solution to these challenges by allowing your team and machines to securely access remote networks without installing the NetBird agent on every machine.

What are Network Routes and Routing Peers?

The diagram below illustrates a network setup using a NetBird network on the left and a private network that can be any internal network, such as an office LAN or VPC in the cloud, like AWS and Azure.

NetBird Network Routes

The NetBird network includes machines with a NetBird agent installed. These machines can be remote employees' laptops, docker containers, on-premises servers, or databases. Each machine in the NetBird network receives a private static IP address assigned by the NetBird Management server that runs in the cloud or on-premises (if you're using the self-hosted version). These machines form an overlay network and can communicate with each other directly (if allowed by access policies) .

The network on the right is a private network that can be an office LAN, a cloud VPC, or any internal network of your organization. The devices and servers in this network do not run the NetBird agent and are not directly accessible from the NetBird network. How can remote employees access these internal resources securely?

The solution is the machine in the middle, a routing peer that resides in the private network and has a NetBird agent installed, making it part of the NetBird network, too. It advertises the private network's range to the NetBird agents that locally apply it as a network route. Consequently, traffic flows from the NetBird network to the private network via this routing peer.

There is a special feature of NetBird Network Routes that allows you to configure multiple machines as routing peers for the same network. This setup makes remote access to internal resources highly available, ensuring reliable connectivity. You'll learn more about the high availability feature of Network Routes later in this article.

Where to Configure Network Routes?

Network Routes are configured in the NetBird Management console , where you can define routing peers and IP ranges they advertise. If you don't have a NetBird account, sign up for a free to get started.

To use the Network Routes feature, you will need to install the NetBird agent on a Linux machine that resides in your private network that you want to route to. You can also run NetBird in a Docker container and use it as a routing peer.

Network Routes View

You can create and manage Network Routes in the NetBird Management web console under the Network Routes tab. The image below shows a table with a list of network routes configured to route traffic to different private networks.

NetBird Network Routes List

The table has two routes: one for the AWS VPC located in the EU and another for api.website.com. While the purpose of the AWS VPC route is clear—allowing access to resources in the network within the AWS VPC—what is the route for? This is an example of a DNS route, which allows you to route traffic to a specific domain name instead of a network range.

Network Range and DNS Routes

When creating network routes in NetBird, you can choose to route traffic to a specific network range or a domain name.

The image below shows an example configuration of a route using the network range in CIDR notation. NetBird Network Range Route

DNS routes can be used in cases where IPs are dynamic or traffic needs to be routed to a specific public or private domain name. When selecting , you can add multiple domain names that will be resolved dynamically to IP addresses by the NetBird agent and added locally as routes. This feature simplifies routing traffic to load balancers, managed databases, internal services, and restricted sites behind CDNs.

NetBird DNS Route

Enabled by default, the switch ensures that resolved IP addresses remain configured even if the domain resolves to a different IP later, maintaining session integrity with the original IP address. This feature is particularly helpful when routing traffic to external and internal services with load balancers or managed databases like AWS RDS.

Routing Peers and Routing Group

You probably noticed another column in the Network Routes table: . The configured values are and . What is the difference between them?

NetBird Network Routes Type

Routing Peers

There are two ways of adding network routes in NetBird: using individual NetBird peers as routing peers, hence the type, or a group of peers - type. In the case of the type, you can select an individual NetBird peer that will act as a routing peer. The requirement is that this peer has to be a Linux machine or a Docker container. The image below shows the selected that runs on AWS in the VPC network.

NetBird Network Routes Routing Peer

Routing Group

NetBird supports a more dynamic way of adding routing peers. Instead of individual peers, you can select a group that will act as routing peers. The image below shows the selected group.

NetBird Network Routes Routing Group

Every NetBird peer in the selected group will automatically become a routing peer, saving you from manually selecting individual peers. Moreover, this feature is particularly useful when running routing peers on Kubernetes clusters or other dynamic environments with auto-scaling capabilities, ensuring highly available remote access to internal resources.

To save you even more time, NetBird allows to automatically add new peers to groups by using the peer auto-grouping feature of setup keys. The ephemeral peers feature will help you dispose of the routing peers automatically after a certain period of time in the event of downscaling.

High Availability

High availability is crucial for ensuring reliable remote access to internal resources. NetBird's Network Routes feature allows you to configure multiple routing peers for the same network, ensuring that traffic is routed if one of the peers goes down.

If you use type, you can add multiple peers to the same network route. To do this, use the button in the Network Routes table and select another peer from the list of available peers:

NetBird Network Routes High Availability

NetBird Network Routes High Availability Add Peer

If you use the type, you can add multiple peers to the routing group, and NetBird will enable high-availability for this route automatically:

NetBird Network Routes High Availability Group

Distribution Groups

The next step in configuring network routes is to define where the routes should apply. NetBird uses a concept of groups everywhere to simplify the management of access policies, DNS, and other configurations. The Network Routes feature is no exception. You can select a list of to apply the route to all peers that are part of these groups:

NetBird Network Routes Distribution Groups

Every NetBird peer that is part of the selected distribution group will receive the route and apply it locally to their operating system's routing table.

The caveat here is that you need to ensure that peers from the selected distribution groups can reach the routing peers. This requires an access policy that allows traffic from the distribution group to the routing peers. You can manage this using the field.

Access Control Groups

You can restrict access to your route by adding the route to and using these groups when creating access policies.

NetBird Network Routes Access Control Groups

The route is added to the group in the image above. When creating an access policy, you can use this group as a destination to restrict access. For example, to allow only developers to access this route, create a policy as follows:

NetBird Network Routes Access Control Policy

This policy allows a one-way HTTP, HTTPS, and SSH remote access to for all machines in the group.

Create Routes for Individual Resources

Network Routes can be used to access entire networks or parts of the network, but you can also use them to access individual resources within a network.

You can create a route to access a specific machine in your network by specifying the exact IP address of this machine in the field. Similarly, you can add the domain name of a particular service in the field. For example, if you have an internal Jira or GitLab server with the IP address , you can create a route as shown in the image below: NetBird Network Routes for Individual Resources

Furthermore, you can restrict access to this resource by adding the route to an and creating an access policy.

Conclusion

NetBird's Network Routes feature provides a practical solution for secure remote access to entire LANs, office networks, and cloud VPCs without requiring the NetBird agent on every device. This is crucial for side-by-side migrations, systems with limited OS access, and legacy networks. Administrators can ensure seamless and reliable connectivity with high availability by configuring multiple routing peers or routing groups.

Using network ranges and DNS routes enables efficient traffic routing, while distribution and access control groups simplify access management. Granular access control ensures that internal resources are securely and reliably accessible, making NetBird's Network Routes an effective tool for modern zero-trust network access.