Tutorial

VPN mesh with no open ports using NetBird on VPS

Security & Monitoring8 min read5 steps

Ten clients, ten different VPS accesses, ten sets of WireGuard keys to manage by hand. For every new admin workstation or remote office, you need to reopen a firewall, redistribute a key, and update configurations on every node. This model fails at scale. NetBird 0.76 solves this problem by fully automating peer discovery, NAT traversal, and TURN relays — and its `netbird expose` command lets you make an internal service accessible from the mesh without opening a single public port on the Internet.

Contents· The problem: managing ten manual WireGuard tunnels1/7
  1. 01The problem: managing ten manual WireGuard tunnels
  2. 02Prerequisites
  3. 03Connect a ServOrbit VPS to a NetBird network
  4. 04`netbird expose`: an internal service without a public port
  5. 05Agency use case: connecting client VPS, office, and admin workstation
  6. 06Troubleshooting: 3 common problems
  7. 07Conclusion: fewer firewall rules, more real security

The problem: managing ten manual WireGuard tunnels

WireGuard is excellent — fast, modern, cryptographically solid. But its configuration model is static: each peer must know the public IP and public key of all its peers. In a fleet of ten clients with nomadic workstations, offices behind CGNAT, and VPS with variable IPs, you spend more time synchronizing wg0.conf files than doing productive work. Add a VPS, modify the peer list on nine machines. Remove a technician, revoke their key everywhere. A subnet changes? Start over. This is the operational nightmare that NetBird was designed to eliminate.

  • Automatic mesh: NetBird manages the control plane — every new peer announces itself, others discover it without manual intervention.
  • NAT and CGNAT traversal: NetBird uses STUN to establish direct peer-to-peer connections through residential and corporate NATs.
  • Automatic TURN relay: when direct connection is impossible (strict firewall, double NAT), NetBird silently switches to an encrypted relay.
  • Granular access audit: access control policies define which peers can reach which services — visible from the dashboard.
  • Open source (BSD-3 for the client, AGPLv3 for the control plane): no vendor lock-in, self-hosting possible.

Prerequisites

Before installing NetBird, verify that your infrastructure meets the following requirements.

  • A ServOrbit VPS running Ubuntu 22.04/24.04 or Debian 12, with root access.
  • A NetBird Cloud account (free for up to 5 peers) or an already-deployed self-hosted control plane.
  • Outbound ports 443 (HTTPS/WSS) and 3478 (STUN/UDP) not blocked from the VPS.
  • The Peer Expose feature enabled on your account (available on Team and higher plans, or on a self-hosted control plane).

Connect a ServOrbit VPS to a NetBird network

Here is the complete procedure for connecting a ServOrbit VPS to your NetBird mesh network.

  1. Install the NetBird agent

    On the VPS, add the official repository and install the package:

    curl -fsSL https://pkgs.netbird.io/install.sh | sh

    Verify the installed version: netbird version should display 0.76.x.

  2. Generate a setup key

    In the NetBird dashboard (app.netbird.io or your self-hosted instance), go to Setup Keys and create a reusable or one-time key. Copy it — it only appears once.

  3. Connect the peer to the control plane

    On the VPS:

    netbird up --setup-key <YOUR_SETUP_KEY>

    For a self-hosted control plane, add --management-url https://netbird.your-domain.com:443. The command returns immediately; the peer appears in the dashboard within seconds.

  4. Add the peer to a network group

    In the NetBird interface, navigate to Peers, select the new VPS and add it to the desired group (e.g. agency-clients). Access policies linked to this group apply immediately — no restart needed.

  5. Verify mesh connectivity

    From another peer already in the network:

    netbird status
    # lists reachable peers with their mesh IP (100.x.x.x) and connection status
    ping 100.x.x.x  # mesh IP of the new VPS

    A responding ping confirms the tunnel is established.

`netbird expose`: an internal service without a public port

The netbird expose command, available since version 0.66 and consolidated in the 0.76 branch, lets you make a service listening locally (on 127.0.0.1 or a private network) accessible from the Internet via NetBird's reverse proxy — without opening a single port on the VPS firewall. The created service is ephemeral: it automatically disappears when the command stops.

Example: your monitoring panel (Grafana, Netdata) listens on localhost:3000 and should only be accessible to authorized mesh members:

netbird expose --protocol http \
  --local-address localhost:3000 \
  --with-user-groups supervision-admins

NetBird generates a public URL at *.tunnel.netbird.io. Port 3000 on the VPS remains closed at the firewall level.

For password-protected access without SSO, add --with-password: NetBird displays a random password you share with your collaborators. Useful for emergency access to a client without an account in your NetBird tenant.

Agency use case: connecting client VPS, office, and admin workstation

Recommended NetBird topology for an agency managing ten independent clients: Create one group per client (e.g. client-acme, client-contoso). Each client's VPS is a member of its client group. Admin workstations are members of their respective client group only. An access policy links each group to itself. The agency office is in an agency-ops group with access to all client groups — the only cross-cutting peer. SSH to client VPS uses the mesh IP (100.x.x.x); no public SSH port is needed:

ufw allow in on netbird0 to any port 22
ufw deny 22

Scroll the table

CriterionNetBird 0.76TailscaleManual WireGuard
Peer managementAutomatic (centralized control plane)Automatic (Tailscale cloud)Manual (wg0.conf files on each node)
NAT/CGNAT traversalAutomatic STUN + TURNAutomatic STUN + DERPRequires public IP or port-forward
Pricing modelFree up to 5 peers; Team/Business plans; self-hosted freeFree up to 3 users; paid plans for teamsFree (software), operational cost in time
Open sourceYes (BSD-3 client, AGPLv3 server)Client open source (BSD-3), proprietary serverYes (GPLv2 kernel, MIT userland)
Expose service without open portYes (`netbird expose`)No (Funnel available but different)Not native (manual SSH tunnel)
Audit and access policiesFull web interface, groups and policiesACL via HuJSON file, web interfaceNone — only AllowedIPs per peer

Troubleshooting: 3 common problems

1. Unreachable peer (Status: Disconnected) — Run netbird status --detail to see the ICE state. If you see no candidate pairs, the issue is network: verify outbound UDP port 3478 is open. If direct connection fails but TURN is available, NetBird switches automatically.

2. STUN/TURN blocked by corporate firewall — NetBird supports TURN over TCP/443. Configure in the dashboard: Settings → Relay → Force TCP.

3. Reading logs — On Linux with systemd:

journalctl -u netbird -f --since '5 minutes ago'

Key messages to watch: failed to connect, signal disconnected, peer connected via relay.

Access control policy: in Access Control → Policies, create a rule that only allows the agency-ops group to reach port 22 on client groups. Other ports (80, 443) can be accessible to the client group itself. This granularity prevents a compromised workstation in the mesh from pivoting to all client VPS.

Conclusion: fewer firewall rules, more real security

NetBird 0.76 represents a paradigm shift for managing a distributed VPS fleet. Instead of multiplying UFW rules and static WireGuard keys, you define groups and policies once — and the control plane handles the rest. The netbird expose command goes further: it physically removes services from Internet exposure without reconfiguring the firewall. For an agency managing ten clients or a company with distributed offices, this is the highest-impact attack surface reduction per hour invested.

Need secure infrastructure for your agency?

Our agency plans include dedicated VPS, dedicated technical support, and a network architecture adapted to multi-client management. Discover how we can simplify your infrastructure.

Need help?

Browse our help center and FAQ, or reach our team — callback, WhatsApp or email. Support in French, English and Arabic.

Message us on WhatsAppopens in a new tab