The problem: managing ten manual WireGuard tunnels
WireGuard is excellent — fast, modern, cryptographically solid. But its configuration model is static: each peer must know the public IP and public key of all its peers. In a fleet of ten clients with nomadic workstations, offices behind CGNAT, and VPS with variable IPs, you spend more time synchronizing wg0.conf files than doing productive work. Add a VPS, modify the peer list on nine machines. Remove a technician, revoke their key everywhere. A subnet changes? Start over. This is the operational nightmare that NetBird was designed to eliminate.
- Automatic mesh: NetBird manages the control plane — every new peer announces itself, others discover it without manual intervention.
- NAT and CGNAT traversal: NetBird uses STUN to establish direct peer-to-peer connections through residential and corporate NATs.
- Automatic TURN relay: when direct connection is impossible (strict firewall, double NAT), NetBird silently switches to an encrypted relay.
- Granular access audit: access control policies define which peers can reach which services — visible from the dashboard.
- Open source (BSD-3 for the client, AGPLv3 for the control plane): no vendor lock-in, self-hosting possible.
Prerequisites
Before installing NetBird, verify that your infrastructure meets the following requirements.
- A ServOrbit VPS running Ubuntu 22.04/24.04 or Debian 12, with root access.
- A NetBird Cloud account (free for up to 5 peers) or an already-deployed self-hosted control plane.
- Outbound ports 443 (HTTPS/WSS) and 3478 (STUN/UDP) not blocked from the VPS.
- The Peer Expose feature enabled on your account (available on Team and higher plans, or on a self-hosted control plane).
Connect a ServOrbit VPS to a NetBird network
Here is the complete procedure for connecting a ServOrbit VPS to your NetBird mesh network.
Install the NetBird agent
On the VPS, add the official repository and install the package:
curl -fsSL https://pkgs.netbird.io/install.sh | shVerify the installed version:
netbird versionshould display0.76.x.Generate a setup key
In the NetBird dashboard (app.netbird.io or your self-hosted instance), go to Setup Keys and create a reusable or one-time key. Copy it — it only appears once.
Connect the peer to the control plane
On the VPS:
netbird up --setup-key <YOUR_SETUP_KEY>For a self-hosted control plane, add
--management-url https://netbird.your-domain.com:443. The command returns immediately; the peer appears in the dashboard within seconds.Add the peer to a network group
In the NetBird interface, navigate to Peers, select the new VPS and add it to the desired group (e.g.
agency-clients). Access policies linked to this group apply immediately — no restart needed.Verify mesh connectivity
From another peer already in the network:
netbird status # lists reachable peers with their mesh IP (100.x.x.x) and connection status ping 100.x.x.x # mesh IP of the new VPSA responding ping confirms the tunnel is established.
`netbird expose`: an internal service without a public port
The netbird expose command, available since version 0.66 and consolidated in the 0.76 branch, lets you make a service listening locally (on 127.0.0.1 or a private network) accessible from the Internet via NetBird's reverse proxy — without opening a single port on the VPS firewall. The created service is ephemeral: it automatically disappears when the command stops.
Example: your monitoring panel (Grafana, Netdata) listens on localhost:3000 and should only be accessible to authorized mesh members:
netbird expose --protocol http \
--local-address localhost:3000 \
--with-user-groups supervision-adminsNetBird generates a public URL at *.tunnel.netbird.io. Port 3000 on the VPS remains closed at the firewall level.
For password-protected access without SSO, add --with-password: NetBird displays a random password you share with your collaborators. Useful for emergency access to a client without an account in your NetBird tenant.
Agency use case: connecting client VPS, office, and admin workstation
Recommended NetBird topology for an agency managing ten independent clients: Create one group per client (e.g. client-acme, client-contoso). Each client's VPS is a member of its client group. Admin workstations are members of their respective client group only. An access policy links each group to itself. The agency office is in an agency-ops group with access to all client groups — the only cross-cutting peer. SSH to client VPS uses the mesh IP (100.x.x.x); no public SSH port is needed:
ufw allow in on netbird0 to any port 22
ufw deny 22Scroll the table
| Criterion | NetBird 0.76 | Tailscale | Manual WireGuard |
|---|---|---|---|
| Peer management | Automatic (centralized control plane) | Automatic (Tailscale cloud) | Manual (wg0.conf files on each node) |
| NAT/CGNAT traversal | Automatic STUN + TURN | Automatic STUN + DERP | Requires public IP or port-forward |
| Pricing model | Free up to 5 peers; Team/Business plans; self-hosted free | Free up to 3 users; paid plans for teams | Free (software), operational cost in time |
| Open source | Yes (BSD-3 client, AGPLv3 server) | Client open source (BSD-3), proprietary server | Yes (GPLv2 kernel, MIT userland) |
| Expose service without open port | Yes (`netbird expose`) | No (Funnel available but different) | Not native (manual SSH tunnel) |
| Audit and access policies | Full web interface, groups and policies | ACL via HuJSON file, web interface | None — only AllowedIPs per peer |
Troubleshooting: 3 common problems
1. Unreachable peer (Status: Disconnected) — Run netbird status --detail to see the ICE state. If you see no candidate pairs, the issue is network: verify outbound UDP port 3478 is open. If direct connection fails but TURN is available, NetBird switches automatically.
2. STUN/TURN blocked by corporate firewall — NetBird supports TURN over TCP/443. Configure in the dashboard: Settings → Relay → Force TCP.
3. Reading logs — On Linux with systemd:
journalctl -u netbird -f --since '5 minutes ago'Key messages to watch: failed to connect, signal disconnected, peer connected via relay.
Access control policy: in Access Control → Policies, create a rule that only allows the agency-ops group to reach port 22 on client groups. Other ports (80, 443) can be accessible to the client group itself. This granularity prevents a compromised workstation in the mesh from pivoting to all client VPS.
Conclusion: fewer firewall rules, more real security
NetBird 0.76 represents a paradigm shift for managing a distributed VPS fleet. Instead of multiplying UFW rules and static WireGuard keys, you define groups and policies once — and the control plane handles the rest. The netbird expose command goes further: it physically removes services from Internet exposure without reconfiguring the firewall. For an agency managing ten clients or a company with distributed offices, this is the highest-impact attack surface reduction per hour invested.