[{"data":1,"prerenderedAt":190},["ShallowReactive",2],{"seo-verification":3,"blog-netbird-mesh-vpn-vps-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"blog-netbird-mesh-vpn-vps-en",{"id":9,"slug":10,"slugs":11,"title":15,"excerpt":16,"readTime":17,"views":18,"isPinned":19,"publishedAt":20,"updatedAt":21,"category":22,"categories":27,"featuredImage":29,"bgImage":30,"posterImage":31,"relatedSolution":29,"intro":32,"sections":33,"ctaTitle":131,"ctaBody":132,"ctaButton":133,"ctaUrl":134,"relatedPosts":135},396,"netbird-mesh-vpn-vps",{"fr":12,"en":10,"ar":13,"es":14},"netbird-vpn-mesh-vps","netbird-شبكة-vpn-mesh-vps","netbird-vpn-malla-vps","VPN mesh with no open ports using NetBird on VPS","Connect your VPS, offices, and remote workstations in a private mesh network without opening a single public port, using NetBird v0.76 and the netbird expose command.",8,0,false,"2026-09-28T00:00:00+00:00","2026-09-29T14:40:42+00:00",{"id":17,"name":23,"slug":24,"color":25,"icon":26},"Security & Monitoring","securite-monitoring","bg-rose-500\u002F10 text-rose-400","security",[28],{"id":17,"name":23,"slug":24,"color":25,"icon":26},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fnetbird-vpn-mesh-vps-poster.svg","Ten clients, ten different VPS accesses, ten sets of WireGuard keys to manage by hand. For every new admin workstation or remote office, you need to reopen a firewall, redistribute a key, and update configurations on every node. This model fails at scale. NetBird 0.76 solves this problem by fully automating peer discovery, NAT traversal, and TURN relays — and its `netbird expose` command lets you make an internal service accessible from the mesh without opening a single public port on the Internet.",[34,38,46,49,55,58,76,79,82,85,123,126,128],{"type":35,"title":36,"body":37},"h2","The problem: managing ten manual WireGuard tunnels","WireGuard is excellent — fast, modern, cryptographically solid. But its configuration model is static: each peer must know the public IP and public key of all its peers. In a fleet of ten clients with nomadic workstations, offices behind CGNAT, and VPS with variable IPs, you spend more time synchronizing `wg0.conf` files than doing productive work. Add a VPS, modify the peer list on nine machines. Remove a technician, revoke their key everywhere. A subnet changes? Start over. This is the operational nightmare that NetBird was designed to eliminate.",{"type":39,"items":40},"ul",[41,42,43,44,45],"Automatic mesh: NetBird manages the control plane — every new peer announces itself, others discover it without manual intervention.","NAT and CGNAT traversal: NetBird uses STUN to establish direct peer-to-peer connections through residential and corporate NATs.","Automatic TURN relay: when direct connection is impossible (strict firewall, double NAT), NetBird silently switches to an encrypted relay.","Granular access audit: access control policies define which peers can reach which services — visible from the dashboard.","Open source (BSD-3 for the client, AGPLv3 for the control plane): no vendor lock-in, self-hosting possible.",{"type":35,"title":47,"body":48},"Prerequisites","Before installing NetBird, verify that your infrastructure meets the following requirements.",{"type":39,"items":50},[51,52,53,54],"A ServOrbit VPS running Ubuntu 22.04\u002F24.04 or Debian 12, with root access.","A NetBird Cloud account (free for up to 5 peers) or an already-deployed self-hosted control plane.","Outbound ports 443 (HTTPS\u002FWSS) and 3478 (STUN\u002FUDP) not blocked from the VPS.","The Peer Expose feature enabled on your account (available on Team and higher plans, or on a self-hosted control plane).",{"type":35,"title":56,"body":57},"Connect a ServOrbit VPS to a NetBird network","Here is the complete procedure for connecting a ServOrbit VPS to your NetBird mesh network.",{"type":59,"steps":60},"steps",[61,64,67,70,73],{"title":62,"body":63},"Install the NetBird agent","On the VPS, add the official repository and install the package:\n```bash\ncurl -fsSL https:\u002F\u002Fpkgs.netbird.io\u002Finstall.sh | sh\n```\nVerify the installed version: `netbird version` should display `0.76.x`.",{"title":65,"body":66},"Generate a setup key","In the NetBird dashboard (app.netbird.io or your self-hosted instance), go to **Setup Keys** and create a reusable or one-time key. Copy it — it only appears once.",{"title":68,"body":69},"Connect the peer to the control plane","On the VPS:\n```bash\nnetbird up --setup-key \u003CYOUR_SETUP_KEY>\n```\nFor a self-hosted control plane, add `--management-url https:\u002F\u002Fnetbird.your-domain.com:443`. The command returns immediately; the peer appears in the dashboard within seconds.",{"title":71,"body":72},"Add the peer to a network group","In the NetBird interface, navigate to **Peers**, select the new VPS and add it to the desired group (e.g. `agency-clients`). Access policies linked to this group apply immediately — no restart needed.",{"title":74,"body":75},"Verify mesh connectivity","From another peer already in the network:\n```bash\nnetbird status\n# lists reachable peers with their mesh IP (100.x.x.x) and connection status\nping 100.x.x.x  # mesh IP of the new VPS\n```\nA responding ping confirms the tunnel is established.",{"type":35,"title":77,"body":78},"`netbird expose`: an internal service without a public port","The `netbird expose` command, available since version 0.66 and consolidated in the 0.76 branch, lets you make a service listening locally (on `127.0.0.1` or a private network) accessible from the Internet via NetBird's reverse proxy — without opening a single port on the VPS firewall. The created service is ephemeral: it automatically disappears when the command stops.\n\nExample: your monitoring panel (Grafana, Netdata) listens on `localhost:3000` and should only be accessible to authorized mesh members:\n```bash\nnetbird expose --protocol http \\\n  --local-address localhost:3000 \\\n  --with-user-groups supervision-admins\n```\nNetBird generates a public URL at `*.tunnel.netbird.io`. Port 3000 on the VPS remains closed at the firewall level.",{"type":80,"body":81},"tip","For password-protected access without SSO, add `--with-password`: NetBird displays a random password you share with your collaborators. Useful for emergency access to a client without an account in your NetBird tenant.",{"type":35,"title":83,"body":84},"Agency use case: connecting client VPS, office, and admin workstation","Recommended NetBird topology for an agency managing ten independent clients: Create one group per client (e.g. `client-acme`, `client-contoso`). Each client's VPS is a member of its client group. Admin workstations are members of their respective client group only. An access policy links each group to itself. The agency office is in an `agency-ops` group with access to all client groups — the only cross-cutting peer. SSH to client VPS uses the mesh IP (`100.x.x.x`); no public SSH port is needed:\n```bash\nufw allow in on netbird0 to any port 22\nufw deny 22\n```",{"type":86,"headers":87,"rows":92},"comparison",[88,89,90,91],"Criterion","NetBird 0.76","Tailscale","Manual WireGuard",[93,98,103,108,113,118],[94,95,96,97],"Peer management","Automatic (centralized control plane)","Automatic (Tailscale cloud)","Manual (wg0.conf files on each node)",[99,100,101,102],"NAT\u002FCGNAT traversal","Automatic STUN + TURN","Automatic STUN + DERP","Requires public IP or port-forward",[104,105,106,107],"Pricing model","Free up to 5 peers; Team\u002FBusiness plans; self-hosted free","Free up to 3 users; paid plans for teams","Free (software), operational cost in time",[109,110,111,112],"Open source","Yes (BSD-3 client, AGPLv3 server)","Client open source (BSD-3), proprietary server","Yes (GPLv2 kernel, MIT userland)",[114,115,116,117],"Expose service without open port","Yes (`netbird expose`)","No (Funnel available but different)","Not native (manual SSH tunnel)",[119,120,121,122],"Audit and access policies","Full web interface, groups and policies","ACL via HuJSON file, web interface","None — only AllowedIPs per peer",{"type":35,"title":124,"body":125},"Troubleshooting: 3 common problems","**1. Unreachable peer (`Status: Disconnected`)** — Run `netbird status --detail` to see the ICE state. If you see `no candidate pairs`, the issue is network: verify outbound UDP port 3478 is open. If direct connection fails but TURN is available, NetBird switches automatically.\n\n**2. STUN\u002FTURN blocked by corporate firewall** — NetBird supports TURN over TCP\u002F443. Configure in the dashboard: **Settings → Relay → Force TCP**.\n\n**3. Reading logs** — On Linux with systemd:\n```bash\njournalctl -u netbird -f --since '5 minutes ago'\n```\nKey messages to watch: `failed to connect`, `signal disconnected`, `peer connected via relay`.",{"type":80,"body":127},"Access control policy: in **Access Control → Policies**, create a rule that only allows the `agency-ops` group to reach port 22 on client groups. Other ports (80, 443) can be accessible to the client group itself. This granularity prevents a compromised workstation in the mesh from pivoting to all client VPS.",{"type":35,"title":129,"body":130},"Conclusion: fewer firewall rules, more real security","NetBird 0.76 represents a paradigm shift for managing a distributed VPS fleet. Instead of multiplying UFW rules and static WireGuard keys, you define groups and policies once — and the control plane handles the rest. The `netbird expose` command goes further: it physically removes services from Internet exposure without reconfiguring the firewall. For an agency managing ten clients or a company with distributed offices, this is the highest-impact attack surface reduction per hour invested.","Need secure infrastructure for your agency?","Our agency plans include dedicated VPS, dedicated technical support, and a network architecture adapted to multi-client management. Discover how we can simplify your infrastructure.","View agency plans","\u002Fsolutions\u002Fagences",[136,155,170],{"id":137,"slug":138,"slugs":139,"title":143,"excerpt":144,"readTime":145,"views":18,"isPinned":19,"publishedAt":146,"updatedAt":147,"category":148,"categories":149,"featuredImage":29,"bgImage":30,"posterImage":151,"relatedSolution":152},141,"wireguard-on-a-vps-a-fast-lean-and-private-vpn",{"fr":140,"en":138,"ar":141,"es":142},"installer-wireguard-vps","wireguard-على-خادم-vps-شبكة-vpn-سريعة-ومبسطة-وخاصة","wireguard-en-un-vps-vpn-rapido-y-privado","WireGuard on a VPS: a fast, lean and private VPN","Deploy WireGuard on a ServOrbit VPS: fast tunnels, readable configuration, client QR codes and private remote access.",4,"2026-02-04T00:00:00+00:00","2026-09-07T11:26:10+00:00",{"id":17,"name":23,"slug":24,"color":25,"icon":26},[150],{"id":17,"name":23,"slug":24,"color":25,"icon":26},"\u002Fblog\u002Fcovers\u002Finstaller-wireguard-vps-poster.svg",{"categorySlug":153,"appSlug":154},"securite","wireguard-server",{"id":156,"slug":157,"slugs":158,"title":162,"excerpt":163,"readTime":164,"views":18,"isPinned":19,"publishedAt":165,"updatedAt":21,"category":166,"categories":167,"featuredImage":29,"bgImage":30,"posterImage":169,"relatedSolution":29},382,"vps-automatic-security-updates-debian-ubuntu",{"fr":159,"en":157,"ar":160,"es":161},"securite-vps-mises-a-jour-automatiques-debian-ubuntu","تحديثات-أمان-تلقائية-vps-debian-ubuntu","actualizaciones-seguridad-vps-debian-ubuntu","Automatic Security Updates on Debian\u002FUbuntu VPS","Configure unattended-upgrades on your Debian\u002FUbuntu VPS to automate security patches and reduce attack surface across your client fleet.",10,"2026-09-26T00:00:00+00:00",{"id":17,"name":23,"slug":24,"color":25,"icon":26},[168],{"id":17,"name":23,"slug":24,"color":25,"icon":26},"\u002Fblog\u002Fcovers\u002Fsecurite-vps-mises-a-jour-automatiques-debian-ubuntu-poster.svg",{"id":171,"slug":172,"slugs":173,"title":177,"excerpt":178,"readTime":164,"views":179,"isPinned":19,"publishedAt":180,"updatedAt":181,"category":182,"categories":187,"featuredImage":29,"bgImage":30,"posterImage":189,"relatedSolution":29},291,"netbird-self-hosted-wireguard-mesh-vpn-on-a-vps",{"fr":174,"en":172,"ar":175,"es":176},"deployer-netbird-controle-vpn-mesh-vps","netbird-شبكة-vpn-مشبكة-wireguard-باستضافة-ذاتية","desplegar-netbird-vpn-mesh-wireguard-en-vps","Netbird: Self-Hosted WireGuard Mesh VPN on a VPS","Connect multiple client VPS without opening any ports: Netbird builds a WireGuard mesh you control — Management, Signal and COTURN relay all self-hosted.",1,"2026-08-21T00:00:00+00:00","2026-09-21T15:22:03+00:00",{"id":183,"name":184,"slug":185,"color":186,"icon":185},3,"Deployment","deploiement","bg-success\u002F10 text-success",[188],{"id":183,"name":184,"slug":185,"color":186,"icon":185},"\u002Fblog\u002Fcovers\u002Fdeployer-netbird-controle-vpn-mesh-vps-poster.svg",1790693269771]