mirror of
https://github.com/netbirdio/docs.git
synced 2026-09-29 18:29:05 +02:00
Document missing CLI flags and client environment variables (#687)
This commit is contained in:
@@ -242,6 +242,22 @@ The upload key is automatically copyable by clicking on it. Share this key throu
|
||||
- Bundles are automatically uploaded to NetBird's secure storage (or your configured upload endpoint for self-hosted deployments)
|
||||
- Upload keys expire after 30 days for security
|
||||
|
||||
### Tracing firewall rules
|
||||
|
||||
If a connection is being blocked and you suspect a policy issue, the `debug trace` command lets you simulate a packet through the firewall rules without sending real traffic. See the [CLI reference](/get-started/cli#debug-trace) for full usage and examples.
|
||||
|
||||
```shell
|
||||
netbird debug trace in 100.64.1.1 self -p tcp --dport 80
|
||||
```
|
||||
|
||||
<Note>
|
||||
On Linux, the userspace packet filter is only active when the kernel firewall backend (nftables/iptables) is not available. `debug trace` is primarily useful on macOS and Windows.
|
||||
</Note>
|
||||
|
||||
### Advanced environment variables
|
||||
|
||||
The client has environment variables for tuning routing, firewall behavior, ICE connectivity, and WireGuard mode. These can help work around edge cases (e.g. `NB_USE_LEGACY_ROUTING` for routing loop issues, `NB_WG_KERNEL_DISABLED` to force userspace WireGuard, `NB_SKIP_NFTABLES_CHECK` to fall back to iptables). See the full list at [Client Environment Variables](/client/environment-variables).
|
||||
|
||||
## Enabling debug logs on agent
|
||||
|
||||
Logs can be temporarily set using the following command.
|
||||
|
||||
Reference in New Issue
Block a user