mirror of
https://github.com/netbirdio/docs.git
synced 2026-09-28 17:59:05 +02:00
docs: explain why the WireGuard port is not a required firewall rule (#1005)
This commit is contained in:
@@ -18,6 +18,10 @@ This section covers **network/perimeter firewall** requirements (e.g., Fortigate
|
||||
|
||||
The NetBird client doesn't require any inbound port to be open; it negotiates the connection with the support of the signal and relay services.
|
||||
|
||||
<Note>
|
||||
NetBird peers use WireGuard over UDP (default port `51820`), but you don't need to open that port inbound. Peers connect outbound and use hole punching. If a direct connection isn't possible, they fall back to the relay over UDP/443 (QUIC) or TCP/443 (WebSocket). An outbound rule for UDP port 51820 won't reliably help either: the port a peer sends to is whatever the NAT in front of the other peer assigned, and that is often not 51820. If your policy requires fixed ports, see [Static peer ports for site-to-site firewall rules](#static-peer-ports-for-site-to-site-firewall-rules).
|
||||
</Note>
|
||||
|
||||
### Outbound ports
|
||||
|
||||
NetBird usually won't need open ports, but sometimes you or your IT team needs to secure and verify all outbound traffic, and that may affect how NetBird clients connect to the [control plane](/about-netbird/how-netbird-works) and negotiate the peer-to-peer connections.
|
||||
|
||||
Reference in New Issue
Block a user