From 8eafcdc59e67940de450f4fb412aa79e222ee5ae Mon Sep 17 00:00:00 2001 From: Jack Carter <128555021+SunsetDrifter@users.noreply.github.com> Date: Mon, 28 Sep 2026 11:38:01 +0200 Subject: [PATCH] docs: explain why the WireGuard port is not a required firewall rule (#1005) --- src/pages/about-netbird/ports-and-firewalls.mdx | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/pages/about-netbird/ports-and-firewalls.mdx b/src/pages/about-netbird/ports-and-firewalls.mdx index 382bbf97..fdad0308 100644 --- a/src/pages/about-netbird/ports-and-firewalls.mdx +++ b/src/pages/about-netbird/ports-and-firewalls.mdx @@ -18,6 +18,10 @@ This section covers **network/perimeter firewall** requirements (e.g., Fortigate The NetBird client doesn't require any inbound port to be open; it negotiates the connection with the support of the signal and relay services. + + NetBird peers use WireGuard over UDP (default port `51820`), but you don't need to open that port inbound. Peers connect outbound and use hole punching. If a direct connection isn't possible, they fall back to the relay over UDP/443 (QUIC) or TCP/443 (WebSocket). An outbound rule for UDP port 51820 won't reliably help either: the port a peer sends to is whatever the NAT in front of the other peer assigned, and that is often not 51820. If your policy requires fixed ports, see [Static peer ports for site-to-site firewall rules](#static-peer-ports-for-site-to-site-firewall-rules). + + ### Outbound ports NetBird usually won't need open ports, but sometimes you or your IT team needs to secure and verify all outbound traffic, and that may affect how NetBird clients connect to the [control plane](/about-netbird/how-netbird-works) and negotiate the peer-to-peer connections.