mirror of
https://github.com/netbirdio/docs.git
synced 2026-09-28 17:59:05 +02:00
Reverse proxy: the server must reach its own public IP (#1002)
The proxy's embedded NetBird client connects to Signal and the relay at the NetBird domain's public address, even when the proxy reaches Management over the Docker network. Without hairpin NAT every proxied service times out; split DNS works but forces relayed connections.
This commit is contained in:
@@ -42,6 +42,7 @@ Before starting, ensure you have:
|
||||
- **A domain for the proxy** - preferably a dedicated domain such as `proxy.example.com`. It can share the NetBird server's domain, but that base hostname remains reserved for the dashboard and management server. Proxied services must use subdomains (e.g., `myapp.netbird.example.com`)
|
||||
- **Wildcard DNS capability** - ability to create a wildcard record such as `*.proxy.example.com` pointing to your server
|
||||
- **Port 443 accessible** - the proxy needs this for ACME TLS-ALPN-01 challenges (certificate provisioning)
|
||||
- **The server can reach its own public IP** - the proxy runs its own NetBird client, and that client connects to Signal and the relay at your NetBird domain's public address, even when the proxy reaches the management server over the Docker network. If the firewall in front of the server does not route a connection from the server back to its own public IP (hairpin NAT), every proxied service returns `504 Gateway Timeout` and the proxy logs `failed connecting to Signal Service`. Resolving the NetBird domain to an internal address instead (split DNS) keeps the services working, but every connection between the proxy and your peers then goes through the relay
|
||||
|
||||
<Note>
|
||||
This guide covers both the **combined container** setup (`netbirdio/netbird-server`, the default for new deployments) and the **multi-container** setup (separate `management`, `signal`, and `relay` images). Where commands or configuration differ between the two setups, both variants are shown.
|
||||
|
||||
Reference in New Issue
Block a user