Update faq.mdx / make TURN firewall rule recommended (#207)

* Update faq.mdx

make the TURN firewall rule recommended - it's needed for peers to connect consistently

* Update src/pages/about-netbird/faq.mdx

Co-authored-by: Maycon Santos <mlsmaycon@gmail.com>

* Update src/pages/about-netbird/faq.mdx

Co-authored-by: Maycon Santos <mlsmaycon@gmail.com>

---------

Co-authored-by: Maycon Santos <mlsmaycon@gmail.com>
This commit is contained in:
Stuart Cardall
2024-08-12 14:17:57 +02:00
committed by GitHub
co-authored by Maycon Santos
parent a90b010ec6
commit d955b3d928
+9
View File
@@ -11,6 +11,13 @@ NetBird usually won't need open ports, but sometimes you or your IT team needs t
all outgoing traffic, and that may affect how NetBird clients connect to the [control layer](/about-netbird/how-netbird-works) all outgoing traffic, and that may affect how NetBird clients connect to the [control layer](/about-netbird/how-netbird-works)
and negotiate the peer-to-peer connections. and negotiate the peer-to-peer connections.
<Note>
Allowing the outbound **Relay (TURN)** service below is **recommended** in more restricted networks for reliable peer connections. This will also improve the reliability of your [High Availability Routes](https://docs.netbird.io/how-to/routing-traffic-to-private-networks#high-availability-routes).
</Note>
<Note>
If using `fail2ban` or similar, you should whitelist each netbird.io endpoint below.
</Note>
Below is the list of NetBird hosted endpoints and ports they listen to: Below is the list of NetBird hosted endpoints and ports they listen to:
* Management service: * Management service:
* **Endpoint**: api.netbird.io * **Endpoint**: api.netbird.io
@@ -27,6 +34,8 @@ Below is the list of NetBird hosted endpoints and ports they listen to:
* **Port range**: UDP/80,443 and TCP/443-65535 * **Port range**: UDP/80,443 and TCP/443-65535
* **IPv4**: The list is dynamic and geo-distributed; we advise you to check the nearest cluster with the following command: * **IPv4**: The list is dynamic and geo-distributed; we advise you to check the nearest cluster with the following command:
* `nslookup turn.netbird.io` * `nslookup turn.netbird.io`
* In more restricted environments, `netbird status` will show `keepalive ping failed` errors without a firewall rule for TURN
* Example `nftables` outbound firewall rule: `ip daddr turn.netbird.io tcp dport 443-65535 accept`
## Why and what are the anonymous usage metrics? ## Why and what are the anonymous usage metrics?