Files
netbird-docs/src
Jack Carter 0653cacbbd docs: routing-peer self-access + Active Directory guides, and DNS/routing-peer clarifications (#796)
* docs: add routing-peer self-access and Active Directory guides

New use-case guides: reaching a service on a routing peer's own LAN IP
(route + peer-to-peer policy + NB_ENABLE_LOCAL_FORWARDING) and an
end-to-end Active Directory / Windows file shares guide over NetBird.

Clarify domain-resource DNS: with Routing Peer DNS Resolution on, the
routing peer answers the client's A/AAAA lookups (a domain resource
matches the exact name; use a wildcard for hostnames under a domain),
but AD still needs a nameserver group for the SRV/DC-locator records.

Add navigation entries, overlay-vs-LAN-IP notes, and ICMP/ping
troubleshooting guidance.

* docs: fix WireGuard anchor slug and sharpen local-forwarding caution

The #why-wireguard-with-netbird anchor doesn't resolve — the heading
slugifies to #why-wire-guard-with-net-bird (decamelized). Fix it in the
networks intro and the netbird-vs-traditional-vpn self-link.

Clarify the NB_ENABLE_LOCAL_FORWARDING caution: with it on, any permitted
peer can reach services bound to the routing peer's own addresses,
including 127.0.0.1, at the peer's NetBird IP.

* docs: polish routing-peer and Active Directory guides

- Correct the DC policy note: TCP/UDP need separate policies because a
  policy carries one protocol, not because of a first-rule limitation
- Make internal-dns-servers the canonical A/AAAA-vs-SRV explanation;
  collapse the three duplicates to one-line pointers
- Trim emphatic bold to enumerated requirements, ports, and flags
- Reduce em-dash density and clarify the routing-peer SSH-management
  and HA cautions in the AD guide

* docs: make Active Directory guide clearer for junior admins

- Rewrite the Verify section to explain why (test as the signed-in
  domain user, port 445 vs ping, name vs IP) instead of assuming
  ICMP/Kerberos/NTLM knowledge
- Clarify the SSH-management and HA cautions in Step 3
- Note Get-DfsnFolderTarget needs the DFS Management tools (RSAT),
  not just any domain-joined machine
- Reduce em-dash density throughout

* docs: Routing Peer DNS Resolution applies to all domain resources, not just wildcards

* docs: refine Active Directory guide and nameserver terminology

- Step 3 DC ports as a Port/Protocol/Needed-for table; promote 123
  (time sync) and 464 (kpasswd) into the baseline
- DFS step: derive each target server's FQDN for the domain resource
- order the agent-placement and reachability shapes consistently
  (dedicated routing peer first)
- drop the niche SSH-wedge caution and the premature masquerade note
- tie the ping/ICMP caveat to the port-scoped policies
- use "Nameserver" + "match domain" (the UI term) instead of
  "nameserver group" across the AD, internal-DNS, and reach-services pages

* docs: scope the local-forwarding caution — loopback exposure is netstack-only

Reaching the routing peer's own 127.0.0.1-bound services via its NetBird IP
only happens on netstack-mode peers; on userspace-TUN (Windows/macOS) it does
not (verified), and Linux kernel mode is a no-op. The general "exposes own
addresses" caution stands; drop the over-broad 127.0.0.1/localhost specifics.

* docs: trim DC-through-routing-peer section to the DNS-only reason and reorder AD subsections

Drop the setup-flavored framing from 'Reaching a Domain Controller
through a routing peer' (it lives on the AD use-case page), keeping the
DNS reference fact: A/AAAA resolves on the routing peer but SRV/DC-locator
records don't, so AD still needs a nameserver to the DC. Heading text is
unchanged so the existing anchor still resolves. Reorder the AD & Domain
Controllers subsections to lead with the recommended case (reach the DC
through a separate routing peer), then the discouraged DC-as-routing-peer
path, then its WireGuard port-conflict troubleshooting.

* docs: drop redundant cross-link from AD Step 4 nameserver note

The note already explains why a domain resource doesn't remove the
nameserver requirement (SRV/DC-locator records). The trailing link to the
DNS page's 'Reaching a Domain Controller through a routing peer' section
just repeated that fact and linked back here, bouncing the reader. Step 4
already links to Internal DNS Servers for the general setup.

* docs: restructure AD routing-peer guidance — least-privilege tiers, DC route/policy split, de-loop cross-links

Active Directory & Windows File Shares:
- Add a TL;DR linking to a new 'The four settings' checklist at the bottom.
- Split Step 3 into Step 3 (route the DC) and Step 4 (allow the AD ports);
  DNS becomes Step 5. Keeps the route distinct from the access policies.
- Step 2: break each routing-peer case into sub-bullets of what's needed;
  point the self-access case to Reach Services on the Routing Peer.
- Step 3: present /32 or apex domain as the granular default and the
  *.corp.example.com wildcard as the least-privilege opt-in — and spell out
  the wildcard's one-policy-scope cost (uniform ports across the whole domain).

Reach Services on the Routing Peer:
- Tighten the setup steps; concrete DNS-nameserver instruction for AD/DFS;
  state the Linux kernel-mode default for NB_ENABLE_LOCAL_FORWARDING.
- 'recipe' -> 'setup' throughout.

Internal DNS Servers:
- Clarify nameserver vs plain share: A/AAAA via the routing peer needs no
  nameserver; AD needs one for SRV records and because the resolver won't
  fall back. Distribute the nameserver to the routing peer's group *and*
  client groups that resolve directly; only when the peer can't resolve on
  its own. Reorder AD subsections; fix the overbroad distribution note.

How Routing Peers Work / cross-links:
- Remove redundant/circular cross-links across the four pages (the
  HRPW -> Internal DNS -> Active Directory -> HRPW loop).

* docs: use "NetBird client"/"clientless" wording in AD and self-access guides

Replace 'the agent'/'agentless' with the preferred 'NetBird client'/'clientless' terms, and add the missing blank line before the Step 2 heading.

* docs: lower altitude of routing-peer/AD guides for junior admins

- Unify the overlay address as 'NetBird IP' and the local one as 'LAN IP' across the routing-peer/DNS pages; add a 2-line two-address primer to the two crux pages.
- Replace the dense userspace/netstack/kernel forwarding sentence with a platform table framed to the self-access case, plus a netstack-override footnote.
- Demote the wildcard policy-scope trade-off in the AD guide to a Note, keeping the granular-first nudge in the main flow.
- Split the 'Reaching a DC through a routing peer' paragraph into what-it-needs / why-a-domain-resource-isn't-enough bullets.
- De-duplicate the self-access section: it now owns the mental model and points to the use-case page for the concrete setup.

* docs: clarify the forwarding section for junior admins

- Disambiguate NB_ENABLE_LOCAL_FORWARDING from the IP-forwarding sysctl by naming the setting explicitly before the table.
- Split local forwarding into its own '### Local forwarding' subheading, distinct from '### IP forwarding'; repoint the #local-forwarding cross-link.
- Drop the netstack-specific override footnote — edge-case reference material that doesn't help the target reader (the row already names the correct flag).

* docs: apply review feedback to routing-peer/AD guides

- AD Step 4: list the AD ports per TCP/UDP access control policy instead of a dense one-rule-per-policy sentence; add 123 to the four-settings recap.
- De-duplicate the route+policy+local-forwarding triad within how-routing-peers-work (Local forwarding now points to the canonical statement); render the LAN-IP requirements as a sub-list.
- Plain-language rewrite of why a domain resource isn't enough for AD DNS.
- Qualify Global Catalog 3268/3269 to multi-domain forests; state the default branch in AD Step 1.
- Fix the Networks Tiles description to say 'NetBird client', not 'agent'.
- Add DNS troubleshooting Issue 7 for the AD symptom (login/DFS fails but file-by-IP works), cross-linked to the AD guide and the DC section.

* docs: recast AD "four settings" as an explicit NetBird config checklist

Rename the summary to 'What you configure in NetBird' and list the discrete NetBird objects: routing peer, a route (resource) to the file server and to the DC, separate access control policies for each, and a DNS nameserver. Keep the full AD port set in Step 4 only; update the TL;DR link to the new (decamelized) anchor.

* docs: clarify the self-access setup steps

- Identify NB_ENABLE_LOCAL_FORWARDING as an environment variable and link the Client Environment Variables reference.
- Front-load the platform on step 3 (Windows/macOS need the flag; Linux kernel forwarding doesn't, only netstack) and soften the 'all three required' framing accordingly.
- Explain that steps 1 and 3 exist only because clients reach the file server at its LAN IP; reaching a peer at its NetBird IP needs only the policy.
2026-06-19 16:23:49 +02:00
..
2025-11-21 11:24:17 +01:00
2023-05-03 19:00:56 +02:00
2023-05-03 19:00:56 +02:00
2026-01-27 12:29:05 +01:00
2026-02-02 17:33:09 +01:00