WZ-IT Logo

What Is NetBird? Zero-Trust Mesh VPN for Secure Infrastructure Access

Timo WevelsiepTimo Wevelsiep•Updated: 02.09.2026

Editorial note: Versions, commands and prices may change. Please verify critical steps independently before production use. This guide does not replace individual consulting.

NetBird is an open-source platform for identity-based network access. It connects devices, servers and sites through encrypted WireGuard connections in a private overlay network. A central control plane manages peers, routes and access policies. Traffic flows directly between devices where possible and otherwise through an encrypted relay service. Connected sites do not require inbound port forwarding.

NetBird can be self-hosted or used as NetBird Cloud. Unlike a traditional VPN gateway, users and devices do not automatically gain access to the entire network: policies expose only the resources they need.

Introducing NetBird or looking for ongoing operations? Managed NetBird includes the control plane, agreed relays, monitoring, updates, backups and support from €349.90 excluding VAT monthly. An existing access solution can be replaced through the VPN migration sprint.

Table of Contents


How NetBird works

NetBird cleanly separates the control plane from the data plane. The control plane consists of three server components (docs.netbird.io):

  • Management service: the central coordinator. It keeps the network state, manages the peers' public WireGuard keys, authenticates them and distributes configuration and access rules into the mesh.
  • Signal service: handles peer discovery and connection negotiation. Peers exchange their connection candidates (ICE) through Signal; the messages are end-to-end encrypted, and Signal "steps out" once the direct connection is up.
  • Relay service: a TURN-style fallback that relays traffic when a direct connection is impossible. Because the WireGuard traffic is point-to-point encrypted, the relay cannot decrypt the data.

The data plane is WireGuard. For NAT traversal NetBird uses ICE (Pion implementation) and STUN to establish a direct peer-to-peer connection wherever possible; only when that fails does the tunnel run through the relay. All peers establish the connection outbound-only, so no port has to be reachable from the internet. More on the data plane in our WireGuard expertise and in the guide WireGuard for site-to-site connectivity.

Zero trust: identity-based access

NetBird follows the zero-trust principle: nothing is reachable until a policy says so (default-deny). Access is not governed by network topology but by identity and policy:

  • Groups and access policies (ACLs): peers are assigned to groups, and policies grant targeted access from source to destination groups, optionally restricted to specific protocols and ports.
  • SSO and identity-provider integration: depending on the deployment, NetBird uses its integrated user management or a connected identity provider such as Keycloak, Authentik or Microsoft Entra ID. MFA is implemented through the selected identity system.
  • Device checks and approvals: depending on edition and configuration, access can also be tied to device attributes or approval workflows.
  • NetBird SSH: the integrated SSH access can bind sessions to authenticated identities. Permissions and logging must be configured accordingly.

This combination makes NetBird more than a VPN: it is an identity-based access layer. Background on our NetBird expertise.

Self-hosting, cloud and licensing

NetBird has two operating models. With self-hosting, you run the control plane and relay services on your own or commissioned infrastructure. NetBird Cloud is the vendor-operated SaaS service. Its Free, Team, Business and Enterprise plans should not be confused with the self-hosting licences.

For self-hosting, the public documentation distinguishes two relevant areas (official licence overview, as of September 2026):

  • The Community Edition can be self-hosted without a vendor licence or time limit. It covers core connectivity, access control and routing.
  • The paid self-hosting licence documented publicly as the Enterprise Commercial License adds active-active high availability, SCIM provisioning, EDR and MDM integrations, traffic-flow logging and vendor support, among other capabilities. NetBird provides commercial terms on request.

The suitable licence does not depend on device count alone. Availability, identity provisioning, device controls, logging and support are the more relevant criteria. As an official NetBird reseller, WZ-IT supports selection and procurement and verifies the vendor terms current at the time of order; vendor licensing, infrastructure and operations are itemised separately.

NetBird vs. Tailscale vs. Headscale vs. plain WireGuard

The main difference is the control plane. NetBird provides a self-hostable control plane, its own clients, a web dashboard and identity-provider integration. Tailscale operates its control plane as a service. Headscale is a separate community project for a self-hosted, Tailscale-compatible control plane. Plain WireGuard has no central user, device or policy management.

The detailed comparison of NetBird, Tailscale and WireGuard assesses operating model, identity, routing and typical use cases separately.

Access to infrastructure without open ports

A core use of NetBird is secure access to infrastructure: servers, internal services, databases and admin interfaces become reachable only through the encrypted mesh, never directly from the internet. This replaces open ports, jump hosts and bastion servers. Instead of exposing an SSH or database port, the server joins the mesh as a peer; it is reachable only for the identities permitted by policy.

In practice that means SSH without port exposure, database access only for defined groups, admin UIs behind default-deny. Combined with posture checks (for example only company-owned, up-to-date devices) and identity-aware SSH, you get traceable, identity-bound access - the basis for RBAC and audit for remote access.

Remote maintenance of distributed machines and plants

NetBird is widely used for remote maintenance of distributed machines, plants and IoT devices - as the network and backend layer. Every site is connected outbound-only, with no port to open on site. Two access patterns run on top:

  • Direct tool access: technicians reach SSH, RDP, VNC or an HMI on the plant directly over the mesh, as if they were on the local network.
  • Under a browser gateway: in sovereign platforms, a browser gateway such as Apache Guacamole sits on top of NetBird and delivers RDP, VNC and SSH clientless in the browser. NetBird is the invisible network backend, the gateway the auditable access layer. Details in What is Apache Guacamole? and Remote maintenance without a VPN client.

External access to Kubernetes services

The NetBird Kubernetes Operator adds selected cluster services to the private network declaratively. Routing peers run inside the cluster, while access policies determine which users or groups can reach the published resources. This means cluster APIs, dashboards and internal services do not have to be generally accessible from the internet.

The guide Access Kubernetes privately through NetBird explains the architecture in detail.

Exposing internal services in a controlled way: NetBird Networks

NetBird Networks can also connect devices and services that cannot run a NetBird client. Routing peers connect a private network to the mesh, while resources define individual IPs, networks or domains. Access policies then determine which identities may reach those destinations.

NetBird also offers a reverse-proxy function for public applications. Whether a private NetBird connection or a controlled public entry point is appropriate depends on the user group and protection requirements. Exposing internal services without a traditional VPN compares the options.

Sovereignty and how WZ-IT uses NetBird

NetBird is fully self-hostable and developed by NetBird GmbH in Berlin. With a self-hosted installation, control, configuration and operational data remain in the selected infrastructure. Whether the overall solution meets specific regulatory or internal requirements also depends on identity, permissions, logging, operating processes and infrastructure. The guide Remote access for NIS2 requirements covers these aspects separately. This article provides general information and is not legal advice.

At WZ-IT we use NetBird as the encrypted network backend of our remote-management and remote-maintenance platforms: sites connected outbound-only, access identity-based and default-deny, with an auditable browser gateway on top. The ABCO Water Systems case study shows how this runs in production for distributed plants in Australia. On request we handle design, build and operation end to end as part of our remote-management platforms.

Further guides

Sources

Want infrastructure reachable without open ports? Get to know us or take a look at our remote-management platforms.

Rather have it operated?

You'd rather not run Remote Access yourself? WZ-IT handles setup, operations and maintenance - privacy-focused from Germany.

Enquiry

Assess remote access and site connectivity

We design and operate controlled access for users, sites, clouds, Kubernetes, and distributed equipment.

How should we get back to you?

Frequently Asked Questions

Answers to the most important questions

NetBird is an open-source platform for identity-based network access. It connects devices, servers and sites through encrypted WireGuard connections in a private overlay network. A central control plane manages peers, routes and access policies. Traffic flows directly between devices where possible and otherwise through an encrypted relay service.

Yes. The self-hosted Community Edition can be used without a vendor licence or time limit and covers core connectivity, access control and routing. NetBird also offers a paid Enterprise Commercial License for self-hosting, including active-active high availability, SCIM, EDR and MDM integrations, traffic-flow logging and vendor support. Pricing is provided individually.

Both use WireGuard-based connections and a central coordination system. NetBird provides a self-hostable control plane and its own clients. Tailscale operates its control plane as a service; Headscale is a separate community project for a self-hosted, Tailscale-compatible control plane. The better fit depends on identity, routing, device count and operating model.

No. Every peer establishes the connection outbound-only. NetBird uses ICE/STUN to find a direct peer-to-peer route and only falls back to a relay server when needed. No port has to be reachable from the internet at the site, which significantly reduces the attack surface.

The NetBird Kubernetes Operator can deploy routing peers in the cluster and add selected internal services to the NetBird network as resources. Authorised users then reach cluster APIs, dashboards and internal services through the encrypted overlay without making them generally available on the internet.

Through NetBird Networks: a routing peer connects the private network to the mesh and makes defined resources such as individual IPs, CIDR ranges or domains available. Access policies determine which users or groups can reach these targets. A separate reverse-proxy function is available for public applications.

Yes. Management, signal and relay functions can run on your own or commissioned infrastructure. This keeps the control plane, configuration and operational data in the selected environment. Sizing and architecture depend on the number of peers, relay traffic, availability and required integrations.

Contact

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

Arrange a callback

Callback

Arrange a callback

Leave your number and we will call back — at the latest on the next business day.

For a longer conversation you can book an appointment instead.

Companies worldwide trust WZ-IT

  • ml&s
  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • nextGYM
  • SweetConnect GmbH
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy AG
  • Negosh
  • ABCO Water Systems
1/3 - Topic Selection33%

What is your inquiry about?

First select the service area that best matches your project.