Hi,
we’ve set up two routing peers and a Dashboard/Server VM in our Datacenter Network.
On RP1 and RP2, the NetBird client is installed directly via apt.
On the Dashboard/Server, NetBird runs as a Docker container.
We are using the latest version as of today. Client 0.77.1, Dashboard/Server: 2.91.1
These are protected by a pfSense 2.8.1. No IDS/IPS or similar in place, just plain port forwarding and firewall rules.
I have set up port forwarding to the routing peers: 50280 → RP1, 50281 → RP2
Also, an Outbound NAT for RP1 and RP2 with static Port enabled.
RP1 and RP2 are set to Masquerading.
80, 443, and 3278 are forwarded and allowed from any to the Dashboard/Server instance in pfSense.
On the other side, there are peers in akamai/linode cloud as containers in Kubernetes. The image used is netbird:0.77.1.
Since Kubernetes uses port 50280 internally, we set the peers to 50281 and opened up the local firewalls.
When we start the netbird-client, all the peers connect via P2P.
We checked with netbird status -d
They also stay connected via P2P as long as there is no traffic flow.
Once we start sending traffic from the Akamai peers to a server in our DC, the connection fails over to relayed after some time, and the speed drops dramatically.
When this happens, we see these log lines on the Akamai peers.
2026-08-25T08:53:35.263Z INFO [peer: peerid] client/internal/peer/conn.go:436: set ICE to active connection
2026-08-25T08:55:07.451Z INFO [peer: peerid] client/internal/peer/conn.go:436: set ICE to active connection
2026-08-25T08:54:35.541Z INFO [peer: peerid2] client/internal/peer/conn.go:436: set ICE to active connection
2026-08-25T08:54:36.358Z INFO [peer: peerid] client/internal/peer/conn.go:436: set ICE to active connection
2026-08-25T08:54:06.224Z INFO [peer: peerid] client/internal/peer/conn.go:436: set ICE to active connection
2026-08-25T09:03:34.214Z INFO [peer: peerid2] client/internal/peer/state_dump.go:79: Dump stat: Status: Connected, SentOffer: 1, RemoteOffer: 0, RemoteAnswer: 1, RemoteCandidate: 2, P2PConnected: 1, SwitchToRelay: 0, WGCheckSuccess: 4, RelayConnected: 1, LocalProxies: 1
2026-08-25T09:03:34.214Z INFO [peer: peerid] client/internal/peer/state_dump.go:79: Dump stat: Status: Connected, SentOffer: 1, RemoteOffer: 1, RemoteAnswer: 1, RemoteCandidate: 2, P2PConnected: 1, SwitchToRelay: 0, WGCheckSuccess: 4, RelayConnected: 1, LocalProxies: 1
2026-08-25T09:03:50.749Z INFO [peer: peerid2] client/internal/peer/conn.go:513: ICE disconnected, set Relay to active connection
2026-08-25T09:03:51.475Z INFO [peer: peerid] client/internal/peer/conn.go:513: ICE disconnected, set Relay to active connection
2026-08-25T09:03:52.396Z INFO [peer: peerid2] client/internal/peer/conn.go:513: ICE disconnected, set Relay to active connection
2026-08-25T09:03:52.559Z INFO [peer: peerid] client/internal/peer/conn.go:513: ICE disconnected, set Relay to active connection
2026-08-25T09:03:52.720Z INFO [peer: peerid] client/internal/peer/conn.go:513: ICE disconnected, set Relay to active connection
2026-08-25T09:03:53.392Z INFO [peer: peerid2] client/internal/peer/conn.go:513: ICE disconnected, set Relay to active connection
2026-08-25T09:03:53.538Z INFO [peer: peerid2] client/internal/peer/conn.go:513: ICE disconnected, set Relay to active connection
2026-08-25T09:03:53.578Z INFO [peer: peerid] client/internal/peer/conn.go:513: ICE disconnected, set Relay to active connection
2026-08-25T09:04:05.189Z INFO [peer: peerid2] client/internal/peer/state_dump.go:79: Dump stat: Status: Connected, SentOffer: 1, RemoteOffer: 1, RemoteAnswer: 1, RemoteCandidate: 4, P2PConnected: 1, SwitchToRelay: 1, WGCheckSuccess: 4, RelayConnected: 1, LocalProxies: 1
2026-08-25T09:04:05.189Z INFO [peer: peerid] client/internal/peer/state_dump.go:79: Dump stat: Status: Connected, SentOffer: 1, RemoteOffer: 1, RemoteAnswer: 1, RemoteCandidate: 4, P2PConnected: 1, SwitchToRelay: 1, WGCheckSuccess: 4, RelayConnected: 1, LocalProxies: 1
2026-08-25T09:04:35.317Z INFO [peer: peerid2] client/internal/peer/state_dump.go:79: Dump stat: Status: Connected, SentOffer: 2, RemoteOffer: 2, RemoteAnswer: 2, RemoteCandidate: 8, P2PConnected: 1, SwitchToRelay: 1, WGCheckSuccess: 5, RelayConnected: 1, LocalProxies: 1
2026-08-25T09:04:35.317Z INFO [peer: peerid] client/internal/peer/state_dump.go:79: Dump stat: Status: Connected, SentOffer: 3, RemoteOffer: 1, RemoteAnswer: 3, RemoteCandidate: 8, P2PConnected: 1, SwitchToRelay: 1, WGCheckSuccess: 5, RelayConnected: 1, LocalProxies: 1
2026-08-25T09:05:06.418Z INFO [peer: peerid] client/internal/peer/state_dump.go:79: Dump stat: Status: Connected, SentOffer: 2, RemoteOffer: 2, RemoteAnswer: 2, RemoteCandidate: 8, P2PConnected: 1, SwitchToRelay: 1, WGCheckSuccess: 4, RelayConnected: 1, LocalProxies: 1
2026-08-25T09:05:06.419Z INFO [peer: peerid2] client/internal/peer/state_dump.go:79: Dump stat: Status: Connected, SentOffer: 2, RemoteOffer: 2, RemoteAnswer: 2, RemoteCandidate: 8, P2PConnected: 1, SwitchToRelay: 1, WGCheckSuccess: 4, RelayConnected: 1, LocalProxies: 1
2026-08-25T09:05:27.863Z INFO [peer: peerid] client/internal/peer/guard/ice_retry_state.go:52: ICE retries exhausted (3/3), switching to hourly retry
2026-08-25T09:05:44.976Z INFO [peer: peerid2] client/internal/peer/guard/ice_retry_state.go:52: ICE retries exhausted (3/3), switching to hourly retry
2026-08-25T09:05:45.218Z INFO [peer: peerid2] client/internal/peer/guard/ice_retry_state.go:52: ICE retries exhausted (3/3), switching to hourly retry
Any advice is welcome.