
NetBird is an open-source peer-to-peer VPN platform that enables secure private networking across distributed infrastructure. It builds encrypted mesh networks using WireGuard tunnels, allowing seamless, low-latency connections between nodes without manual firewall configuration or port forwarding.
In this guide, you'll learn how to self-host the NetBird control plane on a Vultr instance and connect peers across different regions using setup keys (recommended) or a browser-based login flow. By the end, you'll have a functional mesh network with traffic routed through a designated exit node for secure, centralized egress control.
Before you begin, ensure you have the following resources provisioned:
Vultr DEL instanceThis section walks you through the process of self-hosting a NetBird control plane on a publicly accessible Vultr instance deployed in India. In this setup, you will use a single-line script to deploy the entire stack, including the management service, signal server, TURN/STUN server, and a default identity provider (Zitadel).
At the end of this section, you will have a running NetBird instance accessible via your domain over HTTPS.
Allow the following ports required by NetBird for control plane, TURN, management, and user traffic.
Set up Docker's apt repository.
Install Docker Engine, Compose plugin, and utilities.
Enable and start the Docker service.
Allow your user to run Docker without sudo.
If docker still requires sudo, log out and back in to apply the group change.
Verify the Compose plugin is available.
Export your domain name and run the NetBird installation script. Replace example.com with your actual domain, and ensure the domain's A record points to your server’s public IP address.
If you prefer to inspect the script before running it, download and review it locally:
Once the script completes, the NetBird management interface is accessible at:
Use the credentials printed in your terminal to log in to the dashboard and begin adding peers to your mesh network.
Do not close your terminal before copying the setup key and credentials. These values are only shown once during installation.
The recommended way to add servers and headless machines is to use setup keys. Setup keys are pre-authorized tokens that let peers join automatically without interactive login. See the NetBird Setup Keys documentation for more details.
In the Admin Panel, go to Setup Keys and click Create Setup Key. Give it a name (for example, "vultr-servers"), set usage limits as needed, and copy the key value.
On each peer, install the NetBird client.
Register the peer with your self-hosted URLs and the setup key.
In the Admin Panel, the peer will appear automatically. Rename each to something identifiable (for example, vultr-ams and vultr-atl) and assign them to groups as needed.
Navigate to the Peers tab in the Admin Panel.
You should see both vultr-ams and vultr-atl listed as online.
Click each to view their assigned 100.x.x.x mesh IP addresses.
Confirm that both peers can ping each other over the private network.
This completes the addition of two cloud-hosted peers in different regions.
In this section, we’ll configure the vultr-ams instance as an exit node and route all traffic from the vultr-atl instance through it. This is useful for scenarios where you want to route outbound traffic through a central region for auditing, egress control, or geo-IP masking.
Navigate to the Peers tab in the NetBird Admin Panel.
Click on the peer named vultr-ams to open its detail view.
Scroll down and click Set Up Exit Node.
Set an identifier such as ams-exit.
In the Distribution Groups dropdown, select or create a group that will include the vultr-atl node (e.g., atlanta-nodes).
Click Save Changes to apply the configuration.
NetBird will now route all traffic from peers in the atlanta-nodes group through the vultr-ams instance.
In the Peers view, click on vultr-atl.
Assign it to the atlanta-nodes group.
Confirm that it appears in the list of peers using vultr-ams as an exit node.
To confirm that traffic from vultr-atl is correctly routed through the vultr-ams exit node, follow the steps below on the AMS-based instance (vultr-ams), which is now acting as the exit node.
Enable IP forwarding.
Add a MASQUERADE rule to NAT outbound traffic via the correct network interface.
Confirm IP forwarding is enabled.
Monitor traffic routed through this peer.
This command displays a live counter of packets hitting the MASQUERADE rule. You should see the packet count and byte count increase as traffic from the vultr-atl instance flows through the exit node.
If the packet count does not increase, confirm that the vultr-atl peer is set to use vultr-ams as its exit node, and ensure that firewall rules or network settings on both sides are not blocking outbound connections.
In this guide, you deployed a self-hosted NetBird control plane on a Vultr instance and created a secure mesh network across multiple regions. You added peers using setup keys, optionally tested the browser-based flow, designated an exit node for outbound traffic routing, and verified connectivity. This configuration enables secure, scalable private networking ideal for multi-region deployments, remote access, and modern application infrastructures.
0 Comments
Be the first to comment and share your perspective with the community.