Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Connection overview #3122

Open
M0nk3yOo opened this issue Dec 29, 2024 · 5 comments
Open

Connection overview #3122

M0nk3yOo opened this issue Dec 29, 2024 · 5 comments

Comments

@M0nk3yOo
Copy link

M0nk3yOo commented Dec 29, 2024

Is your feature request related to a problem? Please describe.
No

Describe the solution you'd like
Add additional information to the activity log.
Which client tries to reach which resource, with which port (+ routing path). Log could looks like:
image

This should show an administrator more advanced logs for troubleshooting/overview.
Allowed and blocked connection would be useful. This overview should also validate the expected (client) configuration

Additional context
Used platform: selfhosted

@Gauss23
Copy link

Gauss23 commented Dec 30, 2024

I don't know if this is really in the sense of the idea of Netbird. The clients/peers would need to send those metrics to the central management server. When possible Netbird routes traffic directly between the peers, so the management server does not see this traffic at all. And even in relayed mode it only sees that there is traffic flowing from A to B but not the content of the traffic and therefore no ports etc. It would add a lot of cpu load and data which would need to be stored and computed.

What you are suggesting is an approach like Zscaler PIA or ZPA, where Zscaler knows all the traffic.
Technically I would think it's possible, but is this the idea behind Netbird? One is based on privacy and the other one is based on complete observation.

@M0nk3yOo
Copy link
Author

Thanks a lot for your detailed explanation!
I'm currently testing Netbird as a ZTNA. And yes, it makes sense that the management couldn't see the traffic (the sense behind VPN, without man in the middle).
So, if I need additional information, I could/should use the agent debug logs, couldn't I?

@Gauss23
Copy link

Gauss23 commented Dec 31, 2024

Yes that's an option or add a free XDR tool like Wazuh or Security Onion to your environment.

@M0nk3yOo
Copy link
Author

Wazuh might be an option, but those integrations aren't available on self hosted environments :-(
https://docs.netbird.io/how-to/activity-event-streaming

In addition: there seems no 3rd party SIEM integration available in the settings

@Gauss23
Copy link

Gauss23 commented Dec 31, 2024

Sorry, I meant not integrated with Netbird, but as a general tool for your environment with agents on all clients. It would cover all traffic your clients are generating, not only the Netbird connections and traffic.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants