DITCH your VPN - Connect to your Home Server from ANYWHERE
Read full transcript 25 segments
-
After building out my very own After building out my very own self-hosted cloud image backup servers, self-hosted cloud image backup servers, self-hosted cloud image backup servers, media servers, and much more, a critical media servers, and much more, a critical media servers, and much more, a critical component is actually connecting to my component is actually connecting to my component is actually connecting to my home lab home server from anywhere in home lab home server from anywhere in home lab home server from anywhere in the world with the same power and the world with the same power and the world with the same power and control as if I was sitting here right control as if I was sitting here right control as if I was sitting here right next to it. I could just open ports, but next to it. I could just open ports, but next to it. I could just open ports, but for critical things like my image server for critical things like my image server for critical things like my image server or any other services that are housing or any other services that are housing or any other services that are housing like really important data, that's like really important data, that's like really important data, that's that's not really something that I want that's not really something that I want that's not really something that I want to do. Now, recently Netbird reached out to do. Now, recently Netbird reached out to do. Now, recently Netbird reached out to me to check out their software. And to me to check out their software. And to me to check out their software. And no, this is not a sponsored video, but I no, this is not a sponsored video, but I no, this is not a sponsored video, but I do have direct communication with them, do have direct communication with them, do have direct communication with them, and there is maybe some potential of and there is maybe some potential of and there is maybe some potential of contract work in the future, so there is contract work in the future, so there is contract work in the future, so there is definitely going to be a bias there. And definitely going to be a bias there. And definitely going to be a bias there. And they're a company based out of Berlin, they're a company based out of Berlin, they're a company based out of Berlin, which is awesome. So many great open- which is awesome. So many great open- which is awesome. So many great open- source projects end up coming out of source projects end up coming out of source projects end up coming out of Berlin. I've even been there a few times Berlin. I've even been there a few times Berlin. I've even been there a few times covering NextCloud events. And oh boy, covering NextCloud events. And oh boy, covering NextCloud events. And oh boy, am I excited to go back. But probably am I excited to go back. But probably am I excited to go back. But probably the big thing for me with it is a the big thing for me with it is a the big thing for me with it is a majority of everything is completely majority of everything is completely majority of everything is completely open- source and it's completely open- source and it's completely open- source and it's completely self-hostable, including the self-hostable, including the self-hostable, including the controllers, even the management controllers, even the management controllers, even the management software, all that. And that is opposed software, all that. And that is opposed software, all that. And that is opposed to Twing, which isn't completely open to Twing, which isn't completely open to Twing, which isn't completely open sourced. And if you watch the channel, sourced. And if you watch the channel, sourced. And if you watch the channel, you know that's what I've been using for you know that's what I've been using for you know that's what I've been using for quite a while, but ever since trying out quite a while, but ever since trying out quite a while, but ever since trying out Netbird, it is definitely my go-to Netbird, it is definitely my go-to Netbird, it is definitely my go-to solution going forward. Now, I am solution going forward. Now, I am solution going forward. Now, I am getting a little ahead of myself. What getting a little ahead of myself. What getting a little ahead of myself. What is Netbird? Netbird is an overlay VPN is Netbird? Netbird is an overlay VPN is Netbird? Netbird is an overlay VPN designed to make secure peer-to-peer designed to make secure peer-to-peer designed to make secure peer-to-peer connectivity across devices, servers, connectivity across devices, servers, connectivity across devices, servers, networks, cloud environments super easy networks, cloud environments super easy networks, cloud environments super easy to use and set up. This isn't like Nord to use and set up. This isn't like Nord to use and set up. This isn't like Nord uh PIA or AirVPN that rely on
-
uh PIA or AirVPN that rely on uh PIA or AirVPN that rely on centralized servers. While those are centralized servers. While those are centralized servers. While those are great for if you are torrenting an great for if you are torrenting an great for if you are torrenting an Ubuntu ISO trying to hide your IP Ubuntu ISO trying to hide your IP Ubuntu ISO trying to hide your IP address or if you're switching your kind address or if you're switching your kind address or if you're switching your kind of virtual location to access some other of virtual location to access some other of virtual location to access some other country's services. Those are great use country's services. Those are great use country's services. Those are great use cases for that. But this is for secure cases for that. But this is for secure cases for that. But this is for secure connections to your infrastructure, connections to your infrastructure, connections to your infrastructure, whether that be an office server or even whether that be an office server or even whether that be an office server or even connecting like your mobile phone connecting like your mobile phone connecting like your mobile phone directly to your desktop computer. directly to your desktop computer. directly to your desktop computer. Netbird uses WireGuard's lightweight Netbird uses WireGuard's lightweight Netbird uses WireGuard's lightweight encryption to establish direct encrypted encryption to establish direct encrypted encryption to establish direct encrypted tunnels between devices or peers tunnels between devices or peers tunnels between devices or peers automatically. It eliminates manual automatically. It eliminates manual automatically. It eliminates manual configuration by handling tasks like IP configuration by handling tasks like IP configuration by handling tasks like IP assignment, NAT transversal, and assignment, NAT transversal, and assignment, NAT transversal, and connection negotiation through built-in connection negotiation through built-in connection negotiation through built-in signaling services via agents exchanging signaling services via agents exchanging signaling services via agents exchanging connection candidates, IPs, and ports to connection candidates, IPs, and ports to connection candidates, IPs, and ports to ping each other and allow you to work ping each other and allow you to work ping each other and allow you to work through basically any firewall. Plus, through basically any firewall. Plus, through basically any firewall. Plus, you can set up a various amount of you can set up a various amount of you can set up a various amount of single signon providers and multifactor single signon providers and multifactor single signon providers and multifactor authentication for added security. This authentication for added security. This authentication for added security. This in addition to DNS management and full in addition to DNS management and full in addition to DNS management and full access control. There are generally two access control. There are generally two access control. There are generally two ways to going about setting this up. And ways to going about setting this up. And ways to going about setting this up. And the first one is a full peer-to-peer the first one is a full peer-to-peer the first one is a full peer-to-peer mesh network. For this, what you do is mesh network. For this, what you do is mesh network. For this, what you do is you install Netbird on every device that you install Netbird on every device that you install Netbird on every device that you want to have connectivity. And then you want to have connectivity. And then you want to have connectivity. And then you could connect those peers directly you could connect those peers directly you could connect those peers directly to each other, creating the mesh to each other, creating the mesh to each other, creating the mesh network. You could do this with a bunch network. You could do this with a bunch network. You could do this with a bunch of devices on your home network or even of devices on your home network or even of devices on your home network or even remote devices can have that direct remote devices can have that direct remote devices can have that direct connectivity to each other. Another connectivity to each other. Another connectivity to each other. Another option is remote network access with option is remote network access with option is remote network access with NetBird networks because sometimes it's NetBird networks because sometimes it's NetBird networks because sometimes it's not actually feasible to install a not actually feasible to install a not actually feasible to install a NetBird pier on every single device kind
-
NetBird pier on every single device kind NetBird pier on every single device kind of like a printers, IoT devices, so on. of like a printers, IoT devices, so on. of like a printers, IoT devices, so on. In this case, you could set it up as a In this case, you could set it up as a In this case, you could set it up as a NetBird enabled connector on something NetBird enabled connector on something NetBird enabled connector on something like a Raspberry Pi, Proxmox, really like a Raspberry Pi, Proxmox, really like a Raspberry Pi, Proxmox, really whatever you'd like. And then this will whatever you'd like. And then this will whatever you'd like. And then this will act as a bridge allowing other devices act as a bridge allowing other devices act as a bridge allowing other devices in the network to securely access in the network to securely access in the network to securely access devices on your network that you allow devices on your network that you allow devices on your network that you allow it to whether that be individual devices it to whether that be individual devices it to whether that be individual devices or your entire subnet. In the middle of or your entire subnet. In the middle of or your entire subnet. In the middle of the diagram here we can see the the diagram here we can see the the diagram here we can see the coordination server is on the internet. coordination server is on the internet. coordination server is on the internet. Now, this is optional because if I Now, this is optional because if I Now, this is optional because if I wanted to, I could actually self-host wanted to, I could actually self-host wanted to, I could actually self-host that coordination server directly on my that coordination server directly on my that coordination server directly on my local machine, including all the local machine, including all the local machine, including all the management stuff, all that. Both the management stuff, all that. Both the management stuff, all that. Both the cloud and the self-hosted version cloud and the self-hosted version cloud and the self-hosted version include the core functionalities of the include the core functionalities of the include the core functionalities of the software, identity provider integration, software, identity provider integration, software, identity provider integration, multifactor authentication, access multifactor authentication, access multifactor authentication, access control networks, and more. But real control networks, and more. But real control networks, and more. But real quick, I'll talk about some of the quick, I'll talk about some of the quick, I'll talk about some of the benefits of just doing it through them benefits of just doing it through them benefits of just doing it through them directly. So, this right here is their directly. So, this right here is their directly. So, this right here is their website. And if I head over to pricing, website. And if I head over to pricing, website. And if I head over to pricing, we can see the free tier. So you can use we can see the free tier. So you can use we can see the free tier. So you can use their cloud completely for free for up their cloud completely for free for up their cloud completely for free for up to five users and 100 machines. And then to five users and 100 machines. And then to five users and 100 machines. And then if you want to start utilizing some of if you want to start utilizing some of if you want to start utilizing some of their business features, it will be $5 their business features, it will be $5 their business features, it will be $5 per user a month in which you could have per user a month in which you could have per user a month in which you could have unlimited users at that rate. And then unlimited users at that rate. And then unlimited users at that rate. And then they have a business plan with even more they have a business plan with even more they have a business plan with even more features. For their paid business features. For their paid business features. For their paid business features, a big standout is provisioning features, a big standout is provisioning features, a big standout is provisioning users and groups from an identity users and groups from an identity users and groups from an identity provider such as Google or Azure. This provider such as Google or Azure. This provider such as Google or Azure. This basically syncs users and groups from basically syncs users and groups from basically syncs users and groups from your identity provider into Netbird, your identity provider into Netbird, your identity provider into Netbird, automatically granting appropriate automatically granting appropriate automatically granting appropriate network access to specific users and network access to specific users and network access to specific users and groups and immediately revoking access groups and immediately revoking access groups and immediately revoking access if a employee happens to be departing.
-
if a employee happens to be departing. if a employee happens to be departing. Also, traffic event logging is a big one Also, traffic event logging is a big one Also, traffic event logging is a big one if you're giving a bunch of different if you're giving a bunch of different if you're giving a bunch of different people access to critical network people access to critical network people access to critical network infrastructure. And then there's infrastructure. And then there's infrastructure. And then there's features such as uh EDR integrations, features such as uh EDR integrations, features such as uh EDR integrations, peer approvals to join a network, user peer approvals to join a network, user peer approvals to join a network, user invites, event streaming to thirdparty invites, event streaming to thirdparty invites, event streaming to thirdparty platforms, and MSP functionality for platforms, and MSP functionality for platforms, and MSP functionality for managing multiple tenant networks from a managing multiple tenant networks from a managing multiple tenant networks from a single account. Using their cloud single account. Using their cloud single account. Using their cloud platform basically has no maintenance platform basically has no maintenance platform basically has no maintenance effort, which makes it incredibly effort, which makes it incredibly effort, which makes it incredibly convenient if you're just like an convenient if you're just like an convenient if you're just like an individual or a small group on their individual or a small group on their individual or a small group on their free plan or if you're managing like a free plan or if you're managing like a free plan or if you're managing like a larger business organization on their uh larger business organization on their uh larger business organization on their uh business plan. However, I do absolutely business plan. However, I do absolutely business plan. However, I do absolutely love that they have the option to love that they have the option to love that they have the option to self-host this. But for me personally, self-host this. But for me personally, self-host this. But for me personally, I'm probably just going to use their I'm probably just going to use their I'm probably just going to use their cloud-free tier because personally, when cloud-free tier because personally, when cloud-free tier because personally, when it comes to security stuff like this, I it comes to security stuff like this, I it comes to security stuff like this, I trust them a little bit more than myself trust them a little bit more than myself trust them a little bit more than myself to manage this. But regardless, at the to manage this. But regardless, at the to manage this. But regardless, at the end of this video, we're going to go end of this video, we're going to go end of this video, we're going to go into kind of a little demo and setup of into kind of a little demo and setup of into kind of a little demo and setup of the self-hosted instance just to check the self-hosted instance just to check the self-hosted instance just to check it out. So, from there, I'm going to it out. So, from there, I'm going to it out. So, from there, I'm going to dive onto the machine and just kind of dive onto the machine and just kind of dive onto the machine and just kind of go through the whole process of setting go through the whole process of setting go through the whole process of setting everything up from scratch. I've deleted everything up from scratch. I've deleted everything up from scratch. I've deleted everything, cleared my networks, so you everything, cleared my networks, so you everything, cleared my networks, so you could kind of see the entire process of could kind of see the entire process of could kind of see the entire process of everything. All right. So, what I'm everything. All right. So, what I'm everything. All right. So, what I'm going to do first, of course, is create going to do first, of course, is create going to do first, of course, is create an account here. So, I'm just going to an account here. So, I'm just going to an account here. So, I'm just going to click on get started. Here we have a few click on get started. Here we have a few click on get started. Here we have a few options. I'm going to just link this up options. I'm going to just link this up options. I'm going to just link this up to my GitHub. And then, just like that, to my GitHub. And then, just like that, to my GitHub. And then, just like that, we are in. So, the very first thing that we are in. So, the very first thing that we are in. So, the very first thing that we're going to do is generate a setup we're going to do is generate a setup we're going to do is generate a setup key. So, if we head over here, this is key. So, if we head over here, this is key. So, if we head over here, this is where we could go ahead and do that. So, where we could go ahead and do that. So, where we could go ahead and do that. So, let's create a setup key. This one, you let's create a setup key. This one, you let's create a setup key. This one, you call it whatever you want. I'm just call it whatever you want. I'm just call it whatever you want. I'm just going to call this one first setup. What going to call this one first setup. What going to call this one first setup. What I'm going to do here is I'm going to I'm going to do here is I'm going to I'm going to do here is I'm going to make this key reusable cuz I'm going to make this key reusable cuz I'm going to make this key reusable cuz I'm going to use it on three different machines. So, use it on three different machines. So, use it on three different machines. So, I'm going to set a usage limit to three.
-
I'm going to set a usage limit to three. I'm going to set a usage limit to three. We have a days expired. We have some We have a days expired. We have some We have a days expired. We have some security stuff here. So, if a peer is security stuff here. So, if a peer is security stuff here. So, if a peer is offline for more than 5 minutes, it just offline for more than 5 minutes, it just offline for more than 5 minutes, it just will completely remove it. And we have will completely remove it. And we have will completely remove it. And we have extra DNS labels, which I'm going to extra DNS labels, which I'm going to extra DNS labels, which I'm going to leave off for now. And we have groups leave off for now. And we have groups leave off for now. And we have groups here, but we're going to dive into that here, but we're going to dive into that here, but we're going to dive into that a lot more a little bit later. So, I'm a lot more a little bit later. So, I'm a lot more a little bit later. So, I'm just going to go ahead and click on just going to go ahead and click on just going to go ahead and click on create setup key. So, here is my key. create setup key. So, here is my key. create setup key. So, here is my key. I'm just going to give that a copy. And I'm just going to give that a copy. And I'm just going to give that a copy. And if I go ahead and click install Netbird if I go ahead and click install Netbird if I go ahead and click install Netbird here, we have a bunch of different here, we have a bunch of different here, we have a bunch of different options to get it installed. So, on options to get it installed. So, on options to get it installed. So, on Linux, we just simply run a single line Linux, we just simply run a single line Linux, we just simply run a single line command. it uh launches a script to command. it uh launches a script to command. it uh launches a script to install everything for us. On Windows, install everything for us. On Windows, install everything for us. On Windows, they have an installer. Same with Mac. they have an installer. Same with Mac. they have an installer. Same with Mac. And then they have options for Docker. And then they have options for Docker. And then they have options for Docker. I'm going to be showing you both Linux I'm going to be showing you both Linux I'm going to be showing you both Linux and Docker real quick. The first pier and Docker real quick. The first pier and Docker real quick. The first pier that I want to set up is going to be that I want to set up is going to be that I want to set up is going to be Proxmox. And you can install this either Proxmox. And you can install this either Proxmox. And you can install this either in an LXC VM or just directly on host, in an LXC VM or just directly on host, in an LXC VM or just directly on host, which is what I'm going to do. So, I'm which is what I'm going to do. So, I'm which is what I'm going to do. So, I'm going to select my node right here and going to select my node right here and going to select my node right here and then go to the shell. And then to then go to the shell. And then to then go to the shell. And then to install it, we just paste in that single install it, we just paste in that single install it, we just paste in that single curl command which will pull the setup curl command which will pull the setup curl command which will pull the setup script. So we could hit enter and then script. So we could hit enter and then script. So we could hit enter and then it's going to go ahead and install it it's going to go ahead and install it it's going to go ahead and install it for us as well as adding the repository for us as well as adding the repository for us as well as adding the repository and all that of course. And just like and all that of course. And just like and all that of course. And just like that, it's done. You can see it's been that, it's done. You can see it's been that, it's done. You can see it's been started. It's running. It's linked up started. It's running. It's linked up started. It's running. It's linked up with uh systemctl. And before I connect, with uh systemctl. And before I connect, with uh systemctl. And before I connect, if we go over here, we could see peers.
-
if we go over here, we could see peers. if we go over here, we could see peers. Currently, there are no peers. But if I Currently, there are no peers. But if I Currently, there are no peers. But if I head back over to Proxmox and I just run head back over to Proxmox and I just run head back over to Proxmox and I just run the command netb bird up- k for our the command netb bird up- k for our the command netb bird up- k for our setup key and then drop it on in there, setup key and then drop it on in there, setup key and then drop it on in there, hit enter. Boom, it's connected. Just hit enter. Boom, it's connected. Just hit enter. Boom, it's connected. Just like that. And we will immediately see like that. And we will immediately see like that. And we will immediately see the peers. If we go over here, give this the peers. If we go over here, give this the peers. If we go over here, give this a quick little refresh. You can see we a quick little refresh. You can see we a quick little refresh. You can see we have our pier right here. So then I have our pier right here. So then I have our pier right here. So then I could customize this a little bit if I could customize this a little bit if I could customize this a little bit if I wanted to. I could open it up. We could wanted to. I could open it up. We could wanted to. I could open it up. We could see a lot of information. So we have the see a lot of information. So we have the see a lot of information. So we have the netb bird IP address, which we could use netb bird IP address, which we could use netb bird IP address, which we could use that for direct peer-to-peer connection. that for direct peer-to-peer connection. that for direct peer-to-peer connection. You can use domain names. So, the You can use domain names. So, the You can use domain names. So, the default is netbird.cloud. That's another default is netbird.cloud. That's another default is netbird.cloud. That's another thing you could change if you'd like to. thing you could change if you'd like to. thing you could change if you'd like to. And of course, a lot of other system And of course, a lot of other system And of course, a lot of other system information groups. You can enable SSH information groups. You can enable SSH information groups. You can enable SSH access here if you would like to. And I access here if you would like to. And I access here if you would like to. And I don't really like NASCAR. I want to don't really like NASCAR. I want to don't really like NASCAR. I want to change that on my end through Proxmox, change that on my end through Proxmox, change that on my end through Proxmox, but I'm just going to call this PVE but I'm just going to call this PVE but I'm just going to call this PVE Proxmox virtual environment. So, now in Proxmox virtual environment. So, now in Proxmox virtual environment. So, now in peers, you could see right there, we got peers, you could see right there, we got peers, you could see right there, we got our little PVE pier set up. Now, I do our little PVE pier set up. Now, I do our little PVE pier set up. Now, I do want to set up another pier. This one is want to set up another pier. This one is want to set up another pier. This one is going to be on a little Raspberry Pi.
-
going to be on a little Raspberry Pi. going to be on a little Raspberry Pi. That Pi manages, well, it's going to That Pi manages, well, it's going to That Pi manages, well, it's going to manage our VPN connections. It also manage our VPN connections. It also manage our VPN connections. It also manages my network infrastructure. So, manages my network infrastructure. So, manages my network infrastructure. So, omada is installed on there as well as omada is installed on there as well as omada is installed on there as well as DDNS. So, right here, I already sshed DDNS. So, right here, I already sshed DDNS. So, right here, I already sshed into this machine. You can see it's the into this machine. You can see it's the into this machine. You can see it's the Raspberry Pi 5. This I'm going to set up Raspberry Pi 5. This I'm going to set up Raspberry Pi 5. This I'm going to set up with Docker. So, this machine I just with Docker. So, this machine I just with Docker. So, this machine I just have running a single Compose stack for have running a single Compose stack for have running a single Compose stack for everything. uh the through the setup everything. uh the through the setup everything. uh the through the setup there's a simple docker command that you there's a simple docker command that you there's a simple docker command that you can use but I personally prefer to set can use but I personally prefer to set can use but I personally prefer to set everything up in compose and I already everything up in compose and I already everything up in compose and I already kind of threw that in here you have my kind of threw that in here you have my kind of threw that in here you have my uh omata controller and then we have uh omata controller and then we have uh omata controller and then we have netb bird it's currently commented out netb bird it's currently commented out netb bird it's currently commented out so I will undo these comments real quick so I will undo these comments real quick so I will undo these comments real quick so for docker we just give it a so for docker we just give it a so for docker we just give it a container name we give it our host name container name we give it our host name container name we give it our host name which is going to be netb bird pi we cap which is going to be netb bird pi we cap which is going to be netb bird pi we cap add so we give it access to network add so we give it access to network add so we give it access to network system and system resources it's going system and system resources it's going system and system resources it's going to be the host or have access to the to be the host or have access to the to be the host or have access to the network host privileged is going to be network host privileged is going to be network host privileged is going to be true and then under environment from it. true and then under environment from it. true and then under environment from it. We have a place to put our setup key. We have a place to put our setup key. We have a place to put our setup key. And of course, we do have a volume for And of course, we do have a volume for And of course, we do have a volume for the client there in the image. So, all the client there in the image. So, all the client there in the image. So, all we really need to do is pop in our new we really need to do is pop in our new we really need to do is pop in our new setup key. Additionally, down here on setup key. Additionally, down here on setup key. Additionally, down here on the bottom, we're going to add the the bottom, we're going to add the the bottom, we're going to add the volumes for the netb bird client. And volumes for the netb bird client. And volumes for the netb bird client. And then we go to output that. Close out.
-
then we go to output that. Close out. then we go to output that. Close out. And now I should just be able to do a And now I should just be able to do a And now I should just be able to do a docker compose up-d. And you can see docker compose up-d. And you can see docker compose up-d. And you can see it's now pulling net creating those it's now pulling net creating those it's now pulling net creating those volumes. And everything's fired up. And volumes. And everything's fired up. And volumes. And everything's fired up. And we can check that by going to uh docker we can check that by going to uh docker we can check that by going to uh docker logs netbird pi. And we don't have any logs netbird pi. And we don't have any logs netbird pi. And we don't have any errors. So we should be good to go. If I errors. So we should be good to go. If I errors. So we should be good to go. If I go back over here to our peers, refresh go back over here to our peers, refresh go back over here to our peers, refresh that. Well, you look at that. We have that. Well, you look at that. We have that. Well, you look at that. We have netb bird pi set up now as a pier. And netb bird pi set up now as a pier. And netb bird pi set up now as a pier. And theoretically they're in a peer-to-peer theoretically they're in a peer-to-peer theoretically they're in a peer-to-peer mesh network. So if I copy this PVE mesh network. So if I copy this PVE mesh network. So if I copy this PVE right here or the IP address for the PVE right here or the IP address for the PVE right here or the IP address for the PVE up here, and then just do a simple ping up here, and then just do a simple ping up here, and then just do a simple ping of that server, it has a connection. And of that server, it has a connection. And of that server, it has a connection. And even though these two machines are even though these two machines are even though these two machines are local, it is a secure tunnneled local, it is a secure tunnneled local, it is a secure tunnneled connection with WireGuard. And now what connection with WireGuard. And now what connection with WireGuard. And now what we want to do is talk about networks and we want to do is talk about networks and we want to do is talk about networks and routing. So what we're going to do is routing. So what we're going to do is routing. So what we're going to do is head over here to networks and we're head over here to networks and we're head over here to networks and we're going to add a network. This is going to going to add a network. This is going to going to add a network. This is going to be my home network here. So we'll just be my home network here. So we'll just be my home network here. So we'll just call it that home network. And then call it that home network. And then call it that home network. And then click add network. Now here it's giving click add network. Now here it's giving click add network. Now here it's giving us the option to add resources. And us the option to add resources. And us the option to add resources. And we're going to go ahead and do that. So we're going to go ahead and do that. So we're going to go ahead and do that. So I'm going to add a resource. And for our I'm going to add a resource. And for our I'm going to add a resource. And for our very first resource, I am just going to very first resource, I am just going to very first resource, I am just going to call this our network subnet. And then call this our network subnet. And then call this our network subnet. And then we're going to give it the subnet IP we're going to give it the subnet IP we're going to give it the subnet IP address of 10 address of 10 address of 10 000. Obviously, change this if yours is 000. Obviously, change this if yours is 000. Obviously, change this if yours is a little bit different. -24. And then we a little bit different. -24. And then we a little bit different. -24. And then we have destination groups here. Now, have destination groups here. Now, have destination groups here. Now, again, I'm going to dive more into that again, I'm going to dive more into that again, I'm going to dive more into that in just a bit, but I might as well add in just a bit, but I might as well add in just a bit, but I might as well add it to a group. And I can call this like it to a group. And I can call this like it to a group. And I can call this like this is the subnet group. So, add this is the subnet group. So, add this is the subnet group. So, add subnet. Hit enter. And now we can click
-
subnet. Hit enter. And now we can click subnet. Hit enter. And now we can click on add resource. And it's giving us the on add resource. And it's giving us the on add resource. And it's giving us the option to add a policy, but I am going option to add a policy, but I am going option to add a policy, but I am going to do that a little bit later. So in to do that a little bit later. So in to do that a little bit later. So in this network, we need to add a routing this network, we need to add a routing this network, we need to add a routing pier. This again will route traffic from pier. This again will route traffic from pier. This again will route traffic from this netird pier to other devices on our this netird pier to other devices on our this netird pier to other devices on our network, allowing us to remote into the network, allowing us to remote into the network, allowing us to remote into the pier and then connect to other machines pier and then connect to other machines pier and then connect to other machines and other devices or other services that and other devices or other services that and other devices or other services that we're running such as like image, we're running such as like image, we're running such as like image, nextcloud, MB, whatever it may be. And nextcloud, MB, whatever it may be. And nextcloud, MB, whatever it may be. And since we added the subnet, we're going since we added the subnet, we're going since we added the subnet, we're going to be able to do that with our local IP to be able to do that with our local IP to be able to do that with our local IP addresses. So right here I'm just going addresses. So right here I'm just going addresses. So right here I'm just going to click on add routing pier. And here to click on add routing pier. And here to click on add routing pier. And here we have two options. We could either do we have two options. We could either do we have two options. We could either do routing peers or a peer group. So in routing peers or a peer group. So in routing peers or a peer group. So in peers you can assign various devices to peers you can assign various devices to peers you can assign various devices to a group. You can create a routing pier a group. You can create a routing pier a group. You can create a routing pier group and do it that way. But I'm just group and do it that way. But I'm just group and do it that way. But I'm just going to add the devices individually going to add the devices individually going to add the devices individually real quick. So we're going to do our net real quick. So we're going to do our net real quick. So we're going to do our net pi as one of them and then hit continue. pi as one of them and then hit continue. pi as one of them and then hit continue. We're going to enable as a routing pier We're going to enable as a routing pier We're going to enable as a routing pier and we're going to allow access to our and we're going to allow access to our and we're going to allow access to our private networks without configuring private networks without configuring private networks without configuring routes on our network or other devices. routes on our network or other devices. routes on our network or other devices. And then we have our metrics here which And then we have our metrics here which And then we have our metrics here which this is a priority number. So the lower this is a priority number. So the lower this is a priority number. So the lower the number, the higher priority that the number, the higher priority that the number, the higher priority that routing pier will have. But let's just routing pier will have. But let's just routing pier will have. But let's just go ahead and click on add routing pier.
-
go ahead and click on add routing pier. go ahead and click on add routing pier. So just like that, you could see the So just like that, you could see the So just like that, you could see the network is now online and accessible. I network is now online and accessible. I network is now online and accessible. I do have one pier. It says the uh high do have one pier. It says the uh high do have one pier. It says the uh high availability is currently inactive. And availability is currently inactive. And availability is currently inactive. And that's another thing that we might as that's another thing that we might as that's another thing that we might as well just do real quick. Let's say this well just do real quick. Let's say this well just do real quick. Let's say this Raspberry Pi for some reason gets Raspberry Pi for some reason gets Raspberry Pi for some reason gets unplugged. It goes down. Setup like unplugged. It goes down. Setup like unplugged. It goes down. Setup like this. My home network would no longer be this. My home network would no longer be this. My home network would no longer be accessible. So you're going to want to accessible. So you're going to want to accessible. So you're going to want to put additional routing peers into this put additional routing peers into this put additional routing peers into this network. So if one goes down, another network. So if one goes down, another network. So if one goes down, another one can take over. And to do that, we one can take over. And to do that, we one can take over. And to do that, we just simply add another routing pier. In just simply add another routing pier. In just simply add another routing pier. In this case, I'm going to go with our this case, I'm going to go with our this case, I'm going to go with our Proxmox server. Continue. And let's say Proxmox server. Continue. And let's say Proxmox server. Continue. And let's say theoretically I wanted the Proxmox theoretically I wanted the Proxmox theoretically I wanted the Proxmox server to have higher priority. We can server to have higher priority. We can server to have higher priority. We can just change this to a lower number here. just change this to a lower number here. just change this to a lower number here. And then click on add routing pier. And And then click on add routing pier. And And then click on add routing pier. And just like that, you can see this turns just like that, you can see this turns just like that, you can see this turns green. And now high availability is now green. And now high availability is now green. And now high availability is now active. Now, in the most basic sense, active. Now, in the most basic sense, active. Now, in the most basic sense, this is set up and ready to go. So we this is set up and ready to go. So we this is set up and ready to go. So we might as well go ahead and test it. So, might as well go ahead and test it. So, might as well go ahead and test it. So, here I'm just going to grab this uh here I'm just going to grab this uh here I'm just going to grab this uh NetBird app real fast and disconnect NetBird app real fast and disconnect NetBird app real fast and disconnect from our Wi-Fi so we're no longer on from our Wi-Fi so we're no longer on from our Wi-Fi so we're no longer on that same network and open it up. Allow that same network and open it up. Allow that same network and open it up. Allow VPN configurations. When I go ahead and VPN configurations. When I go ahead and VPN configurations. When I go ahead and click on this to connect, it will prompt click on this to connect, it will prompt click on this to connect, it will prompt us with a login. So, I'm going to log us with a login. So, I'm going to log us with a login. So, I'm going to log into the same account. It's the default into the same account. It's the default into the same account. It's the default account, so it's the main admin account.
-
account, so it's the main admin account. account, so it's the main admin account. Hit done. And we should connect and we Hit done. And we should connect and we Hit done. And we should connect and we will or we should see the peers will or we should see the peers will or we should see the peers available when the connection is available when the connection is available when the connection is complete. So, there we go. We're complete. So, there we go. We're complete. So, there we go. We're connected. We have two peers available. connected. We have two peers available. connected. We have two peers available. So just as an example, if I connect So just as an example, if I connect So just as an example, if I connect directly to the NetBird IP address. So directly to the NetBird IP address. So directly to the NetBird IP address. So we'll pop that in and then go to my we'll pop that in and then go to my we'll pop that in and then go to my Proxmox port just like that. You can see Proxmox port just like that. You can see Proxmox port just like that. You can see it is working. So if we visit this it is working. So if we visit this it is working. So if we visit this website, that's just an SSL error. We website, that's just an SSL error. We website, that's just an SSL error. We can log into Proxmox and I'm not can log into Proxmox and I'm not can log into Proxmox and I'm not connected to my local network. Now real connected to my local network. Now real connected to my local network. Now real quick, I actually do want to add a quick, I actually do want to add a quick, I actually do want to add a policy real fast to this subnet. So if I policy real fast to this subnet. So if I policy real fast to this subnet. So if I go ahead and add a policy, I'm going to go ahead and add a policy, I'm going to go ahead and add a policy, I'm going to select the group all just for now. We select the group all just for now. We select the group all just for now. We will change this a little bit later to will change this a little bit later to will change this a little bit later to make it more secure. But if I add all make it more secure. But if I add all make it more secure. But if I add all which my admin user is a part of. We'll which my admin user is a part of. We'll which my admin user is a part of. We'll continue and add that policy. We should continue and add that policy. We should continue and add that policy. We should be able to connect to the local IP be able to connect to the local IP be able to connect to the local IP address now. So you can see address now. So you can see address now. So you can see 10818006. Let's go to that. And you can 10818006. Let's go to that. And you can 10818006. Let's go to that. And you can see it works. We're prompted to log in see it works. We're prompted to log in see it works. We're prompted to log in now because the whole subnet is open. We now because the whole subnet is open. We now because the whole subnet is open. We can access everything on this network.
-
can access everything on this network. can access everything on this network. So, if I go to my media server and then So, if I go to my media server and then So, if I go to my media server and then go to the MB port here, boop on HTTP, go to the MB port here, boop on HTTP, go to the MB port here, boop on HTTP, you can see we have access to MB now. you can see we have access to MB now. you can see we have access to MB now. So, we have a base setup. If all you So, we have a base setup. If all you So, we have a base setup. If all you want to do is spin up a pier and access want to do is spin up a pier and access want to do is spin up a pier and access your network as a single user, as the your network as a single user, as the your network as a single user, as the admin, we're good to go. But real quick, admin, we're good to go. But real quick, admin, we're good to go. But real quick, I want to go over one of my favorite use I want to go over one of my favorite use I want to go over one of my favorite use cases, and that is the peer-to-peer cases, and that is the peer-to-peer cases, and that is the peer-to-peer connections, especially connecting connections, especially connecting connections, especially connecting off-site machines to my uh local off-site machines to my uh local off-site machines to my uh local machines here. An example of that that I machines here. An example of that that I machines here. An example of that that I have is I have a um in a different have is I have a um in a different have is I have a um in a different off-site location I have an instance of off-site location I have an instance of off-site location I have an instance of Proxmox backup server. So here I Proxmox backup server. So here I Proxmox backup server. So here I connected to the Sonology machine just connected to the Sonology machine just connected to the Sonology machine just using the Sonology quick connect. Quick using the Sonology quick connect. Quick using the Sonology quick connect. Quick connect is super slow. It sucks. I'm not connect is super slow. It sucks. I'm not connect is super slow. It sucks. I'm not going to do it now. But spinning up a going to do it now. But spinning up a going to do it now. But spinning up a Net Bird Pier on Sonology is really Net Bird Pier on Sonology is really Net Bird Pier on Sonology is really easy. It's the exact same process with easy. It's the exact same process with easy. It's the exact same process with that single command except for you do that single command except for you do that single command except for you do need to set up a little script that will need to set up a little script that will need to set up a little script that will make sure that Netbird is running if make sure that Netbird is running if make sure that Netbird is running if your Sonology NAS restarts. But I'm just your Sonology NAS restarts. But I'm just your Sonology NAS restarts. But I'm just going to open up my virtual machine going to open up my virtual machine going to open up my virtual machine manager here. And we can see that we manager here. And we can see that we manager here. And we can see that we have Proxmox backup server running here.
-
have Proxmox backup server running here. have Proxmox backup server running here. I'm just going to connect to it real I'm just going to connect to it real I'm just going to connect to it real quick. And you can see I was testing quick. And you can see I was testing quick. And you can see I was testing this earlier. So I already have the this earlier. So I already have the this earlier. So I already have the package installed. But we need to package installed. But we need to package installed. But we need to reconnect to it with that uh new setup reconnect to it with that uh new setup reconnect to it with that uh new setup key. So netbird key. So netbird key. So netbird up- and unfortunately I can't copy and up- and unfortunately I can't copy and up- and unfortunately I can't copy and paste it in here. paste it in here. paste it in here. 5B 62. There we go. So, just like that, 5B 62. There we go. So, just like that, 5B 62. There we go. So, just like that, it should go ahead and Oh, I could cry. it should go ahead and Oh, I could cry. it should go ahead and Oh, I could cry. Oh, the last two numbers got me. 62. Oh, the last two numbers got me. 62. Oh, the last two numbers got me. 62. Enter. Connected. Yay. So, now if I head Enter. Connected. Yay. So, now if I head Enter. Connected. Yay. So, now if I head over here, go to peers, we should have over here, go to peers, we should have over here, go to peers, we should have the very new Proxmox backup server. Now, the very new Proxmox backup server. Now, the very new Proxmox backup server. Now, since that machine is offsite, I am since that machine is offsite, I am since that machine is offsite, I am quickly going to download this for the quickly going to download this for the quickly going to download this for the desktop I'm on. Run the quick desktop I'm on. Run the quick desktop I'm on. Run the quick installation wizard. And there we go. installation wizard. And there we go. installation wizard. And there we go. Netbird's installed. So, I'm going to Netbird's installed. So, I'm going to Netbird's installed. So, I'm going to close this out. Move it. And then right close this out. Move it. And then right close this out. Move it. And then right up here we got Netbird. So let's go up here we got Netbird. So let's go up here we got Netbird. So let's go ahead and click on connect and login ahead and click on connect and login ahead and click on connect and login successful. So now I should just be able successful. So now I should just be able successful. So now I should just be able to grab this IP address right here for to grab this IP address right here for to grab this IP address right here for Proxmox backup server. And then we can Proxmox backup server. And then we can Proxmox backup server. And then we can travel to it at the port travel to it at the port travel to it at the port 8007. I believe this is going to want 8007. I believe this is going to want 8007. I believe this is going to want HTTPS. Hey, will you look at that?
-
HTTPS. Hey, will you look at that? HTTPS. Hey, will you look at that? Absolutely beautiful. And boom, we're Absolutely beautiful. And boom, we're Absolutely beautiful. And boom, we're in. So real quick, I'm going to add this in. So real quick, I'm going to add this in. So real quick, I'm going to add this data store. Do note this isn't a Proxmox data store. Do note this isn't a Proxmox data store. Do note this isn't a Proxmox backup server type dedicated video. I backup server type dedicated video. I backup server type dedicated video. I will probably make that if you're will probably make that if you're will probably make that if you're interested. Do do subscribe. So, we got interested. Do do subscribe. So, we got interested. Do do subscribe. So, we got our remote PVE here and we have the our remote PVE here and we have the our remote PVE here and we have the actual Net Bird Pier installed both on actual Net Bird Pier installed both on actual Net Bird Pier installed both on this off-site backup server and locally this off-site backup server and locally this off-site backup server and locally on my Proxmox instance. Let's head over on my Proxmox instance. Let's head over on my Proxmox instance. Let's head over to data center and then storage. Add a to data center and then storage. Add a to data center and then storage. Add a new one. We're going to add a Proxmox new one. We're going to add a Proxmox new one. We're going to add a Proxmox backup server. I'm just going to call it backup server. I'm just going to call it backup server. I'm just going to call it remote. And for the server, again, I am remote. And for the server, again, I am remote. And for the server, again, I am just going to copy that Netbird IP just going to copy that Netbird IP just going to copy that Netbird IP address there. Drop it on in. fill in address there. Drop it on in. fill in address there. Drop it on in. fill in all of our credentials over on the all of our credentials over on the all of our credentials over on the backup server. Let's go dashboard. Show backup server. Let's go dashboard. Show backup server. Let's go dashboard. Show the fingerprint. Give that a copy. Drop the fingerprint. Give that a copy. Drop the fingerprint. Give that a copy. Drop it in right there. That's actually a it in right there. That's actually a it in right there. That's actually a PAM. And click add. And boom. There we PAM. And click add. And boom. There we PAM. And click add. And boom. There we go. We now have our remote Proxmox go. We now have our remote Proxmox go. We now have our remote Proxmox backup server right here. Connection backup server right here. Connection backup server right here. Connection successful. So now I will have secure successful. So now I will have secure successful. So now I will have secure safe offsite backup. Direct peer-to-peer safe offsite backup. Direct peer-to-peer safe offsite backup. Direct peer-to-peer connection like this is relatively easy connection like this is relatively easy connection like this is relatively easy to set up. It's when you get into to set up. It's when you get into to set up. It's when you get into setting up like clients, desktop mobile setting up like clients, desktop mobile setting up like clients, desktop mobile applications, and those are going to applications, and those are going to applications, and those are going to require specific like policies, require specific like policies, require specific like policies, networks, and things like that. So, now networks, and things like that. So, now networks, and things like that. So, now we are done with Proxmox and our we are done with Proxmox and our we are done with Proxmox and our peer-to-peer connections. You can also peer-to-peer connections. You can also peer-to-peer connections. You can also see here it added my uh iPhone as a see here it added my uh iPhone as a see here it added my uh iPhone as a client, which is pretty cool. But one client, which is pretty cool. But one client, which is pretty cool. But one thing I want to touch on, which is super thing I want to touch on, which is super thing I want to touch on, which is super cool, is going to be some of the DNS cool, is going to be some of the DNS cool, is going to be some of the DNS stuff. Now, there is a lot that you stuff. Now, there is a lot that you stuff. Now, there is a lot that you could do with this. I highly recommend could do with this. I highly recommend could do with this. I highly recommend you check out their documentation. It you check out their documentation. It you check out their documentation. It goes over some of the core concepts such
-
goes over some of the core concepts such goes over some of the core concepts such as the local name resolver, name as the local name resolver, name as the local name resolver, name servers, match domains, as well as a servers, match domains, as well as a servers, match domains, as well as a whole bunch of examples. But for my whole bunch of examples. But for my whole bunch of examples. But for my little example here, what I'm going to little example here, what I'm going to little example here, what I'm going to do is use my existing Pi Hole instance do is use my existing Pi Hole instance do is use my existing Pi Hole instance and use that as the DNS server on my and use that as the DNS server on my and use that as the DNS server on my NetBird networks. This is Pi Hole. If NetBird networks. This is Pi Hole. If NetBird networks. This is Pi Hole. If you don't know what it is, I'm not going you don't know what it is, I'm not going you don't know what it is, I'm not going to get too far into it. It's a uh DNS to get too far into it. It's a uh DNS to get too far into it. It's a uh DNS synhole that allows you to set up ad synhole that allows you to set up ad synhole that allows you to set up ad blocking and some other features such as blocking and some other features such as blocking and some other features such as local DNS. So, if I go over here, you local DNS. So, if I go over here, you local DNS. So, if I go over here, you can see I have a couple records. So, I can see I have a couple records. So, I can see I have a couple records. So, I could use these domains instead of IP could use these domains instead of IP could use these domains instead of IP addresses if I would like to. But over addresses if I would like to. But over addresses if I would like to. But over here on NetBird name servers, I'm just here on NetBird name servers, I'm just here on NetBird name servers, I'm just going to add a name server here. You going to add a name server here. You going to add a name server here. You have options. So, you could uh set up have options. So, you could uh set up have options. So, you could uh set up custom Google, Cloudflare, bunch of custom Google, Cloudflare, bunch of custom Google, Cloudflare, bunch of different options, including custom, different options, including custom, different options, including custom, which we're going to do. And the actual which we're going to do. And the actual which we're going to do. And the actual name server that I'm going to be using name server that I'm going to be using name server that I'm going to be using is 103. That's the uh instance that I is 103. That's the uh instance that I is 103. That's the uh instance that I have Pi Hole installed on. For the have Pi Hole installed on. For the have Pi Hole installed on. For the groups, for now, I'm just going to go groups, for now, I'm just going to go groups, for now, I'm just going to go with all and subnet. And then from there with all and subnet. And then from there with all and subnet. And then from there we have match domains which I'm not we have match domains which I'm not we have match domains which I'm not going to play with right now. Again do going to play with right now. Again do going to play with right now. Again do check out the documentation. And this is check out the documentation. And this is check out the documentation. And this is going to be my Pi Hole DNS. So we're going to be my Pi Hole DNS. So we're going to be my Pi Hole DNS. So we're going to add that name server. And just going to add that name server. And just going to add that name server. And just like that this is now acting as our DNS like that this is now acting as our DNS like that this is now acting as our DNS for Pi Hole. And you can see down here for Pi Hole. And you can see down here for Pi Hole. And you can see down here under the top permitted domains I have under the top permitted domains I have under the top permitted domains I have stun netbird uh turn net. I have been stun netbird uh turn net. I have been stun netbird uh turn net. I have been testing this. So you can see it is testing this. So you can see it is testing this. So you can see it is working as our DNS server. And another working as our DNS server. And another working as our DNS server. And another kind of cool thing is earlier I pointed kind of cool thing is earlier I pointed kind of cool thing is earlier I pointed out the DNS records. So for example, you out the DNS records. So for example, you out the DNS records. So for example, you could see here I am on MBI using the could see here I am on MBI using the could see here I am on MBI using the media.lan. So you can use locally hosted media.lan. So you can use locally hosted media.lan. So you can use locally hosted domain names or local DNS domains
-
domain names or local DNS domains domain names or local DNS domains instead of having to completely rely on instead of having to completely rely on instead of having to completely rely on either IP addresses or even over here either IP addresses or even over here either IP addresses or even over here some of the uh netird DNS stuff which we some of the uh netird DNS stuff which we some of the uh netird DNS stuff which we can see right here. So now we're going can see right here. So now we're going can see right here. So now we're going to get into users groups and access. to get into users groups and access. to get into users groups and access. Let's say theoretically you have Let's say theoretically you have Let's say theoretically you have somebody whether that be like a co-orker somebody whether that be like a co-orker somebody whether that be like a co-orker or a family member that you want to be or a family member that you want to be or a family member that you want to be able to connect to your network and able to connect to your network and able to connect to your network and access specific services without having access specific services without having access specific services without having like full subnet access like we set up like full subnet access like we set up like full subnet access like we set up earlier. That is very very doable and earlier. That is very very doable and earlier. That is very very doable and most of this stuff is going to be most of this stuff is going to be most of this stuff is going to be managed here in the access controls. You managed here in the access controls. You managed here in the access controls. You can see that uh subnet policy that we can see that uh subnet policy that we can see that uh subnet policy that we already created. All sources have access already created. All sources have access already created. All sources have access to the subnet and the default which is to the subnet and the default which is to the subnet and the default which is currently enabled. All is access to all. currently enabled. All is access to all. currently enabled. All is access to all. You start adding more people. You are You start adding more people. You are You start adding more people. You are going to want to disable this default going to want to disable this default going to want to disable this default policy and then customize your policies policy and then customize your policies policy and then customize your policies specific for whatever it is that you're specific for whatever it is that you're specific for whatever it is that you're trying to do. So since I disabled that trying to do. So since I disabled that trying to do. So since I disabled that policy, I probably am going to start policy, I probably am going to start policy, I probably am going to start having a couple issues. So for example, having a couple issues. So for example, having a couple issues. So for example, here you can see my remote instance on here you can see my remote instance on here you can see my remote instance on Proxmox. it it's having some issues. It Proxmox. it it's having some issues. It Proxmox. it it's having some issues. It lost that connection because it's no lost that connection because it's no lost that connection because it's no longer running the all policy longer running the all policy longer running the all policy communication error. And to fix that, communication error. And to fix that, communication error. And to fix that, for example, I'd head over to my peers for example, I'd head over to my peers for example, I'd head over to my peers and I would assign these some groups. So and I would assign these some groups. So and I would assign these some groups. So for Proxmox backup server, I could for Proxmox backup server, I could for Proxmox backup server, I could create a group specifically for this create a group specifically for this create a group specifically for this task if I want to, just as an example.
-
task if I want to, just as an example. task if I want to, just as an example. So I can make a group called remote So I can make a group called remote So I can make a group called remote sync. Add this to that remote sync sync. Add this to that remote sync sync. Add this to that remote sync group. Save it. And then let's make a group. Save it. And then let's make a group. Save it. And then let's make a group for our local PVE server. And we group for our local PVE server. And we group for our local PVE server. And we could call this something like uh could call this something like uh could call this something like uh trusted. Obviously, you could call all trusted. Obviously, you could call all trusted. Obviously, you could call all these what you want depending on how you these what you want depending on how you these what you want depending on how you want to organize it and configure it, want to organize it and configure it, want to organize it and configure it, but we'll set this as a trusted group. but we'll set this as a trusted group. but we'll set this as a trusted group. I'm going to save the group. And then if I'm going to save the group. And then if I'm going to save the group. And then if I go under the policies here, we're I go under the policies here, we're I go under the policies here, we're going to go ahead and add a new policy. going to go ahead and add a new policy. going to go ahead and add a new policy. And I want the trusted groups or the And I want the trusted groups or the And I want the trusted groups or the trusted peers that are assigned this trusted peers that are assigned this trusted peers that are assigned this group to have access to remote sync. group to have access to remote sync. group to have access to remote sync. Right now, it's set to all ports. We're Right now, it's set to all ports. We're Right now, it's set to all ports. We're going to dive into that for the next going to dive into that for the next going to dive into that for the next example, but I'm going to continue here. example, but I'm going to continue here. example, but I'm going to continue here. We're not going to enable posture checks We're not going to enable posture checks We're not going to enable posture checks at the moment, but this is actually at the moment, but this is actually at the moment, but this is actually pretty cool. I'll just start the free pretty cool. I'll just start the free pretty cool. I'll just start the free trial. It It's real nice that they don't trial. It It's real nice that they don't trial. It It's real nice that they don't make you like pop in a credit card, make you like pop in a credit card, make you like pop in a credit card, anything right away, so you could test anything right away, so you could test anything right away, so you could test it without having to do all that. But if it without having to do all that. But if it without having to do all that. But if I add a posture check, I can set it so I add a posture check, I can set it so I add a posture check, I can set it so it has to be like a specific country or it has to be like a specific country or it has to be like a specific country or region, a specific operating system. And region, a specific operating system. And region, a specific operating system. And that could get down to whether if it's that could get down to whether if it's that could get down to whether if it's like mobile only or desktop only. you like mobile only or desktop only. you like mobile only or desktop only. you get all the way down to running as a get all the way down to running as a get all the way down to running as a specific like process on a machine. But specific like process on a machine. But specific like process on a machine. But for example, if I wanted to go country for example, if I wanted to go country for example, if I wanted to go country region, I could add a location and for region, I could add a location and for region, I could add a location and for example, let's just go to Antarctica. If example, let's just go to Antarctica. If example, let's just go to Antarctica. If I wanted to block anything coming in I wanted to block anything coming in I wanted to block anything coming in from Antarctica, I could do that and you from Antarctica, I could do that and you from Antarctica, I could do that and you could get to specific locations, but could get to specific locations, but could get to specific locations, but there's probably not not a lot going to there's probably not not a lot going to there's probably not not a lot going to show up under that. So, if I save that, show up under that. So, if I save that, show up under that. So, if I save that, continue. For the name of the posture continue. For the name of the posture continue. For the name of the posture check, I could say something like no check, I could say something like no check, I could say something like no penguins. No penguins allowed for this
-
penguins. No penguins allowed for this penguins. No penguins allowed for this policy. So, we'll create that posture policy. So, we'll create that posture policy. So, we'll create that posture check. There we go. So continue and this check. There we go. So continue and this check. There we go. So continue and this is going to be our is going to be our is going to be our remote sync policy. So we'll add that remote sync policy. So we'll add that remote sync policy. So we'll add that policy. And there it is. We can see now policy. And there it is. We can see now policy. And there it is. We can see now all trusted machines can have access to all trusted machines can have access to all trusted machines can have access to remote sync. And if I go over here and remote sync. And if I go over here and remote sync. And if I go over here and let's kind of refresh this. Let it think let's kind of refresh this. Let it think let's kind of refresh this. Let it think about it again. Look at that. It's about it again. Look at that. It's about it again. Look at that. It's working. I'm not getting that connection working. I'm not getting that connection working. I'm not getting that connection error anymore. So here, this is my admin error anymore. So here, this is my admin error anymore. So here, this is my admin kind of user. So I'm actually going to kind of user. So I'm actually going to kind of user. So I'm actually going to make a new group and I'm going to call make a new group and I'm going to call make a new group and I'm going to call it admin. So boom. Save changes. And now it admin. So boom. Save changes. And now it admin. So boom. Save changes. And now if I head back over to our access if I head back over to our access if I head back over to our access control policies for this subnet control policies for this subnet control policies for this subnet network, I want all instead of all, network, I want all instead of all, network, I want all instead of all, we're going to go with I want admins we're going to go with I want admins we're going to go with I want admins just like that to have access to the just like that to have access to the just like that to have access to the subnet. So if I click save and I just subnet. So if I click save and I just subnet. So if I click save and I just verified that that policy works real verified that that policy works real verified that that policy works real quick. So we're good to go. So now let's quick. So we're good to go. So now let's quick. So we're good to go. So now let's add another user with a completely add another user with a completely add another user with a completely different group. Now I'm going to invite different group. Now I'm going to invite different group. Now I'm going to invite a user and this is going to be my wife. a user and this is going to be my wife. a user and this is going to be my wife. This is my official final setup. So, I'm This is my official final setup. So, I'm This is my official final setup. So, I'm actually going to do it properly. Popped actually going to do it properly. Popped actually going to do it properly. Popped in her email. We do have some default in her email. We do have some default in her email. We do have some default user types here. I'm just going to make user types here. I'm just going to make user types here. I'm just going to make her a user and auto assign groups. This her a user and auto assign groups. This her a user and auto assign groups. This right here, I'm going to make a new one.
-
right here, I'm going to make a new one. right here, I'm going to make a new one. I'm just going to call it family. So, if I'm just going to call it family. So, if I'm just going to call it family. So, if I invite anybody else that happens to be I invite anybody else that happens to be I invite anybody else that happens to be a family member, I could put them in the a family member, I could put them in the a family member, I could put them in the family group. And then I could set up family group. And then I could set up family group. And then I could set up policies so that family group has access policies so that family group has access policies so that family group has access to specific resource ports and so on. to specific resource ports and so on. to specific resource ports and so on. So, we'll add that. Send the invitation. So, we'll add that. Send the invitation. So, we'll add that. Send the invitation. And now I actually have to go have her And now I actually have to go have her And now I actually have to go have her accept it. So, I'll be back. So, I'm accept it. So, I'll be back. So, I'm accept it. So, I'll be back. So, I'm back. I I explained to my wife what I back. I I explained to my wife what I back. I I explained to my wife what I was doing, and she just handed me her was doing, and she just handed me her was doing, and she just handed me her phone and told me to do it. Accepted the phone and told me to do it. Accepted the phone and told me to do it. Accepted the invite, signed her in. Boom. Accept invite, signed her in. Boom. Accept invite, signed her in. Boom. Accept that. There we go. Connected. But she is that. There we go. Connected. But she is that. There we go. Connected. But she is connected to no peers. So, what I'm connected to no peers. So, what I'm connected to no peers. So, what I'm going to do is give her access to a very going to do is give her access to a very going to do is give her access to a very specific service. So, what we can do is specific service. So, what we can do is specific service. So, what we can do is first let's go under networks into our first let's go under networks into our first let's go under networks into our home network and we're going to add a home network and we're going to add a home network and we're going to add a new resource. since she's not having new resource. since she's not having new resource. since she's not having access to the entire subnet, we need to access to the entire subnet, we need to access to the entire subnet, we need to add the uh the actual machine add the uh the actual machine add the uh the actual machine specifically. So here, let's add a specifically. So here, let's add a specifically. So here, let's add a resource. And this one is going to be resource. And this one is going to be resource. And this one is going to be our media server. And for the IP, I'm our media server. And for the IP, I'm our media server. And for the IP, I'm just going to pop in our local IP just going to pop in our local IP just going to pop in our local IP address for that machine. And for the address for that machine. And for the address for that machine. And for the designated groups, I'm actually going to designated groups, I'm actually going to designated groups, I'm actually going to put this into a media group because I put this into a media group because I put this into a media group because I have a couple other machines that have a couple other machines that have a couple other machines that function as kind of media type server function as kind of media type server function as kind of media type server devices. So I'll give them this group as devices. So I'll give them this group as devices. So I'll give them this group as well. So I will add that add the well. So I will add that add the well. So I will add that add the resource and now right here I am going resource and now right here I am going resource and now right here I am going to add a new policy for this. For this I to add a new policy for this. For this I to add a new policy for this. For this I am going to allow family to connect to am going to allow family to connect to am going to allow family to connect to the destination media which is the destination media which is the destination media which is automatically filled out for us. But in
-
automatically filled out for us. But in automatically filled out for us. But in this case I want to give it port this case I want to give it port this case I want to give it port specific access. So I'm going to enable specific access. So I'm going to enable specific access. So I'm going to enable TCP here and pop in only the port for TCP here and pop in only the port for TCP here and pop in only the port for MB. That's going to be MB. That's going to be MB. That's going to be 8096. So add that port and when I fully 8096. So add that port and when I fully 8096. So add that port and when I fully go through and set everything up, I'll go through and set everything up, I'll go through and set everything up, I'll add ports for like a overseer image and add ports for like a overseer image and add ports for like a overseer image and things like that. So we continue. I'm things like that. So we continue. I'm things like that. So we continue. I'm not going to add any posture checks. And not going to add any posture checks. And not going to add any posture checks. And this can be the media server policy. So this can be the media server policy. So this can be the media server policy. So let's add that policy. And then there we let's add that policy. And then there we let's add that policy. And then there we go. We now have our media server with go. We now have our media server with go. We now have our media server with the IP address there. Oh, I do need to the IP address there. Oh, I do need to the IP address there. Oh, I do need to change this to 24. Save those changes. change this to 24. Save those changes. change this to 24. Save those changes. So we have the IP address. It's active So we have the IP address. It's active So we have the IP address. It's active groups media with the policy. So on her groups media with the policy. So on her groups media with the policy. So on her device here, what I will do is first try device here, what I will do is first try device here, what I will do is first try to navigate to something I know that to navigate to something I know that to navigate to something I know that there's no access to. And we'll even do there's no access to. And we'll even do there's no access to. And we'll even do it on the same machine for this example. it on the same machine for this example. it on the same machine for this example. So 200 and let's go 7878, which is So 200 and let's go 7878, which is So 200 and let's go 7878, which is another service I'm running on here. If another service I'm running on here. If another service I'm running on here. If I hit go, probably help if I disable I hit go, probably help if I disable I hit go, probably help if I disable Wi-Fi. So now when I try that, you can Wi-Fi. So now when I try that, you can Wi-Fi. So now when I try that, you can see it's stalling out, not working. She see it's stalling out, not working. She see it's stalling out, not working. She has no access. But according to my has no access. But according to my has no access. But according to my calculations, if she goes to the MB port calculations, if she goes to the MB port calculations, if she goes to the MB port we given her access to, hit go. Will you we given her access to, hit go. Will you we given her access to, hit go. Will you look at that? So now this user in the look at that? So now this user in the look at that? So now this user in the family group because of our policy, the family group because of our policy, the family group because of our policy, the family group has access to media which family group has access to media which family group has access to media which we can see here. So has access to that we can see here. So has access to that we can see here. So has access to that port which is running the MB service.
-
port which is running the MB service. port which is running the MB service. And you could get really specific with And you could get really specific with And you could get really specific with how things are set up. You could add a how things are set up. You could add a how things are set up. You could add a lot more groups and things. So, for lot more groups and things. So, for lot more groups and things. So, for example, one thing I'd want to do is example, one thing I'd want to do is example, one thing I'd want to do is this NetBird Pi. I would want to set this NetBird Pi. I would want to set this NetBird Pi. I would want to set this up as a trusted machine. Save that this up as a trusted machine. Save that this up as a trusted machine. Save that group. So, now in the policies, I could group. So, now in the policies, I could group. So, now in the policies, I could modify this uh network subnet policy for modify this uh network subnet policy for modify this uh network subnet policy for example. And I could just call it the example. And I could just call it the example. And I could just call it the admin policy. And then go over here and admin policy. And then go over here and admin policy. And then go over here and source admin. I'll have access to both source admin. I'll have access to both source admin. I'll have access to both the subnet as well as our trusted the subnet as well as our trusted the subnet as well as our trusted devices here. Remote sync. And I could devices here. Remote sync. And I could devices here. Remote sync. And I could play around with and configure that play around with and configure that play around with and configure that however I would like to. So save however I would like to. So save however I would like to. So save changes. And now you can see I have a changes. And now you can see I have a changes. And now you can see I have a admin policy with a bunch of admin policy with a bunch of admin policy with a bunch of destinations here. So now, like I said, destinations here. So now, like I said, destinations here. So now, like I said, I'm not actually gonna run this with a I'm not actually gonna run this with a I'm not actually gonna run this with a self-hosted instance, but it's self-hosted instance, but it's self-hosted instance, but it's definitely worth checking out seeing the definitely worth checking out seeing the definitely worth checking out seeing the installation process and how easy it is. installation process and how easy it is. installation process and how easy it is. So let's go ahead and test that out. So So let's go ahead and test that out. So So let's go ahead and test that out. So here we are. This is the self-hosting here we are. This is the self-hosting here we are. This is the self-hosting quick start guide. There are a few quick start guide. There are a few quick start guide. There are a few prerequisites. First, a machine powerful prerequisites. First, a machine powerful prerequisites. First, a machine powerful enough, one CPU, and 2 gigs of memory.
-
enough, one CPU, and 2 gigs of memory. enough, one CPU, and 2 gigs of memory. numerous ports need to be accessible and numerous ports need to be accessible and numerous ports need to be accessible and a public domain. Now, for this case, I'm a public domain. Now, for this case, I'm a public domain. Now, for this case, I'm going to be doing this on a uh VPS going to be doing this on a uh VPS going to be doing this on a uh VPS because I don't want the failure point because I don't want the failure point because I don't want the failure point to be my internet at home. It's Xfinity, to be my internet at home. It's Xfinity, to be my internet at home. It's Xfinity, which is just wired cable. And if you've which is just wired cable. And if you've which is just wired cable. And if you've ever used Xfinity, you probably know ever used Xfinity, you probably know ever used Xfinity, you probably know it's not always. Additionally, we are it's not always. Additionally, we are it's not always. Additionally, we are going to need Docker installed and a few going to need Docker installed and a few going to need Docker installed and a few packages. And this right here is our packages. And this right here is our packages. And this right here is our VPS. I'm already logged in. I've VPS. I'm already logged in. I've VPS. I'm already logged in. I've installed all the prerequisites installed all the prerequisites installed all the prerequisites including Docker and a few packages. including Docker and a few packages. including Docker and a few packages. I've also went ahead and pointed a I've also went ahead and pointed a I've also went ahead and pointed a subdomain to the IP address of this VPS. subdomain to the IP address of this VPS. subdomain to the IP address of this VPS. And to run this, we're actually just And to run this, we're actually just And to run this, we're actually just going to be using a nice little script going to be using a nice little script going to be using a nice little script here. So, I'm going to go ahead and give here. So, I'm going to go ahead and give here. So, I'm going to go ahead and give it a copy. We're going to make a new it a copy. We're going to make a new it a copy. We're going to make a new directory called netbird. And I'm just directory called netbird. And I'm just directory called netbird. And I'm just going to drop that on in. Right at the going to drop that on in. Right at the going to drop that on in. Right at the start of the command, we are going to start of the command, we are going to start of the command, we are going to want to replace the Netbird domain with want to replace the Netbird domain with want to replace the Netbird domain with the one that we actually set up. So, the one that we actually set up. So, the one that we actually set up. So, mine is mine is mine is hopky.net. And then hit enter. This is hopky.net. And then hit enter. This is hopky.net. And then hit enter. This is going to do a lot of things, including going to do a lot of things, including going to do a lot of things, including pulling some Docker stuff, so it may pulling some Docker stuff, so it may pulling some Docker stuff, so it may take just a little bit of time. There we take just a little bit of time. There we take just a little bit of time. There we go. It's starting up Zitadel, which if go. It's starting up Zitadel, which if go. It's starting up Zitadel, which if you didn't notice is a free and open you didn't notice is a free and open you didn't notice is a free and open source identity provider that we are source identity provider that we are source identity provider that we are going to be using with this installation going to be using with this installation going to be using with this installation right here with Zadell identity right here with Zadell identity right here with Zadell identity provider. So once this completely spins provider. So once this completely spins provider. So once this completely spins up, we could dive in. And there we go.
-
up, we could dive in. And there we go. up, we could dive in. And there we go. And we do have some credentials right And we do have some credentials right And we do have some credentials right here that we can use to log in with our here that we can use to log in with our here that we can use to log in with our initial login. So let's just see if initial login. So let's just see if initial login. So let's just see if that's spun up ready to go for us. So that's spun up ready to go for us. So that's spun up ready to go for us. So here it is. It's first putting us in here it is. It's first putting us in here it is. It's first putting us in ZEL. So let's go ahead and log in. So ZEL. So let's go ahead and log in. So ZEL. So let's go ahead and log in. So pop in our username and then our pop in our username and then our pop in our username and then our password. We could go next. And now password. We could go next. And now password. We could go next. And now we're going to set up two factor. Now we we're going to set up two factor. Now we we're going to set up two factor. Now we can use an authentication app or a can use an authentication app or a can use an authentication app or a device dependent one. I'm just going to device dependent one. I'm just going to device dependent one. I'm just going to do this with a authenticator app for do this with a authenticator app for do this with a authenticator app for now. Let's go next. Going to add that now. Let's go next. Going to add that now. Let's go next. Going to add that real quick and log in. Boom. Two factors real quick and log in. Boom. Two factors real quick and log in. Boom. Two factors verified. So we could go ahead and go verified. So we could go ahead and go verified. So we could go ahead and go next. Type in a new password. Making next. Type in a new password. Making next. Type in a new password. Making sure it is super strong and secure. And sure it is super strong and secure. And sure it is super strong and secure. And next. So there we go. Our password has next. So there we go. Our password has next. So there we go. Our password has been changed. Type in our authenticator been changed. Type in our authenticator been changed. Type in our authenticator code once again. and then dive on in to code once again. and then dive on in to code once again. and then dive on in to the dashboard. It was really as simple the dashboard. It was really as simple the dashboard. It was really as simple as that. So, we have no peers or as that. So, we have no peers or as that. So, we have no peers or anything set up obviously. And if I go anything set up obviously. And if I go anything set up obviously. And if I go down to users, you can see I have the down to users, you can see I have the down to users, you can see I have the one Zadell admin user. There's no option one Zadell admin user. There's no option one Zadell admin user. There's no option to invite users here. And to do that, to invite users here. And to do that, to invite users here. And to do that, you're actually going to need it to do you're actually going to need it to do you're actually going to need it to do it through the Zadell dashboard it through the Zadell dashboard it through the Zadell dashboard UI/ console. And everything that you UI/ console. And everything that you UI/ console. And everything that you could do here is incredibly could do here is incredibly could do here is incredibly comprehensive. We're not going to have comprehensive. We're not going to have comprehensive. We're not going to have the time to cover all this in this the time to cover all this in this the time to cover all this in this video, but over here under users, this video, but over here under users, this video, but over here under users, this right here is my default user. And this right here is my default user. And this right here is my default user. And this is where you'd go ahead and add those is where you'd go ahead and add those is where you'd go ahead and add those new users. So, for now, let's just go new users. So, for now, let's just go new users. So, for now, let's just go back to Netbird and check to see if we back to Netbird and check to see if we back to Netbird and check to see if we can set up a pier. So, here under peers, can set up a pier. So, here under peers, can set up a pier. So, here under peers, actually, let's go setup keys and create actually, let's go setup keys and create actually, let's go setup keys and create our very first setup key. This is going our very first setup key. This is going our very first setup key. This is going to be our quick test key. I am only to be our quick test key. I am only to be our quick test key. I am only going to install this on one machine.
-
going to install this on one machine. going to install this on one machine. So, I'm going to have this one expire or So, I'm going to have this one expire or So, I'm going to have this one expire or not be usable after one. Going to check not be usable after one. Going to check not be usable after one. Going to check this just in case my machine goes this just in case my machine goes this just in case my machine goes offline. And for groups, I'm just going offline. And for groups, I'm just going offline. And for groups, I'm just going to assign it to a VM group cuz that's to assign it to a VM group cuz that's to assign it to a VM group cuz that's what I'm going to install it on. And what I'm going to install it on. And what I'm going to install it on. And then we can create our setup key. Now, then we can create our setup key. Now, then we can create our setup key. Now, for this, let's log into a local machine for this, let's log into a local machine for this, let's log into a local machine here. So, I'm going to log into the VM here. So, I'm going to log into the VM here. So, I'm going to log into the VM that handles my NexCloud instance, for that handles my NexCloud instance, for that handles my NexCloud instance, for example, and then going to go back to example, and then going to go back to example, and then going to go back to the Netbird quick install guide and grab the Netbird quick install guide and grab the Netbird quick install guide and grab the little setup script here and just the little setup script here and just the little setup script here and just drop her on in. And it's installed. drop her on in. And it's installed. drop her on in. And it's installed. Netbird's up. But a key difference here Netbird's up. But a key difference here Netbird's up. But a key difference here is we're going to need to connect this is we're going to need to connect this is we're going to need to connect this to our self-hosted instance as opposed to our self-hosted instance as opposed to our self-hosted instance as opposed to the cloud instance that's hosted by to the cloud instance that's hosted by to the cloud instance that's hosted by Netbird themselves. So, now over here, I Netbird themselves. So, now over here, I Netbird themselves. So, now over here, I cleared out my console real quick. We're cleared out my console real quick. We're cleared out my console real quick. We're just going to do a uh netb bird up and just going to do a uh netb bird up and just going to do a uh netb bird up and first we're going to change the first we're going to change the first we're going to change the management URL to our own instead of management URL to our own instead of management URL to our own instead of theirs. So we're going to go https and theirs. So we're going to go https and theirs. So we're going to go https and then the domain I set which is going to then the domain I set which is going to then the domain I set which is going to be be be netbird.hopkkey.net. This is at 443 and netbird.hopkkey.net. This is at 443 and netbird.hopkkey.net. This is at 443 and we're going to set up our key. So if we we're going to set up our key. So if we we're going to set up our key. So if we do dash k and again let's make sure I do dash k and again let's make sure I do dash k and again let's make sure I have this key copied and then drop her have this key copied and then drop her have this key copied and then drop her on in there. And then when I hit enter on in there. And then when I hit enter on in there. And then when I hit enter it is going to connect. You can see it's it is going to connect. You can see it's it is going to connect. You can see it's connected. Simple as that. So, we should connected. Simple as that. So, we should connected. Simple as that. So, we should be able to see it here. If we go under be able to see it here. If we go under be able to see it here. If we go under peers, well, we can see that it has used peers, well, we can see that it has used peers, well, we can see that it has used that key. So, if we go to peers here, that key. So, if we go to peers here, that key. So, if we go to peers here, there we are. It is our cloud VM. So, we there we are. It is our cloud VM. So, we there we are. It is our cloud VM. So, we have a pier connected. We're we're good have a pier connected. We're we're good have a pier connected. We're we're good to go. Again, it's absolutely fantastic to go. Again, it's absolutely fantastic to go. Again, it's absolutely fantastic that this is an option, but for me that this is an option, but for me that this is an option, but for me personally, I'm going to stick with just
-
personally, I'm going to stick with just personally, I'm going to stick with just having them do it in their cloud. So, having them do it in their cloud. So, having them do it in their cloud. So, that was the self-hosted setup. Again, that was the self-hosted setup. Again, that was the self-hosted setup. Again, I'm just going to keep this current I'm just going to keep this current I'm just going to keep this current setup that I have here on the NetBird setup that I have here on the NetBird setup that I have here on the NetBird website. Overall, it's functioning website. Overall, it's functioning website. Overall, it's functioning really well. I like how easy it is to really well. I like how easy it is to really well. I like how easy it is to add uh peer-to-peer connections between add uh peer-to-peer connections between add uh peer-to-peer connections between all these different machines. The access all these different machines. The access all these different machines. The access control policies are fantastic. So, you control policies are fantastic. So, you control policies are fantastic. So, you can get really gl granular. yet can get really gl granular. yet can get really gl granular. yet granular and how you get all this set up granular and how you get all this set up granular and how you get all this set up not only with remote connections for not only with remote connections for not only with remote connections for accessing services but that kind of uh accessing services but that kind of uh accessing services but that kind of uh peerto-peer for example the Proxmox peerto-peer for example the Proxmox peerto-peer for example the Proxmox backup server thing that we got set up. backup server thing that we got set up. backup server thing that we got set up. So with all that I do hope you enjoyed So with all that I do hope you enjoyed So with all that I do hope you enjoyed this video. There'll be links down below this video. There'll be links down below this video. There'll be links down below to the documentation so you can check to the documentation so you can check to the documentation so you can check that out the actual website so you could that out the actual website so you could that out the actual website so you could sign up if you want to go ahead and play sign up if you want to go ahead and play sign up if you want to go ahead and play around with it. And with all that, I do around with it. And with all that, I do around with it. And with all that, I do hope you have an absolutely beautiful hope you have an absolutely beautiful hope you have an absolutely beautiful day and goodbye.
Summary
The main theme is securely connecting to self-hosted home lab servers from anywhere. The transcript references Netbird as a solution, contrasting it with traditional VPNs like NordVPN and highlighting its open-source and self-hostable nature, utilizing WireGuard for encryption. The practical takeaway is that Netbird offers a superior and effortless way to achieve secure, direct peer-to-peer connections to personal infrastructure.