Skip to content

Conversation

@SunsetDrifter
Copy link
Contributor

Comprehensive guide for implementing Zero Trust with NetBird,
aligned with NIST SP 800-207. Covers planning phases, IdP
integration, access policies, posture checks, routing peers,
high availability, traffic visibility, and troubleshooting.

Includes:

  • Terminology and naming conventions
  • Worked example for three-tier app segmentation
  • Masquerading vs return routes decision table
  • Common failure modes and CLI diagnostics
  • Quick reference appendices

- Add guide to navigation menu
- Rewrite section 5.2 on routing peer traffic direction for clarity
- Add documentation links throughout (Networks, Access Control, DNS,
  Control Center, Setup Keys, IdP sync, Traffic Events, Event Streaming)
- Add internal section and appendix cross-references
- Remove "Subject" terminology, replace with "source groups" and
  clearer user/peer terminology
- Expand acronyms on first use (IdP, SSO, MFA, SIEM, CIDR, VPC, etc.)
- Add explanations for technical concepts (masquerading, overlay networks,
  NAT traversal, protocols, ports)
- Enhance firewall rules section with service explanations and FAQ link
- Improve worked examples with port and protocol context
- Add command-line tool explanations for troubleshooting
- Make guide more accessible for junior network admins and students
@SunsetDrifter SunsetDrifter marked this pull request as ready for review December 29, 2025 12:59
@shuuri-labs shuuri-labs force-pushed the use-case-zero-trust-guide branch from 6649b66 to e628f95 Compare January 22, 2026 16:17
shuuri-labs and others added 3 commits January 22, 2026 17:22
  - Add Note/Warning MDX components replacing markdown blockquotes
  - Add TURN service rules to firewall configuration section
  - Add JSON API example for policy creation
  - Improve three-tier app diagram with box-drawing characters
  - Add Networks vs legacy Network Routes warning for Zero Trust
  - Add CIDR posture check limitation note (iOS/Android unsupported)
  - Add DNS forwarder port change note (v0.59.0+)
  - Add lazy connections feature limitations and version requirements
  - Add Users view to Control Center documentation
  - Convert verification checklists to Note components
  - Fix grammar throughout (serial commas, hyphenation consistency)
  - Improve term definitions and service descriptions
…references

- Replace detailed outbound allowlist rules with links to FAQ and self-hosted guide for port requirements
- Minor adjustments to lazy connections feature description for consistency
@shuuri-labs shuuri-labs merged commit ac7b74a into main Jan 22, 2026
1 check passed
@shuuri-labs shuuri-labs deleted the use-case-zero-trust-guide branch January 22, 2026 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants