NetBird Access Validation Matrix
Use this matrix to capture proof that protected endpoints are accessible from NetBird clients and denied from non-NetBird sources.
Use this matrix to capture proof that protected endpoints are accessible from NetBird clients and denied from non-NetBird sources.
Execution Metadata
- Validation date (UTC):
- Validator:
- Owner approval reference:
- NetBird client peer id used:
- Non-NetBird source used:
Expected Results
- NetBird source: reachable/login prompt as intended.
- Non-NetBird source: denied by policy (typically 403 or blocked TCP).
Endpoint Matrix
| Endpoint | Path Type | NetBird expected | Non-NetBird expected | NetBird result | Non-NetBird result | Evidence reference |
|---|---|---|---|---|---|---|
| pgsql.perspective-v.com:5432 | DB TCP | reachable | blocked | |||
| mysql.perspective-v.com:3306 | DB TCP | reachable | blocked | |||
| mongo.perspective-v.com:27017 | DB TCP | reachable | blocked | |||
| mssql.perspective-v.com:1433 | DB TCP | reachable | blocked | |||
| redis.perspective-v.com:6379 | Cache TCP | reachable | blocked | |||
| pgadmin.perspective-v.com | DB UI | app login | denied | |||
| phpmyadmin.perspective-v.com | DB UI | app login | denied | |||
| mongo-express.perspective-v.com | DB UI | app login | denied | |||
| konga.perspective-v.com | Gateway UI | app login | denied | |||
| wud.perspective-v.com | Ops UI | app login | denied | |||
| registry-admin.perspective-v.com — RETIRED 2026-07-01 (replaced by Gitea) | Registry UI | app login | denied | |||
| rustfs.perspective-v.com | Object storage UI | app login | denied | |||
| rustfs-api.perspective-v.com | Object storage API | auth gate | denied |
Sign-off
- All protected endpoints validated from both source types.
- Evidence links added for each row.
- Owner sign-off captured.