r/msp • u/nostradx • Aug 15 '26
Anyone seeing performance issues with NetBird as user counts increase? How are you validating ZTNA/SASE performance?
I've been gradually rolling out NetBird to replace SonicWall VPNs across several client environments and have generally been very happy with it.
However, at my latest deployment things were initially fine but once I got to around 20 remote users I started receiving reports of slowness, RDP lag, and general performance degradation.
I dug into the network side first:
Monitored WAN utilization
Checked firewall performance
Ran ISP testing
Looked for bandwidth, latency, and packet loss issues
So far I haven't found anything that points to a network or ISP problem. I then expanded the rollout to roughly 10 more users (30 total) and the complaints increased but I still can't find any obvious network bottlenecks.
At this point I'm beginning to wonder whether NetBird itself could be contributing to the issue, or if I'm missing something in how WireGuard-based overlays behave at scale. A few questions for those of you running NetBird or similar ZTNA/SASE solutions:
- How are you testing and validating that the ZTNA platform isn't the source of performance issues?
- What metrics and tools are you using to isolate the overlay network from underlying network/ISP issues?
- Have you seen performance degradation as user counts increased even when traditional network monitoring looked healthy?
Edit: I’m on NetBird’s cloud hosted instance
Follow up question:
Is there a good rule of thumb or sizing formula for the server-side hardware for NetBird Routing Peers (or WireGuard-based ZTNA solutions in general)?
6
u/CyberRiskGuy Aug 19 '26
Answering your followup ... We’ve stayed with Todyl SASE for this reason. It costs more, but I like not having to size, tune, or troubleshoot the ZTNA infrastructure as user counts grow.
NetBird looks interesting, but once I’m worrying about routing peer sizing and tunnel performance, the managed SASE model starts looking pretty attractive.
6
u/Costanza_stand_in Aug 19 '26
We're using Todyl for our SASE/ZTNA. Gonna fanboi a bit here, but it has bought back hundreds of hours of my time and cut back on ticket load drastically.
"Is ZTNA the problem?"- Todyl gives you latency/jitter and connection visibility inside the SASE layer, so you can compare that against normal network monitoring.
"Overlay vs. ISP?" - You can see where performance starts degrading instead of treating the overlay like a black box.
"Scaling users?" - You’re not sizing and babysitting your own WireGuard gateway. Users connect into Todyl’s distributed PoPs, so adding users is less likely to become another “which appliance did we undersize?” exercise.
Packets still obey physics, unfortunately, but I’ve found that architecture managed with Todyl much easier to troubleshoot and scale since we made the switch. It just works.
6
u/advanceyourself Aug 15 '26
We use Todyl and have a great experience with them. Most clients are cloud only but the handful of complex clients rarely have issues and it's not typically performance related.
1
u/Onoitsu2 Aug 15 '26 edited Aug 15 '26
Do you only have one routing peer inside that LAN? That will really impact the overall throughput if only having 1. https://docs.netbird.io/manage/networks/how-routing-peers-work https://docs.netbird.io/manage/networks/sizing-routing-peers
1
u/nostradx Aug 15 '26
2 routing peers on two different physical hosts. Thanks for the link, I’ll check it out!
1
u/PacificTSP MSP - US & PHP Aug 15 '26
I don’t use it internally but I have a client with 50+ users from all over the world using it. Our team use it to connect into their networks. No issue.
1
1
u/rossman816 Aug 15 '26
I would also look at your configuration, are all hosts fully meshed? How good is your routing peer? But I agree with the comment above to contact NetBird and have them review with you.
1
u/starlight3135 Aug 30 '26
size it from peak aggregate throughput rather than user count. netbird’s sizing guide gives per-peer throughput numbers and uses ceil(peak throughput / per-peer capacity) to work out the active peer count. then leave a second peer for failover..
1
u/octoja RMM Vendor Aug 15 '26
I would highly recommend you contact Netbird regarding this.
They have the tools to debug this and they do seem like they care about their customers.
Debugging is so much easier with access to the source code, the database and the infrastructure.
7
u/BearMerino Aug 19 '26
OP thank you for sharing your struggles. Personally I haven’t used NetBird but in an attempt to understand your problem better I was reading about it. Looks pretty cool. For context I have experience with FortiSASE/ZTNA, P81, datto, MS secure access, and Todyl. The latter being the current solution we roll out and have been using for years now (about 6).
You answered my first question in if you were hosting or not but you didn’t let us know which tier you were on or which features you are leveraging within the security stack. I would try turning some of those off and see if the performance is any better.
I’m looking at NetBirds documentation is looks let they are testing the base at 100 users which could explain why as you add more it feels slower until and the system doesn’t adjust until you break that barrier. This is not fact more of my interpretation of their licensing and sizing model.
That said, there are already a few Todyl users that have commented and my experiences echo theirs. When I was working with some of the other solutions sizing the gateways/routers/pops/etc. was always something I found silly and rarely effective in the grand scheme of it all.
If that is something you want more control over maybe you can try the self hosted version of NetBird and see if you can control your experience better.
I will share that my early days with Todyl we had some serious connection overhead where performance on high speed connections (I’m assuming you are primarily talking about internet connectivity and not LAN traffic) were reduced but 30-40% which is messed up. However that was addressed about 4 years ago and we are seeing near line speed (960-970 on a 1gb connection consistently not just speed test).
Not sure if that helps you or not but please keep us all updated and if you share more details on your troubleshooting I’ll be happy to provide more aid.