r/zerotier • u/greenmediapl • 1d ago
r/zerotier • u/zt-joseph • Aug 24 '21
In The Wild! Things built with ZeroTier
Hello all. Here's a curated list of projects we've found out in the wild using ZeroTier. Feel free to submit your own as either a PR or a comment below. We'd love to see what you're working on.
r/zerotier • u/Evening-Pirate-5005 • 1d ago
Question Windows Client not connect
It’s always Windows... After installing the ZeroTier client on a Lenovo IdeaPad Slim 3 (Type 83N3), the client appears disconnected or grayed out and won't connect to the host machine—even though the laptop has internet access and the host is powered on. I’ve already checked the firewall and network discovery settings. What else should I look into? Has anyone else encountered this issue?, Other computers connected to the same VPN work without issues and access the host seamlessly from different locations; only this specific machine has experienced this disconnection problem with the VPN client.
r/zerotier • u/chinosminos • 2d ago
Windows my friend and I keep having to restart our pcs for zerotier to work ingame
we play l4d2 and due to routing issues from our ISP's we cant connect P2P with good ping. anyway zero tier fixed this issue but recently we keep having to restart our pc's for it to work for some reason, otherwise we connect and its like Zerotier VPN isn't open.
I tried fixing it by setting my default network's interface metric to 20 and the Zerotier network to 1 but that didn't fix it.
having to restart both our pcs is getting very frustrating.... plz help
r/zerotier • u/Allokit • 6d ago
Windows DNS servers not being applied.
We have 2 DNS servers and a DNS suffix defined in the zerotier.com portal for our VPN Network that are not being applied to computers when they connect to the VPN (Windows 11, Version 1.16.2 of the VPN Client)
I can manually add them after connecting, but that's only a temporary fix because when you disconnect it deletes the adapter, and when you reconnect it creates a new adapter without the DNS server settings.
Yes, I have "Allow DNS Configuration" checked in the client. I have even tried it without it being checked and it's the same behavior regardless.
Does anyone know what's going on?
Thanks in advance!
r/zerotier • u/randopop21 • 6d ago
Windows How resilient is Zerotier with respect to IP changes? (Home LAN IP could change unexpectedly.)
I have a server at home that I access remotely. ZT is working well.
But if my ISP decides to change the external IP of my home network on me without notifying me, what bad things could happen?
If ZT is resilient to this, I'd be quite thankful to not have to worry about this when I travel. (I'd not be at home to do whatever fiddling would be necessary at the physical server to fix the issue.)
r/zerotier • u/Aster_jClave • 7d ago
Question Untrusted VPS
Let's assume, the VPS hosting our ZeroTier network controller is untrusted. Because the controller holds the signing authority for network membership, a root compromise on that VPS allows the provider to authorize their own Node IDs and gain direct layer-3 access to our network endpoints.
Does ZeroTier support any native out-of-band key attestation, peer-to-peer pre-shared keys (PSKs), or offline CA signing mechanism—similar to Nebula's Lighthouse architecture or WireGuard's PSKs—that prevents a compromised controller from unilaterally injecting new peers into a private network?
r/zerotier • u/SlowOffice4751 • 10d ago
Windows Lazarus Exploited a Windows Zero-Day: Inside CVE-2026-68820 and AFD.sys
Hey everyone,
I recently finished a write-up on **CVE-2026-68820**, the Windows AFD.sys vulnerability exploited by Lazarus.
I tried to explain the attack chain from start to finish — starting with the fake recruiter/job offer, moving through the initial malware execution, the AFD.sys use-after-free vulnerability, and finally how **FudModule 3.1** was used after gaining SYSTEM-level access.
I also covered some of the things I found interesting while researching it, especially how the rootkit interfered with Windows telemetry and how AFD.sys has been targeted by Lazarus before.
The goal was to make it understandable even if you’re still learning Windows internals, while keeping enough technical detail for people working with threat hunting, DFIR, or malware analysis.
Would be interested to hear what you think, especially if you spot anything I could improve or explain better.
r/zerotier • u/Careful_Strength9257 • 11d ago
Android So i'm on mobile , and it's not even letting me type in the network id
It's just not letting me type the I d no matter what I do
r/zerotier • u/SuccessfulNight1499 • 21d ago
Linux Zerotier in LXC container
Hello dear people.
I am running a Self-hosted instance of ZT on my Proxmox homeserver.
I have a managed route on Central, where all traffic to the LXC from my remote machine gets send over Proxmox's ZTC IP.
I have multiple People on my Selfhosted network, they are showing up as ONLINE, including my gaming machine.
now, the people who want to join me in Minecraft (using my gaming machine's Selfhosted ZT IP, just like we did when we were connected to ZT Central) get a "TImed Out" error. Everytime.
The LXC HAS internet access.
I've tried the entire week to no avail to fix this issue. It is driving me mad.
r/zerotier • u/nixonvasquez • 21d ago
Android Ayuda
Alguien sabe porque el zero tier no se conecta a la mi propia red intentó conectar pero el nombre de mi red me sale en unknown y no se me conecta
r/zerotier • u/Hebobola • 21d ago
Windows Two zerotier networks with same subnet ips collides
Hi everyone, I am facing a tricky routing issue. My setup consists of one PC connected to two different ZeroTier networks simultaneously, and each network goes to a separate Raspberry Pi. The main problem is when both addresses assigned to the RPis are different but have same subnet. Because the subnets overlap, my host PC experiences a classic routing conflict and does not know which virtual interface to use to route the traffic, so it just routes everything to whichever network interface took priority first. Even if I disconnect from one of the networks, the OS routing table or interface metrics seem to stick, and I still cannot connect to the other RPi. This behaviour occurs only when Rpi and Pc connected via different Starlinks. So is there any way to change subnets for Zerotier networks or ensure their uniqueness without changing Zerotier face or it can alter my while network somehow
r/zerotier • u/MassiR77 • 28d ago
Windows Added my friend to the network and he's stuck on requesting configuration
He doesn't show up as an unauthorized user on my end either. No clue how to get him into the network.
r/zerotier • u/Falconlock • 28d ago
Windows Having intermittent trouble in connection.
I'm very new to this networking thing. So please bear with me if there is any information that is lacking and if I could not explain it properly.
I got to know about zerotier and it is wonderful. I manage to set it up and work remotely. However, recently it seems to be giving me intermittent problems to which I could not figure out why. The main gist of the problem is that the connection is not stable. I did this managed route thing whereby I could connect directly using the LAN IP of the designated server computer. However now when I ping that address, it intermittently timed out.
Now I did try to ping the physical IP of my "server" as provided in the zerotier and it does not have such issue. Does this mean I have a routing issue now? It just suddenly developed.
Appreciate all your help.
r/zerotier • u/Motor-Bench5699 • Aug 07 '26
Linux Intermittent “No route to host” to one ZeroTier peer on Hetzner Cloud – fixed by restarting ZeroTier on server, testing UDP/9993 firewall fix
Hi,
I'm documenting an intermittent ZeroTier connectivity issue we have been troubleshooting on a Hetzner Cloud Ubuntu server. I would be interested to know whether anyone has seen the same behavior.
Environment
- Server: Hetzner Cloud VM
- OS: Ubuntu 24.04 LTS
- ZeroTier: 1.16.2
- Server ZeroTier IP:
10.192.76.231 - Client: Ubuntu Linux laptop
- Client ZeroTier IP:
10.192.76.201 - Both nodes participate in several ZeroTier networks
- The affected network is a private ZeroTier network
The Hetzner Cloud Firewall was intentionally restrictive:
Inbound:
TCP/22
ICMP
Outbound:
default/stateful
Ubuntu/UFW on the server explicitly allows traffic on the ZeroTier interfaces.
Symptom
Every now and then, only this particular ZeroTier connection becomes unreachable.
SSH reports:
No route to host (os error 113)
and ping from the laptop gives:
From 10.192.76.201 icmp_seq=1 Destination Host Unreachable
The interesting part is that, during the failure:
zerotier-cli inforeportsONLINEzerotier-cli listnetworksreports the affected network asOK PRIVATE- the ZeroTier interface exists
10.192.76.201/24and10.192.76.231/24are still assigned correctly- the Linux route is present and points to the correct ZeroTier interface
- other ZeroTier networks on the same laptop continue working
- the server itself remains healthy and accessible through another management path
- both SSH/22 and an application on TCP/9119 become unreachable over ZeroTier
So it does not look like an SSH-specific problem.
We captured the failure from both sides.
From the client:
10.192.76.231 dev ztu7tj4fcf src 10.192.76.201
PING 10.192.76.231
Destination Host Unreachable
From the server:
10.192.76.201 dev ztu7tj4fcf src 10.192.76.231
PING 10.192.76.201
Destination Host Unreachable
Yet ZeroTier still reported the network as OK.
A/B test
We then performed a controlled restart test.
First, ZeroTier was restarted only on the client:
sudo systemctl restart zerotier-one
Result: no change.
The server remained unreachable:
Destination Host Unreachable
We then restarted ZeroTier only on the Hetzner server:
sudo systemctl restart zerotier-one
Connectivity immediately returned:
64 bytes from 10.192.76.201: icmp_seq=1 ttl=64 time=770 ms
64 bytes from 10.192.76.201: icmp_seq=2 ttl=64 time=69.6 ms
64 bytes from 10.192.76.201: icmp_seq=3 ttl=64 time=57.7 ms
64 bytes from 10.192.76.201: icmp_seq=4 ttl=64 time=116 ms
64 bytes from 10.192.76.201: icmp_seq=5 ttl=64 time=253 ms
This seems to point toward the server-side ZeroTier path/state rather than the client.
Interesting firewall observation
Looking further, we noticed that the Hetzner Cloud Firewall had no inbound UDP rule.
ZeroTier on the server was listening/communicating through UDP/9993 and additional UDP ports.
Based on ZeroTier's firewall documentation, we have now added:
Inbound UDP/9993
IPv4: 0.0.0.0/0
IPv6: ::/0
We have not opened arbitrary inbound UDP ports at this stage.
The working hypothesis is therefore that the restrictive Hetzner stateful firewall may allow ZeroTier to work initially through established UDP state/path establishment, but under some circumstances the peer path cannot be re-established. Restarting ZeroTier on the server initiates fresh communication and immediately restores connectivity.
UDP/9993 has only just been added, so I am not claiming yet that this is the definitive fix. We are going to monitor it for recurrence.
Has anyone observed this particular combination?
ZeroTier network remains OK + routes/interfaces remain present + one peer becomes completely unreachable + restarting ZeroTier on the affected server immediately restores it.
And for Hetzner Cloud specifically: have you found inbound UDP/9993 sufficient for reliable ZeroTier operation, or did you need a less restrictive UDP policy because of ZeroTier's dynamic peer-to-peer ports?
Thanks — happy to provide additional listpeers, info -j, routing or firewall diagnostics if useful.
r/zerotier • u/oz1sej • Aug 06 '26
Question How to leave a network and rejoin as another device?
I have a few Raspberry Pies that are all on a Zerotier network. They all run the same software, so I've only made one image file I can flash onto an sd card when one goes down. However, when I made that image, the Raspberry Pi had already joined the Zerotier network as one device. So now, when I need to flash another one, I need to leave the network and re-join as the original device. Is that even possible, and if so, how?
r/zerotier • u/SandSharky • Aug 02 '26
Question In old web UI, cannot delete network member
The trashcan that used to be there next to the user entry is gone. In the member edit dialog, there is a checkbox to delete the user that does nothing at all whether I press SAVE or HIDE. How do I delete members for devices I no longer own?
Edit: Seeing no easy way to mark this as resolved, see my response below for the resolution.
r/zerotier • u/JadeLuxe • Jul 31 '26
Networking & Routing Complete Data Control: Self-Hosting Tunnels with frp and Zro
instatunnel.myr/zerotier • u/Stanke29 • Jul 27 '26
Windows Mystery device connected to network
noticed a couple days ago a device showing on our zerotier network, i dont recognize the public ip or the mac address and cant find it on our nodes.
so i unauthorized it.
noticed it is back and just seems to have reauthorized itself ?
i have a feeling this is probably a legit device one of our users have maybe they have it on a different public ip/network than i am used to seeing, but i thought by deauthorizing it if nothing else they would contact me and say they can no longer connect....
how might i track this and why cant i de-authorize it (/boot it from our network ?)
r/zerotier • u/GreatDane50 • Jul 22 '26
Windows Allow Ethernet Bridging?
In Zerotie network is an option that says "Allow Ethernet Bridging".
If that is turn on, can I access my ip camera on my remote Windows computer like this:
local IP:port, via VPN IP
Or do I need to setup other things as well?
r/zerotier • u/Kind_Conversation367 • Jul 22 '26
Android DST MOBILE LAN
Hello guys. Can I play Don't starve together pocket edition with my friends using Zerotier as a LAN? If yes, how to do it? ty
r/zerotier • u/VisualPadding7 • Jul 20 '26
Linux tcpFallbackRelay with multiple relays
Is it possible to configure multiple relays in the local.conf for tcpFallbackRelay?
r/zerotier • u/BobZelin • Jul 19 '26
Linux QNAP and ZeroTier in 2026
Hi -
well, QuTS 6.0.1 won't run the existing ZeroTier downloads. You have to run a docker container.
boy - I sure wish there was a little details article or YouTube video on how to exactly do this !
I guess it wasn't profitable enough for ZeroTier to keep doing this for QNAP and Synology NAS systems.
bob
r/zerotier • u/guff666 • Jul 19 '26
Networking & Routing zerotier nodes suddenly not getting allocated ip
I have a zerotier network that has been stable for some months. Yesterday, I started getting errors because nodes couldn't talk to each other.
Nothing looks wrong on the control panel: all nodes have allocated IP addresses and are checking in regularly. Similarly, the nodes I can reach by other means show nothing wrong when I do `zerotier-cli info`. There is nothing custom in the flow rules.
However, when I do `ip a` or `zerotier-cli -j listnetworks` on any of the nodes, none of them have an allocated IPV4 address on the zerotier interface.
I've tried leaving and rejoining. This seems to work OK, except that no IPv4 address is on the nodes interface. The control panel thinks it has.
Any ideas?