I am about to setup a Zerotier network with one ‘master server’ containing applications that needs to communicate with a lot of clients. (At this point, all Windows 10). That’s pretty strait forward, everyone can communicate with everyone.

My challenge is, that clients should NOT be allowed to communicate with other clients - Only to the master-server. How do I achieve that? As far as I can see, there is no firewall in the Zerotier Central?

Is this only possible to prevent with client-firewalls? Or can I do this in another way, by creating the Zerotier network structure in a specific way?

Not true. Have you ever logged into ?
This is the example for your specific use case - Client Isolation

Yes, all my setup is done through

In general, im working with iptables in Linux and pfSense, but unfortunately i dont understand how zerotier-firewall works then. If that is best practice in this case, ill need to look a bit more into how the firewall is working.


See this recent discussion for ideas: Allow rdp and ping only - #2 by AndrewZ

Much better, i can work with that! :slight_smile:


