Skip to main content

Diagnostics

If you see access failure, denial, latency, or disconnects, follow this order. In most cases, you can isolate the issue direction in about 10 minutes.

Step 1: confirm device online state

  1. In Nodes, confirm source device is online.
  2. In Nodes, confirm target device is online.
  3. Verify device names to avoid selecting stale or similarly named nodes.

If a device is offline, fix that first before moving on.

Step 2: confirm ACL allow rules

  1. In ACLs, confirm the subject is your account or expected user group.
  2. Confirm target device is correct.
  3. Confirm protocol and port match your real request.

If ACL was just updated, wait a few seconds and retry.

Step 3: confirm subnet routing (if subnet is involved)

  1. In Routers, confirm subnet route approval status.
  2. Verify the subnet range is correct.
  3. Retry the subnet endpoint.

Step 4: confirm relay path

  1. Free shared relay is already available by default for all users.
  2. If you need lower latency or stronger stability, use dedicated relay.
  3. If you use user-managed relay, verify address and ports carefully.

Step 5: run one positive and one negative test

  1. Test with an authorized account and confirm success.
  2. Test with an unauthorized account/device and confirm denial.

This quickly proves whether your policy behavior matches expectation.

Step 6: if unresolved, send this info to support

  • Time of issue
  • Account and tenant name
  • Source and target device names
  • Protocol and port
  • Steps already tested