I have an Ubuntu 18.04 box. It has zerotier setup but it is showing as offline
Any recommendations to diagnose? I suspect the machines outgoing traffic is being blocked somehow, I see inbound ports to open, are there known outbound paths I can ask to be opened up that may help ??
You likely have firewall rules blocking ZeroTier from communicating. Check ufw (i believe the default on Ubuntu) or iptables. At the very least, it needs to be able to send & receive packets on UDP port 9993. Beyond that, it’s possible your router may be blocking traffic. How to fix that is dependent on your router.
Also, you’re on version 1.6.5. 1.10.0 was released last week. You may want to upgrade
Yeah iptables looks like it’s on accept across the board there, so it’s not the firewall on your machine. Hopefully your IT department can help you out. Ideally you need incoming & outgoing UDP for things to work properly.
IT Finally opened up the ports but we still show status OFFLINE. Are there any clever ideas on how to test that outgoing or incoming UDP ports are really open, I genuinely do not trust IT. My normal trick of using TCP won’t work since it is UDP
dev@connectria /d/h/dev> sudo systemctl restart zerotier-one.service
dev@connectria /d/h/dev> sudo zerotier-cli status
200 info 185eabf82d 1.6.5 OFFLINE
I am also having occasional disconnects with the system telling me it is offline. It seems this started with the update to version 1.10. I will see if downgrading will help.
Same problem here with some servers. Example bellow is a Debian 11. The same machine have a OpenVPN that not stop working for months. Firewall is completely off. Tcpdump reports thats packets are out an in in 9993 and other ports:
09:04:33.062445 eno1 Out IP 192.168.1.10.38062 > 50.7.252.138.9993: UDP, length 137
09:04:33.062452 eno1 Out IP 192.168.1.10.30202 > 50.7.252.138.9993: UDP, length 137
09:04:33.062465 eno1 Out IP 192.168.1.10.9993 > 104.194.8.134.9993: UDP, length 137
09:04:33.062476 eno1 Out IP 192.168.1.10.38062 > 104.194.8.134.9993: UDP, length 137
09:04:33.062483 eno1 Out IP 192.168.1.10.30202 > 104.194.8.134.9993: UDP, length 137
09:04:33.175989 eno2 In IP 103.195.103.66.9993 > 192.168.1.10.9993: UDP, length 629
09:04:33.255201 eno2 In IP 104.194.8.134.9993 > 192.168.1.10.38062: UDP, length 629
09:04:33.285850 eno2 In IP 84.17.53.155.9993 > 192.168.1.10.9993: UDP, length 629
09:04:33.420511 eno2 In IP 50.7.252.138.9993 > 192.168.1.10.38062: UDP, length 629
But status stay offline and peers shows all RELAYED. Suddenly, they become ONLINE for a while, sometimes RELAYED and some direct. Other machine (an old Debian 7) in the same network stay online not relayed all the time, but I never can ping them.
OpenVPN have a log thats helps, but I can’t find any in ZT.