Troubleshooting library
What is going wrong?
Start with a symptom. Each page narrows the possible causes before suggesting a change.
Try “Synology”, “Tailscale”, or “NAS unreachable”
- publishedCloudflare Tunnel
Cloudflare Tunnel Is Connected but the Public Hostname Returns 502: Unable to Reach Origin Service
Confirm the tunnel is connected and the visitor sees the tunnel-specific 502 Unable to reach the origin service, then match the exact cloudflared log signature to a stopped origin, a wrong ingress scheme, a wrong ingress port, or an untrusted origin certificate.
Follow the diagnosis → - publishedDocker Engine
Docker Published Port Works Locally but Is Unreachable from the LAN
Compare the working local endpoint with the failing LAN endpoint before investigating publication, application listening context or filtering.
Follow the diagnosis → - publishedHome Assistant
Home Assistant Blocks Requests from a Reverse Proxy Until It Is Trusted
Confirm direct access works, verify that Trust X-Forwarded-For and the proxy address are set as a network CIDR, then save and confirm the restart within the Home Assistant 2026.8 revert window.
Follow the diagnosis → - publishedEclipse Mosquitto
Mosquitto Rejects the MQTT Client Connection
Prove TCP reachability to the broker first, then read the MQTT CONNACK refusal code and match the listener-specific authentication on Mosquitto 2.1.x before changing any broker configuration.
Follow the diagnosis → - publishedNetwork UPS Tools
NUT Reports Data Stale for a USB UPS
Confirm the current stale response, then separate driver freshness, USB visibility, access and transport evidence without changing shutdown protection.
Follow the diagnosis → - publishedPi-hole
Pi-hole Installed but Clients Get No DNS Response
Separate clients bypassing Pi-hole from Pi-hole answering nothing by checking FTL state, a direct query, the upstream path, port 53 ownership, and the effective client resolver before any upstream or DHCP change.
Follow the diagnosis → - publishedProxmox VE
Proxmox VM Reaches Its Gateway but Cannot Reach the Internet
Separate guest addressing, resolution, bridge/segment evidence, outbound policy and upstream reachability after confirming the intended gateway responds.
Follow the diagnosis → - publishedrestic
restic Reports the Repository Is Already Locked
Capture the restic exit code, separate a still-running lock from a stale one, then use the documented unlock command without disabling locking for write operations.
Follow the diagnosis → - publishedSynology DSM · Synology Hyper Backup
Synology Hyper Backup Insufficient Destination Quota
Inspect retained versions and destination usage before choosing a capacity or retention procedure, without deleting recovery points as a diagnostic test.
Follow the diagnosis → - publishedSynology DSM · Synology Hyper Backup
Synology Hyper Backup Restore Only After an Integrity Check
Confirm the integrity-check finding, preserve recovery options, and identify the evidence needed for a destination-specific recovery plan.
Follow the diagnosis → - publishedSynology DSM · Synology Hyper Backup
Synology Hyper Backup Taking Longer Than Expected
Check task state, logs, NAS resources, and destination-specific signals when Hyper Backup is still running without a confirmed error.
Follow the diagnosis → - publishedSynology DSM · Synology Hyper Backup
Synology Hyper Backup Task Suspended After Interruption
Distinguish a resumable interruption from cancellation, identify the interruption context, and preserve the right backup-version expectations.
Follow the diagnosis → - publishedSynology DSM · Tailscale
Synology Tailscale Connected but NAS Is Unreachable
Separate tailnet connectivity, name resolution, the tailnet access policy, DSM firewall rules, and the exact Synology service port before changing the NAS.
Follow the diagnosis → - publishedSynology DSM · Tailscale
Synology Tailscale Subnet Router: LAN Device Unreachable
NAS access works, but a LAN service behind it does not. Separate subnet advertisement, CIDR, approval, access policy, client routing and target-side evidence.
Follow the diagnosis → - publishedTailscale
Tailscale Connection Stuck on DERP Relay
The connection works, but DERP persists during poor performance. Compare both peers and network observations before requesting a scoped network-owner investigation.
Follow the diagnosis → - publishedTrueNAS SCALE
TrueNAS SCALE SMB Share Exists but Client Access Is Denied
Confirm the share is reachable and the client authenticates as a Samba-enabled user, then separate the share ACL, the dataset (filesystem) ACL, the parent Traverse permission, and the share read-only and enumeration settings before any ACL change.
Follow the diagnosis → - publishedUnraid OS
Unraid Array Will Not Start
Match the exact Main Array Operation message first, then separate missing disks, device-limit, license, key-server, and withdrawn-release branches before any array, disk, or license change.
Follow the diagnosis → - publishedWireGuard
WireGuard Handshake Succeeds but Traffic Does Not Pass
Confirm the handshake is recent, separate a universal WireGuard configuration issue (AllowedIPs and routes) from a platform-specific Ubuntu Server gateway forwarding or NAT issue, then apply a bounded configuration or gateway change with console recovery and rollback.
Follow the diagnosis → - publishedZigbee2MQTT
Zigbee2MQTT Cannot Open the Adapter Serial Port
Separate a missing USB device from an incorrect serial path, runtime mapping, access denial or a competing coordinator owner.
Follow the diagnosis →