Troubleshooting library
What is going wrong?
Start with a symptom. Each page narrows the possible causes before suggesting a change.
Try “Synology”, “Tailscale”, or “NAS unreachable”
38 available problems
- Cloudflare Tunnel
Cloudflare Tunnel Is Connected but the Public Hostname Returns 502: Unable to Reach Origin Service
Confirm the tunnel is connected and the visitor sees the tunnel-specific 502 Unable to reach the origin service, then match the exact cloudflared log signature to a stopped origin, a wrong ingress scheme, a wrong ingress port, or an untrusted origin certificate.
Follow the diagnosis → - Docker Engine
Docker Container DNS Not Working: Separate IP Path from Name Resolution
Confirm the IP path first, then separate default-bridge and user-defined-bridge resolver behavior when a container reaches external IPs but hostname resolution fails.
Follow the diagnosis → - Docker Engine
Docker Container Has No Internet: Diagnose the Outbound Bridge Path
Separate container state, network mode, addressing, gateway, external IP reachability, and DNS when a running container on rootful Docker Engine bridge networking cannot reach external networks.
Follow the diagnosis → - Docker Engine
Docker Published Port Works Locally but Is Unreachable from the LAN
Compare the working local endpoint with the failing LAN endpoint before investigating publication, application listening context or filtering.
Follow the diagnosis → - ESPHome
ESPHome Device Is Online but Unavailable in Home Assistant
When an ESPHome device is on the network but Home Assistant cannot use it, separate endpoint identity, reachability from the HA runtime, native API port 6053, encryption, and runtime stability before reflashing.
Follow the diagnosis → - Frigate
Frigate Says “No Frames Have Been Received”
Use the exact Frigate 0.17.2 Stream Offline message and FFmpeg evidence to separate camera reachability, RTSP authentication/path, input preset, and decode failures without exposing camera credentials.
Follow the diagnosis → - Home Assistant
Home Assistant Matter Device Is Unavailable After Pairing
Start after successful Matter commissioning, then separate Matter Server health, Wi-Fi versus Thread transport, border-router continuity, IPv6, and multicast evidence without resetting the device or fabric.
Follow the diagnosis → - Home Assistant
Home Assistant Cannot Add a Matter over Thread Device
Confirm the device is a Matter-over-Thread unit that was never commissioned, then separate the Companion commissioning entry, border-router visibility, Thread credentials, and the local network stage before changing anything.
Follow the diagnosis → - Home Assistant
Home Assistant Blocks Requests from a Reverse Proxy Until It Is Trusted
Confirm direct access works, verify that Trust X-Forwarded-For and the proxy address are set as a network CIDR, then save and confirm the restart within the Home Assistant 2026.8 revert window.
Follow the diagnosis → - Immich
Immich Mobile Backup Stalls or Uploads Keep Failing
Verify whether expected originals are actually missing server-side on Immich 3.1.0, then separate album selection, background constraints, proxy path, storage, and dependency failures before touching any data or database.
Follow the diagnosis → - Jellyfin
Jellyfin Playback Failed Due to a Fatal Player Error
Reproduce one failing item on Jellyfin 12.0, correlate the client error with the server and FFmpeg logs at the same timestamp, and isolate whether the failure is at input, transcoding, output storage, or the client path before changing anything.
Follow the diagnosis → - Eclipse Mosquitto
Mosquitto Rejects the MQTT Client Connection
Prove TCP reachability to the broker first, then read the MQTT CONNACK refusal code and match the listener-specific authentication on Mosquitto 2.1.x before changing any broker configuration.
Follow the diagnosis → - Nextcloud
Nextcloud Shows “Access through untrusted domain”
Confirm the exact Nextcloud untrusted-domain error on 34.0.3, compare the browser hostname with trusted_domains, and make only the narrow trusted-host change supported by the evidence.
Follow the diagnosis → - Nginx Proxy Manager
Nginx Proxy Manager 502 Bad Gateway: Diagnose the Upstream
NPM opens and the proxy host exists, but requests through it return 502 Bad Gateway. Compare upstream reachability from the NPM network context and match the forward address and the proxy error log against a stopped upstream, a wrong port, a localhost or name-resolution mismatch, or a TLS scheme failure.
Follow the diagnosis → - Nginx Proxy Manager
Nginx Proxy Manager Let’s Encrypt Certificate Renewal Fails
Separate HTTP-01 reachability from DNS-01 credential or plugin failures on Nginx Proxy Manager 2.15.x, then respect exact ACME errors and rate limits instead of deleting certificates or data.
Follow the diagnosis → - Network UPS Tools
NUT Reports Data Stale for a USB UPS
Confirm the current stale response, then separate driver freshness, USB visibility, access and transport evidence without changing shutdown protection.
Follow the diagnosis → - OPNsense
OPNsense VLAN Client Gets an IP Address but Has No Internet
Use the expected DHCP lease only as a scope gate, then separate gateway reachability, DNS-only failure, firewall blocking, Source NAT coverage, and WAN routing on OPNsense 26.7.3.
Follow the diagnosis → - Pi-hole
Pi-hole Installed but Clients Get No DNS Response
Separate clients bypassing Pi-hole from Pi-hole answering nothing by checking FTL state, a direct query, the upstream path, port 53 ownership, and the effective client resolver before any upstream or DHCP change.
Follow the diagnosis → - Portainer
Portainer Agent Environment Is Unreachable
Scope the failure to a standard remote Portainer Agent environment, then separate Agent container state, server/Agent version mismatch, port reachability, and TLS evidence on Portainer CE 2.45 LTS.
Follow the diagnosis → - Proxmox VE
Proxmox LXC Container Has No Internet: Diagnose Bridge, Gateway and Firewall
Separate container addressing, bridge attachment, gateway reachability, firewall scope, and upstream path when a running Proxmox LXC container cannot reach the external network.
Follow the diagnosis → - Proxmox VE
Proxmox VE Host Has No Network After an 8-to-9 Upgrade
From a physical or independent console, compare enumerated links, bridge membership, addresses, and parsed configuration against the known pre-upgrade design after a Proxmox VE 8.4 to 9 upgrade, and stop before any change without recovery access.
Follow the diagnosis → - Proxmox VE
Proxmox VM Reaches Its Gateway but Cannot Reach the Internet
Separate guest addressing, resolution, bridge/segment evidence, outbound policy and upstream reachability after confirming the intended gateway responds.
Follow the diagnosis → - restic
restic Reports the Repository Is Already Locked
Capture the restic exit code, separate a still-running lock from a stale one, then use the documented unlock command without disabling locking for write operations.
Follow the diagnosis → - Syncthing
Syncthing Reports “Folder Marker Missing”
Treat .stfolder as a safety guard: prove the configured path, expected filesystem, and expected local data are present before recreating the marker or considering a folder reset in Syncthing 2.1.3.
Follow the diagnosis → - Synology DSM · Synology Hyper Backup
Synology Hyper Backup Insufficient Destination Quota
Inspect retained versions and destination usage before choosing a capacity or retention procedure, without deleting recovery points as a diagnostic test.
Follow the diagnosis → - Synology DSM · Synology Hyper Backup
Synology Hyper Backup Restore Only After an Integrity Check
Confirm the integrity-check finding, preserve recovery options, and identify the evidence needed for a destination-specific recovery plan.
Follow the diagnosis → - Synology DSM · Synology Hyper Backup · Tailscale
Synology Hyper Backup Destination Offline over Tailscale
Separate the Tailscale path from the Hyper Backup Vault service when a remote Synology destination over Tailscale cannot connect. Test from the source NAS, then the exact address, service port, and DSM 7 outbound access.
Follow the diagnosis → - Synology DSM · Synology Hyper Backup
Synology Hyper Backup Taking Longer Than Expected
Check task state, logs, NAS resources, and destination-specific signals when Hyper Backup is still running without a confirmed error.
Follow the diagnosis → - Synology DSM · Synology Hyper Backup
Synology Hyper Backup Task Suspended After Interruption
Distinguish a resumable interruption from cancellation, identify the interruption context, and preserve the right backup-version expectations.
Follow the diagnosis → - Synology DSM · Tailscale
Synology Tailscale Connected but NAS Is Unreachable
Separate tailnet connectivity, name resolution, the tailnet access policy, DSM firewall rules, and the exact Synology service port before changing the NAS.
Follow the diagnosis → - Synology DSM · Tailscale
Synology Tailscale Subnet Router: LAN Device Unreachable
NAS access works, but a LAN service behind it does not. Separate subnet advertisement, CIDR, approval, access policy, client routing and target-side evidence.
Follow the diagnosis → - Tailscale
Tailscale Connection Stuck on DERP Relay
The connection works, but DERP persists during poor performance. Compare both peers and network observations before requesting a scoped network-owner investigation.
Follow the diagnosis → - Tailscale
Tailscale Exit Node Is Connected but There Is No Internet
Separate exit-node approval and policy, Linux forwarding, the exit node's own upstream connectivity, client numeric-IP reachability, firewall/NAT evidence, and DNS on Tailscale 1.102.3.
Follow the diagnosis → - TrueNAS SCALE
TrueNAS SCALE SMB Share Exists but Client Access Is Denied
Confirm the share is reachable and the client authenticates as a Samba-enabled user, then separate the share ACL, the dataset (filesystem) ACL, the parent Traverse permission, and the share read-only and enumeration settings before any ACL change.
Follow the diagnosis → - Unraid OS
Unraid Array Will Not Start
Match the exact Main Array Operation message first, then separate missing disks, device-limit, license, key-server, and withdrawn-release branches before any array, disk, or license change.
Follow the diagnosis → - WireGuard
WireGuard Handshake Succeeds but Traffic Does Not Pass
Confirm the handshake is recent, separate a universal WireGuard configuration issue (AllowedIPs and routes) from a platform-specific Ubuntu Server gateway forwarding or NAT issue, then apply a bounded configuration or gateway change with console recovery and rollback.
Follow the diagnosis → - Zigbee2MQTT
Zigbee2MQTT Cannot Open the Adapter Serial Port
Separate a missing USB device from an incorrect serial path, runtime mapping, access denial or a competing coordinator owner.
Follow the diagnosis → - Z-Wave JS
Z-Wave JS Node Is Dead but the Controller Is Online
Use the exact Z-Wave JS node status to separate Dead from Asleep/Awake, then check communication evidence, power, and mesh path without removing the node or rebuilding the network.
Follow the diagnosis →