From 36c52d8860241158aceb484352ba4c7ec4ecaa09 Mon Sep 17 00:00:00 2001 From: Vuong Hoang Date: Fri, 2 Oct 2026 22:53:30 -0700 Subject: [PATCH] docs(meshcentral): stale CIRA tunnel reproduced on a single shutdown --- servers/pfi-tacticalrmm/README.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/servers/pfi-tacticalrmm/README.md b/servers/pfi-tacticalrmm/README.md index f96d2fd..2d0e12a 100644 --- a/servers/pfi-tacticalrmm/README.md +++ b/servers/pfi-tacticalrmm/README.md @@ -64,8 +64,9 @@ Monitors and manages endpoints, pushes patches, runs scripts, etc. **Fix:** `sudo ss -tnio state established "( sport = :4433 )"`. Find the device's public IP with a large `lastrcv` (ms) or a `backoff`. Healthy tunnels show `lastrcv` of seconds. Then `sudo ss -K -tn "dst [::ffff:]:"`. Verify with `scripts/meshcentral-amt-relay-probe.js`, using - another AMT as a positive control. Likely whenever a host whose AMT shares its NIC (esh-pve-2) power-cycles. - Seen once so far. + another AMT as a positive control. Seen twice on esh-pve-2. The second time, one graceful shutdown from MeshCentral (22:48:52) left the old + tunnel dead within seconds, and it was gone by 2252. The first one lingered 13+ min, probably because repeated + connect attempts kept writing to it (inferred). - Before 2026-10-02: `"WANonly": true` (TacticalRMM's install default). In that mode MeshCentral SILENTLY DROPS "Add Intel AMT computer": `meshuser.js` line 2682, `if (args.wanonly == true) return;`. No error, no event. LAN-mode AMT needs `WANonly` false (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM's