docs(meshcentral): stale CIRA tunnel reproduced on a single shutdown

This commit is contained in:
vh
2026-10-02 22:53:30 -07:00
parent ad0322bf83
commit 36c52d8860
+3 -2
View File
@@ -64,8 +64,9 @@ Monitors and manages endpoints, pushes patches, runs scripts, etc.
**Fix:** `sudo ss -tnio state established "( sport = :4433 )"`. Find the device's public IP with a large **Fix:** `sudo ss -tnio state established "( sport = :4433 )"`. Find the device's public IP with a large
`lastrcv` (ms) or a `backoff`. Healthy tunnels show `lastrcv` of seconds. Then `lastrcv` (ms) or a `backoff`. Healthy tunnels show `lastrcv` of seconds. Then
`sudo ss -K -tn "dst [::ffff:<ip>]:<its port>"`. Verify with `scripts/meshcentral-amt-relay-probe.js`, using `sudo ss -K -tn "dst [::ffff:<ip>]:<its port>"`. Verify with `scripts/meshcentral-amt-relay-probe.js`, using
another AMT as a positive control. Likely whenever a host whose AMT shares its NIC (esh-pve-2) power-cycles. another AMT as a positive control. Seen twice on esh-pve-2. The second time, one graceful shutdown from MeshCentral (22:48:52) left the old
Seen once so far. tunnel dead within seconds, and it was gone by 2252. The first one lingered 13+ min, probably because repeated
connect attempts kept writing to it (inferred).
- Before 2026-10-02: `"WANonly": true` (TacticalRMM's install default). In that mode MeshCentral SILENTLY DROPS - Before 2026-10-02: `"WANonly": true` (TacticalRMM's install default). In that mode MeshCentral SILENTLY DROPS
"Add Intel AMT computer": `meshuser.js` line 2682, `if (args.wanonly == true) return;`. No error, no "Add Intel AMT computer": `meshuser.js` line 2682, `if (args.wanonly == true) return;`. No error, no
event. LAN-mode AMT needs `WANonly` false (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM's event. LAN-mode AMT needs `WANonly` false (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM's