Connection failures can come from an unreachable node address, a blocked port, mismatched protocol parameters, incorrect TLS/SNI, incorrect system time, or local network restrictions. If every node in a group fails, synchronize system time and retest on another network. If only one node fails, give the provider the node name, log time, and relevant error.
Did DNS, TCP, TLS, or authentication fail?
Switch to another node from the same subscription and inspect the first failure in the log: lookup indicates resolution, dial indicates the address or port, and handshake or x509 indicates the protocol or certificate.
- Was the subscription just updated, and did the node address or port change?
- Does the log show a DNS, TCP, TLS, handshake, or authentication error?(See Outbound proxy configuration)
- Are system time and time zone correct?
- Do other clients or devices also fail on the same network?
Switch nodes and rule out time or local network problems
- Switch to another node in the same subscription to determine whether only one node is affected
- Check system time; TLS-based protocols are sensitive to clock drift
- Use the error stage in the log to troubleshoot DNS, connection, and handshake separately(See Log Troubleshooting FAQ)
- If every node fails, verify the local firewall, proxy mode, and system proxy status
Node connectivity depends on both the configuration provider and network environment
A successful subscription update does not mean proxy nodes are reachable
Do not post complete node URLs or subscription tokens publicly
