Cloudflare Tunnel (fixed broken by http block firewall rule)

youd need to access the machine a different way and check the logs
30 Replies
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
depends how you installed cloudflared if you installed a service, sudo journalctl -u cloudflared -f and then reproduce the issue and it should appear
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
yes so try doing that while the log tail is open and see if it logs any errors
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
Ctrl+C
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
Thats weird then
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
normally you want to set the IP to localhost (127.0.0.1)
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
Is there anything in your browsers console or network log in devtools when you try accessing SSH? Have you tried connecting from SSH CLI (cloudflared access ssh-config, add the config and then ssh to it) And as weird as it sounds, have you checked Cloudflare's Firewall logs
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
Errors or just warnings?
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
Does it tell you why and is it definitely the right domain?
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
Alright Had one like this before, someone changed a rule to make it more strict and it broke all their SSH
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
They didn't realise it applied to SSH but those are done over HTTPS so the same settings take effect
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
¯\_(ツ)_/¯ thats controlled by your browser, and may be different for websockets, impossible to know for sure
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
this is why blocking based on http version is not actually as smart as it seems, because browsers use older versions for all kinds of strange reasons we cant fathom
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
it looks like chrome may prefer http 1.1 for websockets
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
no idea why, but there you are
Unknown User
Unknown User2y ago
Message Not Public
Sign In & Join Server To View
Erisa
Erisa2y ago
no problem, anytime