Troubleshoot a noobtunnel connection
A public tunnel has several stages. Testing them in order gives you a useful failure report and avoids changing unrelated routes or firewall rules. Work only on devices and services you are allowed to inspect.
Start at the application
Request the backend from the agent's machine or container using its configured host, port and protocol. If that fails, check whether the process is running, which address it listens on and whether a local firewall blocks that port. A backend bound to 127.0.0.1 cannot be reached as localhost from a different container or host.
Check the backend's own logs at the test time. A successful request from your browser on the application machine is not enough when the agent uses a different network namespace.
Check the agent and mesh separately
Look for the agent's online status and recent handshake or connection information. If it is offline, inspect its service log and outbound route to the configured control endpoint. Verify the clock and certificate settings instead of disabling certificate validation.
For a private mesh problem, test the destination's mesh address and application port from another enrolled device. If the control panel works but mesh traffic fails, inspect the mesh route, destination firewall and application listener. The control connection and the WireGuard data path are separate.
Verify the public exit and DNS
Read the exit assigned to the resource and compare it with the public hostname's DNS records. An A record pointing at the control panel instead of the chosen publishing exit can send the request to the wrong machine. Check AAAA records too; an outdated IPv6 record can cause failures for some visitors while IPv4 tests succeed.
DNS caches can retain older answers until their TTL expires. Compare the authoritative records with what your client resolves. Test the actual public hostname from an external connection and note which address it reached.
Separate TLS and proxy errors
A certificate name mismatch means the connection reached an endpoint that did not present a certificate valid for your hostname. Confirm the domain verification, DNS and certificate status. A visitor-facing valid certificate does not prove that the backend HTTPS connection is configured correctly.
If the proxy returns a gateway error, compare its request log with the backend log. No backend request suggests a failure before the application: address, port, agent route or protocol. A backend request with an application error points to the application itself. Allowance exhaustion can also change behavior; check the resource's monthly usage and the published limits.
Prepare a useful report
Record the public hostname, affected resource, UTC time, resolved IP, response code and whether local backend and mesh tests succeeded. Include a short sanitized log excerpt. Send private service reports through Contact; remove cookies, passwords, tokens and private keys.