Troubleshooting Common Issues

Quick Reference Guide

Issue 1: Tunnel Health Check Failing

  • Check: Customer allows ICMP from Cloudflare IPs
  • Check: GRE tunnel is up on customer side
  • Check: No firewall blocking GRE (protocol 47)

Issue 2: Endpoint Health Check Failing

  • Check: Customer allows ICMP from Cloudflare IPs
  • Check: Target endpoint is reachable
  • Check: No ACLs blocking probes

Issue 3: Prefix Not Advertising

  • Check: IRR entries valid
  • Check: LOA approved
  • Check: Prefixes unlocked in Ninja Panel
  • Check: RPKI valid (if using RPKI)

Issue 4: Traffic Drops/MSS Issues

  • Check: MSS clamp applied (1436 or lower)
  • Check: Applied on WAN interface, not tunnel