Troubleshooting
When something does not work, run juist status first. It says what needs attention and prints a hint with the fix. This page lists the common cases.
Where to look
Run this on the device that has the problem:
juist statusWarnings start with warning: and come below the device table. Each is
followed by a hint: line with the command to run. Any local user may run
juist status; see Status and devices for what
each line means.
For more detail, read the daemon’s own log:
journalctl -u juistdA second network on the same device has its own daemon and log:
journalctl -u juistd@juist1.
Common problems
juistd not running
The daemon, the program that keeps the tunnels up, is not running. Start it:
sudo systemctl enable --now juistdFor a second network on the device, the daemon is juistd@juist1. On
FreeBSD, service juistd start. See Install.
read-only; to manage this device …
You are not root and not the device’s operator, the local user who may manage it without sudo. You can see the status, and nothing more. Make yourself the operator, once:
sudo juist set --operator=$USERno answer from nas: offline, or udp/41643 blocked
The device nas did not answer. Either it is switched off or offline, or a
firewall in front of it closes port 41643/udp. Check that it is running. If it
has a public address, open 41643/udp there. See
Relays.
no tunnel traffic from nas
nas is known, but no traffic arrives from it. Port 41643/udp is blocked, or
both devices sit behind NAT and there is no relay, a member that passes traffic
between devices that cannot reach each other. Open 41643/udp on a device with a
public address, as the hint says:
hint: on a device with a public address: sudo ufw allow juist, or firewall-cmd --add-service=juist
Or make such a device a relay with juist grant vps relay. See
Relays.
no device reaches this relay
This device is a relay, but no other device gets through to it. Port 41645 is likely closed, for TCP or UDP. Open both on the relay, and in any firewall in front of it, such as your hosting provider’s:
sudo ufw allow juist-relayWith firewalld: sudo firewall-cmd --permanent --add-service=juist-relay && sudo firewall-cmd --reload.
See Relays.
log sync to nas fails in the tunnel
The tunnel works, but a firewall on this host drops the log sync inside it,
TCP 41644 on juist0. The device then misses changes to the network,
removals included. Let juist0 in, on both devices, as the hint says:
hint: on both devices: sudo ufw allow in on juist0, or add juist0 to firewalld's trusted zone
Where firewalld is the cause, juist status says firewalld blocks juist0
and gives the command for it. See Relays.
no device may relay
In a network of more than two devices, no device is allowed to relay. Devices behind strict NATs need one. On an admin’s device, give the role to a device with a public address:
juist grant vps relaySee Relays.
Freshness expired; vouchers only
No voucher has been reachable for 48 hours. A voucher is a device that
confirms every hour that the network’s state is current. Until one does again,
this device keeps tunnels only to vouchers, and its state reads limited.
Bring a voucher back online. See
Removing a device.
removed
This device is no longer in the network. To use it again, join with a new invite, or start over:
juist resetSee Removing a device and Invites.
no IPv4 on this host
This device is in two networks whose IPv4 ranges overlap. The second one then works over IPv6 only. Move one of them to another range, for example:
juist network renumber work 10.7.0.0/24See Several networks.
Exit node vps, internet refused: …
This device sends its internet traffic through the exit node vps, but cannot
use it right now, for example because vps cannot be reached. juist then
refuses the traffic rather than send it directly. Bring vps back, or go
direct again:
juist exit offSee Exit nodes.
this device does not serve: IP forwarding is off …
This device is meant to be an exit node, but the host does not forward traffic. Run this again on it; it sets the host up with sudo:
juist exit serveSee Exit nodes.
DNS goes to …, outside the tunnel: systemd-resolved refused juistd …
While you use an exit node, systemd-resolved did not let juistd send DNS through the tunnel, so lookups go out directly. The juist package brings a polkit rule that allows juistd to do this. Install juist as the package. See Install and Names.