Tunnel Doctor
Cloudflare Tunnel 502 Troubleshooter
Diagnose why cloudflared can connect to Cloudflare but cannot reach the origin.
What this usually means
When the log says cloudflared cannot reach the origin, the Tunnel can still be connected to Cloudflare while the request fails between cloudflared and the configured origin service.
What it does not mean
A 502 does not automatically mean the Cloudflare edge or Tunnel connector is down. A connector availability problem is closer to Error 1033. First identify the failing hop from the log.
Typical redacted log
ERR Unable to reach the origin service: dial tcp [REDACTED_IP]:8080: connect: connection refused
Check in this order
These are baseline command examples. For Windows Service or Kubernetes, open the analyzer and select the actual environment to get platform-native commands.
curl -v --connect-timeout 5 <origin-url>nc -vz -w 3 <origin-host> <origin-port>cloudflared tunnel info <TUNNEL_NAME_OR_UUID>Common false diagnoses
- Restarting cloudflared before testing the origin.
- Disabling TLS verification when the actual problem is TCP reachability or an HTTP/HTTPS mismatch.
- Changing DNS without first confirming which hostname failed to resolve.
How to verify recovery
- The exact origin URL succeeds from cloudflared's network environment.
- The matching origin error stops appearing for new requests.
- A fresh request through the public hostname returns the expected application response.
Still unsure?
Paste the relevant cloudflared log into the local analyzer. Redaction is on by default and the log is not uploaded to a TRACER RECART backend.
Open analyzer