Tunnel Doctor
Cloudflare Tunnel TLS Handshake Troubleshooter
Identify HTTP/HTTPS mismatches and certificate validation failures.
What this usually means
A TLS-related Tunnel failure can come from different classes: the port may actually speak HTTP, the certificate may be untrusted or for another name, SNI may be wrong, or the handshake itself may fail.
What it does not mean
Turning on noTLSVerify is not a general TLS fix. It cannot repair an HTTP/HTTPS scheme mismatch and it can hide a real certificate trust or hostname problem.
Typical redacted log
Unable to reach the origin service: remote error: tls: handshake failure
Check in this order
These are baseline command examples. For Windows Service or Kubernetes, open the analyzer and select the actual environment to get platform-native commands.
curl -vk --connect-timeout 5 https://<origin-host>:<origin-port>/openssl s_client -connect <origin-host>:<origin-port> -servername <certificate-host> </dev/nullcurl -v http://<origin-host>:<origin-port>/Common false diagnoses
- Assuming every TLS string means an invalid certificate.
- Disabling verification before checking whether the port is plain HTTP.
- Changing certificates before identifying whether the failed TLS hop is the origin or the Cloudflare edge.
How to verify recovery
- The origin answers using the configured HTTP/HTTPS scheme.
- For HTTPS, the expected server name completes a valid handshake.
- Fresh Tunnel requests no longer emit the same TLS family error.
Still unsure?
Paste the relevant cloudflared log into the local analyzer. Redaction is on by default and the log is not uploaded to a TRACER RECART backend.
Open analyzer