Tunnel Doctor by TRACER RECART中文
Tunnel Doctor

Cloudflare Tunnel TLS Handshake Troubleshooter

Identify HTTP/HTTPS mismatches and certificate validation failures.

Open this case in the local analyzer

What this usually means

A TLS-related Tunnel failure can come from different classes: the port may actually speak HTTP, the certificate may be untrusted or for another name, SNI may be wrong, or the handshake itself may fail.

What it does not mean

Turning on noTLSVerify is not a general TLS fix. It cannot repair an HTTP/HTTPS scheme mismatch and it can hide a real certificate trust or hostname problem.

Typical redacted log

Unable to reach the origin service: remote error: tls: handshake failure

Check in this order

These are baseline command examples. For Windows Service or Kubernetes, open the analyzer and select the actual environment to get platform-native commands.

curl -vk --connect-timeout 5 https://<origin-host>:<origin-port>/openssl s_client -connect <origin-host>:<origin-port> -servername <certificate-host> </dev/nullcurl -v http://<origin-host>:<origin-port>/

Common false diagnoses

  • Assuming every TLS string means an invalid certificate.
  • Disabling verification before checking whether the port is plain HTTP.
  • Changing certificates before identifying whether the failed TLS hop is the origin or the Cloudflare edge.

How to verify recovery

  • The origin answers using the configured HTTP/HTTPS scheme.
  • For HTTPS, the expected server name completes a valid handshake.
  • Fresh Tunnel requests no longer emit the same TLS family error.

Still unsure?

Paste the relevant cloudflared log into the local analyzer. Redaction is on by default and the log is not uploaded to a TRACER RECART backend.

Open analyzer