Natalia On-Premise troubleshooting
Network flows, collection incidents and appliance access. Wizard test codes are detailed in the error codes page. Case not listed? Contact [email protected].
Network flows
Flows needed on your LAN, whatever the contractual mode. Internet flows depend on the mode: see flows per mode.
| Source | Destination | Port | Use |
|---|---|---|---|
| Appliance | PBX OXE | 22 TCP | SSH/SCP ticket collection |
| Appliance | PBX OXO | 30021 TCP + passive data ports | Embedded FTP ticket collection |
| Admin workstations | Appliance | 443 TCP | Web interface (HTTPS, TLS 1.2+) |
| Admin workstations | Appliance | 80 TCP | Redirect to HTTPS, health probe |
Collection incidents
Test OK, but no ticket collected
The first collection reports "no CDR file detected yet". On OXE, check the Taxation over IP license and that TAXA*, icals* or ocals* files exist in /usr4/account. A custom filename pattern can also exclude every file: empty it. On OXO, keep the default folder and pattern (account.gz).
OXO: recent calls missing
The tickets.gz file of /current/metering is a subset that can lag behind real time. Collect account.gz from /current/nmc, the default.
Collection stopped: "PBX SSH key changed"
The OXE presents a different SSH key. The appliance stops collecting this site rather than talk to an unknown machine. Confirm the change with your telephony team, then click "Re-approve the PBX key". Details: SSH_HOST_KEY.
Times shifted by one or two hours
The PBX clock is local. Check the site time zone set in the PBX configuration (Europe/Paris by default).
OXE: raw SSH messages
Useful when your telephony team reproduces the connection from a LAN workstation (ssh mtcl@<OXE-IP>).
| Message | Cause | Resolution |
|---|---|---|
Connection refused | SSH not enabled on the OXE | netadmin -m → Security → SSH |
No route to host | Wrong IP or routing | Check the IP and the VLAN between the appliance and the PBX |
Permission denied (publickey,password) | Wrong login or password | Check the account on the OXE |
ls: /usr4/account: No such file or directory | Taxation over IP license inactive, or non-standard path | spadmin -l | grep -i account |
scp: ... Permission denied | No read right on /usr4/account | setfacl -R -m u:<account>:rX /usr4/account/ |
Host key verification failed | OXE key changed since pairing | SSH_HOST_KEY |
Appliance access
Where is the initial admin password?
It is displayed once on the serial console at first boot, and stored in the first-connection file of the data disk. The wizard asks for it, then makes you set a new one.
Admin password lost
There is no reset by email: the appliance sends no email. From the serial console, run as root:
natalia-reset-admin
bash
A new random password is applied to the admin account, displayed on the console and appended to the first-connection file.
The appliance does not start
At boot, the appliance checks that the data disk is mounted and writable, and that free space is sufficient. If a check fails, it stops and prints the reason on the serial console. Most frequent case: data disk not attached to the VM.
License banner displayed
The license is close to expiry or expired. Collection continues. See license lifecycle.
More context: the glossary (CDR, SCP, embedded FTP, mtcl…) and the error codes.