Natalia On-Premise troubleshooting

Network flows, collection incidents and appliance access. Wizard test codes are detailed in the error codes page. Case not listed? Contact [email protected].

Network flows

Flows needed on your LAN, whatever the contractual mode. Internet flows depend on the mode: see flows per mode.

Source Destination Port Use
AppliancePBX OXE22 TCPSSH/SCP ticket collection
AppliancePBX OXO30021 TCP + passive data portsEmbedded FTP ticket collection
Admin workstationsAppliance443 TCPWeb interface (HTTPS, TLS 1.2+)
Admin workstationsAppliance80 TCPRedirect to HTTPS, health probe

Collection incidents

Test OK, but no ticket collected

The first collection reports "no CDR file detected yet". On OXE, check the Taxation over IP license and that TAXA*, icals* or ocals* files exist in /usr4/account. A custom filename pattern can also exclude every file: empty it. On OXO, keep the default folder and pattern (account.gz).

OXO: recent calls missing

The tickets.gz file of /current/metering is a subset that can lag behind real time. Collect account.gz from /current/nmc, the default.

Collection stopped: "PBX SSH key changed"

The OXE presents a different SSH key. The appliance stops collecting this site rather than talk to an unknown machine. Confirm the change with your telephony team, then click "Re-approve the PBX key". Details: SSH_HOST_KEY.

Times shifted by one or two hours

The PBX clock is local. Check the site time zone set in the PBX configuration (Europe/Paris by default).

OXE: raw SSH messages

Useful when your telephony team reproduces the connection from a LAN workstation (ssh mtcl@<OXE-IP>).

Message Cause Resolution
Connection refusedSSH not enabled on the OXEnetadmin -m → Security → SSH
No route to hostWrong IP or routingCheck the IP and the VLAN between the appliance and the PBX
Permission denied (publickey,password)Wrong login or passwordCheck the account on the OXE
ls: /usr4/account: No such file or directoryTaxation over IP license inactive, or non-standard pathspadmin -l | grep -i account
scp: ... Permission deniedNo read right on /usr4/accountsetfacl -R -m u:<account>:rX /usr4/account/
Host key verification failedOXE key changed since pairingSSH_HOST_KEY

Appliance access

Where is the initial admin password?

It is displayed once on the serial console at first boot, and stored in the first-connection file of the data disk. The wizard asks for it, then makes you set a new one.

Admin password lost

There is no reset by email: the appliance sends no email. From the serial console, run as root:

natalia-reset-admin
bash

A new random password is applied to the admin account, displayed on the console and appended to the first-connection file.

The appliance does not start

At boot, the appliance checks that the data disk is mounted and writable, and that free space is sufficient. If a check fails, it stops and prints the reason on the serial console. Most frequent case: data disk not attached to the VM.

License banner displayed

The license is close to expiry or expired. Collection continues. See license lifecycle.

More context: the glossary (CDR, SCP, embedded FTP, mtcl…) and the error codes.

Last updated :

Suggest an edit