---
title: "Natalia On-Premise Troubleshooting | CDR Collection, Access - Natalia"
description: "Troubleshoot Natalia On-Premise: network flows, no ticket collected, PBX SSH key changed, lost admin password, appliance that does not start."
url: https://getnatalia.com/en/documentation/natalia-analytics-on-premise/troubleshooting
lang: en
---

[Home](https://getnatalia.com/en/) / [Documentation](https://getnatalia.com/en/documentation) / [On-Premise](https://getnatalia.com/en/documentation/natalia-analytics-on-premise) / Troubleshooting

# Natalia On-Premise troubleshooting

Network flows, collection incidents and appliance access. Wizard test codes are detailed in the [error codes](https://getnatalia.com/en/documentation/natalia-analytics-on-premise/error-codes) page. Case not listed? Contact [contact@getnatalia.com](mailto:contact@getnatalia.com).

## Network flows

Flows needed on your LAN, whatever the contractual mode. Internet flows depend on the mode: see [flows per mode](https://getnatalia.com/en/documentation/natalia-analytics-on-premise/installation#flux-reseau).

| Source | Destination | Port | Use |
| --- | --- | --- | --- |
| Appliance | PBX OXE | `22` TCP | SSH/SCP ticket collection |
| Appliance | PBX OXO | `30021` TCP + passive data ports | Embedded FTP ticket collection |
| Admin workstations | Appliance | `443` TCP | Web interface (HTTPS, TLS 1.2+) |
| Admin workstations | Appliance | `80` TCP | Redirect to HTTPS, health probe |

## Collection incidents

Test OK, but no ticket collected

The first collection reports "no CDR file detected yet". On OXE, check the [Taxation over IP license](https://getnatalia.com/en/documentation/natalia-analytics-on-premise/oxe-configuration#taxation) and that `TAXA*`, `icals*` or `ocals*` files exist in `/usr4/account`. A custom filename pattern can also exclude every file: empty it. On OXO, keep the default folder and pattern (`account.gz`).

OXO: recent calls missing

The tickets.gz file of /current/metering is a subset that can lag behind real time. Collect account.gz from /current/nmc, the default.

Collection stopped: "PBX SSH key changed"

The OXE presents a different SSH key. The appliance stops collecting this site rather than talk to an unknown machine. Confirm the change with your telephony team, then click "Re-approve the PBX key". Details: [SSH\_HOST\_KEY](https://getnatalia.com/en/documentation/natalia-analytics-on-premise/error-codes#hostkey).

Times shifted by one or two hours

The PBX clock is local. Check the site time zone set in the PBX configuration (Europe/Paris by default).

## OXE: raw SSH messages

Useful when your telephony team reproduces the connection from a LAN workstation (ssh mtcl@<OXE-IP>).

| Message | Cause | Resolution |
| --- | --- | --- |
| `Connection refused` | SSH not enabled on the OXE | `netadmin -m` → Security → SSH |
| `No route to host` | Wrong IP or routing | Check the IP and the VLAN between the appliance and the PBX |
| `Permission denied (publickey,password)` | Wrong login or password | Check the account on the OXE |
| `ls: /usr4/account: No such file or directory` | Taxation over IP license inactive, or non-standard path | `spadmin -l | grep -i account` |
| `scp: ... Permission denied` | No read right on /usr4/account | `setfacl -R -m u:<account>:rX /usr4/account/` |
| `Host key verification failed` | OXE key changed since pairing | [SSH\_HOST\_KEY](https://getnatalia.com/en/documentation/natalia-analytics-on-premise/error-codes#hostkey) |

## Appliance access

Where is the initial admin password?

It is displayed once on the serial console at first boot, and stored in the first-connection file of the data disk. The wizard asks for it, then makes you set a new one.

Admin password lost

There is no reset by email: the appliance sends no email. From the serial console, run as root:

```bash
natalia-reset-admin
```

bash

A new random password is applied to the admin account, displayed on the console and appended to the first-connection file.

The appliance does not start

At boot, the appliance checks that the data disk is mounted and writable, and that free space is sufficient. If a check fails, it stops and prints the reason on the serial console. Most frequent case: data disk not attached to the VM.

License banner displayed

The license is close to expiry or expired. Collection continues. See [license lifecycle](https://getnatalia.com/en/documentation/natalia-analytics-on-premise/license-lifecycle).

More context: the [glossary](https://getnatalia.com/en/documentation/natalia-analytics-on-premise/glossary) (CDR, SCP, embedded FTP, mtcl…) and the [error codes](https://getnatalia.com/en/documentation/natalia-analytics-on-premise/error-codes).

Last updated : October 5, 2026

[Suggest an edit](mailto:doc@getnatalia.com?subject=Doc%20edit%3A%20natalia-analytics-on-premise%2Ftroubleshooting)
