XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Internet connectivity - Check XOA failed.

    Scheduled Pinned Locked Moved Unsolved Management
    6 Posts 4 Posters 63 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      zorro
      last edited by

      The internet check was timing out on the IPv6 address for xen-orchestra.com IPv4 was fine the whole time.

      curl -4 -I --max-time 15 https://xen-orchestra.com/ # HTTP/2 200
      curl -6 -I --max-time 15 https://xen-orchestra.com/ # couldn't connect

      What fixed it was disabling IPv6 at boot, then rebooting so xo-server starts with it already off:

      printf '%s\n' 'net.ipv6.conf.all.disable_ipv6=1' 'net.ipv6.conf.default.disable_ipv6=1' | sudo tee /etc/sysctl.d/99-disable-ipv6.conf

      After that, xoa check was green, including internet connectivity and no more check for upgrade issues. I'm hoping this fixes my XO Config Cloud Backup. I will report back if not.

      ✖ 17/17 - Internet connectivity: Error: HTTP connection has timed out
      at ClientRequest.<anonymous> (/usr/local/lib/node_modules/xoa-cli/node_modules/http-request-plus/index.js:61:25)
      at ClientRequest.emit (node:events:519:28)
      at ClientRequest.patchedError [as emit] (file:///usr/local/lib/node_modules/xoa-cli/index.mjs:31:17)
      at TLSSocket.emitRequestTimeout (node:_http_client:927:9)
      at Object.onceWrapper (node:events:633:28)
      at TLSSocket.emit (node:events:531:35)
      at TLSSocket.patchedError [as emit] (file:///usr/local/lib/node_modules/xoa-cli/index.mjs:31:17)
      at Socket._onTimeout (node:net:604:8)
      at listOnTimeout (node:internal/timers:585:17)
      at process.processTimers (node:internal/timers:521:7) {
      url: 'https://xen-orchestra.com/',
      originalUrl: 'http://xen-orchestra.com/'
      }

      XOA Update sometimes failed too but hitting Refresh a couple times got it going.
      10/1/2026, 10:03:28 AM: All up to date
      10/1/2026, 10:26:26 AM: Start updating...
      10/1/2026, 10:26:32 AM: HTTP connection has timed out
      10/1/2026, 10:27:14 AM: Start updating...
      10/1/2026, 10:27:14 AM: stable channel selected
      10/1/2026, 10:27:14 AM: All up to date

      poddingueP 1 Reply Last reply
      Reply Quote 1
      • poddingueP poddingue marked this topic as a question
      • poddingueP
        poddingue Vates 🪐 @zorro
        last edited by

        Thanks for posting the fix. 👍

        The same thing came up in an older thread, https://xcp-ng.org/forum/topic/9957, where disabling IPv6 also made xoa check go green.

        @HamiltonWDS explained a likely reason in https://xcp-ng.org/forum/post/87831: Node tries the addresses with a short timeout and can end up on the IPv6 one. 🤷
        Your curl -6 test helps a lot here, because it shows IPv6 doesn't connect at all on that network, so it's more than a slow path.

        Turning it off in XOA seems reasonable if you don't use IPv6 there; if you do, I'd guess the router side is where it really needs fixing, though I could be wrong (still haven't migrated to IPv6 myself 😊 ).

        Curious whether it sorts out the Cloud Backup too.

        acebmxerA 1 Reply Last reply
        Reply Quote 0
        • acebmxerA
          acebmxer @poddingue
          last edited by acebmxer

          @poddingue

          I had issue with a remote xo proxy.. showed error in xoa untill i disabled ipv6. But only with one of two remote proxies. This was in a support ticket.

          J 1 Reply Last reply
          Reply Quote 0
          • J
            john.c @acebmxer
            last edited by john.c

            @acebmxer said:

            @poddingue

            I had issue with a remote proxy.. showed error in xoa untill i disabled ipv6. But only with one of two remote proxies. This was in a support ticket.

            Did you test your full stack IP v6 readiness with one of the online testers? The reason being your local LAN maybe ready even at your router level, but if your ISP doesn’t have full stack (or even dual full stack - v4 and v6) then FQDN addresses which are only on IP v6 only may not work). Also v4 and v6 IP address has to also be associated with the FQDN being contacted.

            acebmxerA 1 Reply Last reply
            Reply Quote 0
            • acebmxerA
              acebmxer @john.c
              last edited by

              @john.c

              We currently dont use ipv6 internally. No network changes were made at this location other then moving the proxy to the correct network for nbd connections. With that move some how made the ipv6 issue appear. So it was just easy to disable ipv6 in the proxy. I guess if we ever switch to ipv6 (no plans too) then i guess i will have to look back into it.

              J 1 Reply Last reply
              Reply Quote 0
              • J
                john.c @acebmxer
                last edited by john.c

                @acebmxer said:

                @john.c

                We currently dont use ipv6 internally. No network changes were made at this location other then moving the proxy to the correct network for nbd connections. With that move some how made the ipv6 issue appear. So it was just easy to disable ipv6 in the proxy. I guess if we ever switch to ipv6 (no plans too) then i guess i will have to look back into it.

                If any of your VMs are facing the public internet, completing your IPv6 Readiness compliance is vital. With regional internet registries completely exhausted of free-pool IPv4 space, modern endpoints and cloud architectures are increasingly deploying IPv6-only infrastructure.

                If you are referring to an internet access proxy, disabling IPv6 introduces significant architectural risk. If any upstream transit provider, carrier, or edge CDN in the path to your target FQDN transitions to an IPv6-only topology, your access path will break, causing a hard outage. If you are specifically utilizing a transit provider like XO Proxy, transitioning to dual-stack or IPv6-only transport is even more critical to ensure deterministic routing across the wider internet footprint.

                From an architecture and security standpoint, IPv6 introduces critical enterprise enhancements:

                • SLAAC Privacy Extensions: Enables temporary, rotating addresses to mitigate device fingerprinting and endpoint tracking.
                • Native IPSec Integration: While RFC 8200 technically shifted IPSec from a hard protocol requirement to an optional component, it remains a native architectural element of the IPv6 stack. Unlike IPv4—where IPSec must be bolted on as an awkward overlay—IPv6 accommodates encryption headers natively, simplifying the deployment of secure end-to-end transport encryption across enterprise and government domains.

                If you need to pitch this network-wide transition to leadership for project approval, I highly recommend framing it around business continuity and risk mitigation. Pointing out the looming vulnerability of upstream IPv6-only transit paths—combined with the compliance advantages of native architectural security—should give you the exact leverage needed to get this budgeted, planned, and implemented.

                1 Reply Last reply
                Reply Quote 0

                Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                With your input, this post could be even better 💗

                Register Login
                • First post
                  Last post