# General Questions

**URL:** https://openziti.discourse.group/c/support/general-questions/7.md?page=2

[Latest](https://openziti.discourse.group/latest.md) · [Categories](https://openziti.discourse.group/categories.md)

**Page:** 3

---

## [Suggested Configuration for High Traffic Apps hosted through ziti](https://openziti.discourse.group/t/suggested-configuration-for-high-traffic-apps-hosted-through-ziti/4761)

<div class="topic-metadata">

**Author:** [@rsatrio](https://openziti.discourse.group/u/rsatrio)\
**Replies:** 4\
**Last updated:** [July 11, 2025, 11:56am UTC](https://openziti.discourse.group/t/suggested-configuration-for-high-traffic-apps-hosted-through-ziti/4761 "2025-07-11T11:56:50Z")

</div>

Hi, I'm looking for some guidance on the best practices for configuring Ziti to secure and share a message queue application. My specific use case involves a persistent TCP connection to the message queue, and I need to…

---

## [Fail2ban jail for openziti controllwe](https://openziti.discourse.group/t/fail2ban-jail-for-openziti-controllwe/4852)

<div class="topic-metadata">

**Author:** [@Tikal](https://openziti.discourse.group/u/Tikal)\
**Replies:** 0\
**Last updated:** [July 9, 2025, 4:31pm UTC](https://openziti.discourse.group/t/fail2ban-jail-for-openziti-controllwe/4852 "2025-07-09T16:31:03Z")

</div>

Hi. does anyone have a fail2ban jail config for openziti controller for authentications coming from the web and SDK. Thank you

---

## [Browzer bootstrap related question](https://openziti.discourse.group/t/browzer-bootstrap-related-question/3794)

<div class="topic-metadata">

**Author:** [@ss\_vinoth22](https://openziti.discourse.group/u/ss_vinoth22)\
**Replies:** 13\
**Last updated:** [July 8, 2025, 4:31pm UTC](https://openziti.discourse.group/t/browzer-bootstrap-related-question/3794 "2025-07-08T16:31:07Z")

</div>

I’ve recently enabled Ziti BrowZer Runtime (ZBR) for my demo environment and am planning to enable it for production soon. However, I’d like to streamline the user experience by disabling a few options to make it more in…

---

## [Replacing Site-to-Site VPN with OpenZiti (ZAC) — Guidance Needed](https://openziti.discourse.group/t/replacing-site-to-site-vpn-with-openziti-zac-guidance-needed/4817)

<div class="topic-metadata">

**Author:** [@iamroot](https://openziti.discourse.group/u/iamroot)\
**Replies:** 1\
**Last updated:** [July 1, 2025, 3:52pm UTC](https://openziti.discourse.group/t/replacing-site-to-site-vpn-with-openziti-zac-guidance-needed/4817 "2025-07-01T15:52:31Z")

</div>

Dear OpenZiti Team, First of all, thank you for building such an amazing platform. We’ve been actively exploring OpenZiti and have successfully implemented various scenarios — everything is working great so far. Curren…

---

## [Linux ext-jwt-signer w/Google OIDC](https://openziti.discourse.group/t/linux-ext-jwt-signer-w-google-oidc/4798)

<div class="topic-metadata">

**Author:** [@Daryll](https://openziti.discourse.group/u/Daryll)\
**Replies:** 12\
**Last updated:** [July 1, 2025, 11:21am UTC](https://openziti.discourse.group/t/linux-ext-jwt-signer-w-google-oidc/4798 "2025-07-01T11:21:36Z")

</div>

I'm new with Ziti, so I'm trying to figure out all the configuration options. My first success was to run the linux-edge-tunnel with a host token. All good. DNS sees my ziti hosts and I can reach my service. My next st…

---

## [iOS unable to connect after edge router certificate rolled](https://openziti.discourse.group/t/ios-unable-to-connect-after-edge-router-certificate-rolled/4548)

<div class="topic-metadata">

**Author:** [@gooseleggs](https://openziti.discourse.group/u/gooseleggs)\
**Replies:** 7\
**Last updated:** [June 13, 2025, 12:32pm UTC](https://openziti.discourse.group/t/ios-unable-to-connect-after-edge-router-certificate-rolled/4548 "2025-06-13T12:32:05Z")

</div>

So, I updated my iPhone to 18.5 yesterday. After restart Ziti client on the phone is not working. I checked with my laptop and that was working as expected. I started nosing around, and found that it appears that the …

---

## [Secure and Recommended OpenZiti Deployment?](https://openziti.discourse.group/t/secure-and-recommended-openziti-deployment/4709)

<div class="topic-metadata">

**Author:** [@Sjoerd\_van\_Eindhoven](https://openziti.discourse.group/u/Sjoerd_van_Eindhoven)\
**Replies:** 6\
**Last updated:** [June 7, 2025, 12:11pm UTC](https://openziti.discourse.group/t/secure-and-recommended-openziti-deployment/4709 "2025-06-07T12:11:09Z")

</div>

Hi All, I have set up 3 Ubuntu VMs, each residing in its own VLAN, as described in my current setup here: I plan to add Microsoft Entra ID for authentication, following the guide here: My main concerns are: Is thi…

---

## [Ziti Configurations (forward versus non forward)](https://openziti.discourse.group/t/ziti-configurations-forward-versus-non-forward/4711)

<div class="topic-metadata">

**Author:** [@Crystech](https://openziti.discourse.group/u/Crystech)\
**Replies:** 2\
**Last updated:** [June 6, 2025, 6:23pm UTC](https://openziti.discourse.group/t/ziti-configurations-forward-versus-non-forward/4711 "2025-06-06T18:23:07Z")

</div>

Hi all, I'm currently developing an API to automate configuration creation and would appreciate some clarification on the following: In ZAC, I noticed there are two options for service configurations: Forwarding and N…

---

## [HA OIDC 404 / unexpected content-type](https://openziti.discourse.group/t/ha-oidc-404-unexpected-content-type/4383)

<div class="topic-metadata">

**Author:** [@blup66](https://openziti.discourse.group/u/blup66)\
**Replies:** 11\
**Last updated:** [June 6, 2025, 5:31pm UTC](https://openziti.discourse.group/t/ha-oidc-404-unexpected-content-type/4383 "2025-06-06T17:31:34Z")

</div>

Running the latest April 15th Ziti binaries (1.6) HA with 2 controllers at the moment. Client is ZDEW latest 2.6.5 and I am using ext-jwt-auth to an external provider (https://oidc-test.example.internal) I am observing …

---

## [Ngx\_ziti\_module still alive?](https://openziti.discourse.group/t/ngx-ziti-module-still-alive/4637)

<div class="topic-metadata">

**Author:** [@snowman](https://openziti.discourse.group/u/snowman)\
**Replies:** 6\
**Last updated:** [June 4, 2025, 4:22am UTC](https://openziti.discourse.group/t/ngx-ziti-module-still-alive/4637 "2025-06-04T04:22:26Z")

</div>

last time it was updated was 2-3 years ago. nothing wrong with that. just want to know if using nginix with ziti module consider anti-pattern? I see it a quick way to expose value of ziti without doing much heavy lift…

---

## [Hostname Resolution With Homarr/nextjs](https://openziti.discourse.group/t/hostname-resolution-with-homarr-nextjs/4248)

<div class="topic-metadata">

**Author:** [@thedarkula](https://openziti.discourse.group/u/thedarkula)\
**Replies:** 23\
**Last updated:** [June 2, 2025, 3:41pm UTC](https://openziti.discourse.group/t/hostname-resolution-with-homarr-nextjs/4248 "2025-06-02T15:41:08Z")

</div>

I have given homarr running in kubernetes a ziti identity. In the pod, I can successfully resolve a ziti service via dig or curl. From what I understand, nextjs uses ICMP to resolve hostnames, so homarr throws this err…

---

## [Express install without downloading binary (air-gap environment))](https://openziti.discourse.group/t/express-install-without-downloading-binary-air-gap-environment/4631)

<div class="topic-metadata">

**Author:** [@snowman](https://openziti.discourse.group/u/snowman)\
**Replies:** 1\
**Last updated:** [May 26, 2025, 2:52pm UTC](https://openziti.discourse.group/t/express-install-without-downloading-binary-air-gap-environment/4631 "2025-05-26T14:52:51Z")

</div>

For air gap environment running curl will failed. glance over ziti-cli-functions.sh there doesn't appear to be a flag for skip download/install ziti? little curl-ectomy and mess around with ZITI\_BIN\_DIR seem to does th…

---

## [0.0.0.0/1 route on intercept not working](https://openziti.discourse.group/t/0-0-0-0-1-route-on-intercept-not-working/4619)

<div class="topic-metadata">

**Author:** [@bodleytunes](https://openziti.discourse.group/u/bodleytunes)\
**Replies:** 9\
**Last updated:** [May 25, 2025, 4:17pm UTC](https://openziti.discourse.group/t/0-0-0-0-1-route-on-intercept-not-working/4619 "2025-05-25T16:17:31Z")

</div>

I'm trying to catch all traffic using the 0.0.0.0/1 and 128.0.0.0/1 trick, and I've noticed that even though the tproxy rules appear, only the 128.0.0.0/1 network appears on the loopback, I suppose its because possibly 0…

---

## [API sessions grey out in HA Cluster setup](https://openziti.discourse.group/t/api-sessions-grey-out-in-ha-cluster-setup/4580)

<div class="topic-metadata">

**Author:** [@Crystech](https://openziti.discourse.group/u/Crystech)\
**Replies:** 7\
**Last updated:** [May 22, 2025, 9:00pm UTC](https://openziti.discourse.group/t/api-sessions-grey-out-in-ha-cluster-setup/4580 "2025-05-22T21:00:27Z")

</div>

Hi all, After I setup HA Cluster Controller , I was able to deploy deploy , router (on second vm). I deployed services , service policy after router followed by identity for windows. I was able to enrolled successfull…

---

## [Ziti Controller And Router Behind Traefik](https://openziti.discourse.group/t/ziti-controller-and-router-behind-traefik/4547)

<div class="topic-metadata">

**Author:** [@thedarkula](https://openziti.discourse.group/u/thedarkula)\
**Replies:** 7\
**Last updated:** [May 21, 2025, 2:30pm UTC](https://openziti.discourse.group/t/ziti-controller-and-router-behind-traefik/4547 "2025-05-21T14:30:27Z")

</div>

I currently have both the controller and router running on non-stardard ports, with LoadBalancers. Is it possible to have all ziti services run with ClusterIPs behind a public traefik instance that listens on port 443? …

---

## [Controllers Cluster issues](https://openziti.discourse.group/t/controllers-cluster-issues/4573)

<div class="topic-metadata">

**Author:** [@Crystech](https://openziti.discourse.group/u/Crystech)\
**Replies:** 2\
**Last updated:** [May 19, 2025, 4:44pm UTC](https://openziti.discourse.group/t/controllers-cluster-issues/4573 "2025-05-19T16:44:16Z")

</div>

hi Team , last few days I been working on setting Controller Clusters. I like to check if others are facing similar issues . (I tried to search here but didn't get answers i need) Scenario: Setup 4 Notes Controller Clu…

---

## [How to release all environments](https://openziti.discourse.group/t/how-to-release-all-environments/4521)

<div class="topic-metadata">

**Author:** [@ben-chen](https://openziti.discourse.group/u/ben-chen)\
**Replies:** 1\
**Last updated:** [May 14, 2025, 1:16am UTC](https://openziti.discourse.group/t/how-to-release-all-environments/4521 "2025-05-14T01:16:46Z")

</div>

Is there a way to release all environments? I have 92 shares that are meant to be ephemeral (I'm running them in flyte pods) and I think I ran into the limit trying to enable. I don't really want to go through all of the…

---

## [Performance question regarding Edge routers behind a NAT](https://openziti.discourse.group/t/performance-question-regarding-edge-routers-behind-a-nat/4467)

<div class="topic-metadata">

**Author:** [@greggw01](https://openziti.discourse.group/u/greggw01)\
**Replies:** 12\
**Last updated:** [May 6, 2025, 3:12pm UTC](https://openziti.discourse.group/t/performance-question-regarding-edge-routers-behind-a-nat/4467 "2025-05-06T15:12:50Z")

</div>

Greetings! I am working on a proof of concept for accessing data stored in the cloud, and cached on-prem, and was hoping to use OpenZiti to connect the two halves. In all of my previous deployments, the on-prem routers…

---

## [Ziti Edge Tunnel On Linux Leaks Memory](https://openziti.discourse.group/t/ziti-edge-tunnel-on-linux-leaks-memory/4314)

<div class="topic-metadata">

**Author:** [@thedarkula](https://openziti.discourse.group/u/thedarkula)\
**Replies:** 7\
**Last updated:** [May 4, 2025, 5:03pm UTC](https://openziti.discourse.group/t/ziti-edge-tunnel-on-linux-leaks-memory/4314 "2025-05-04T17:03:23Z")

</div>

I noticed that ziti-edge-tunnel has a severe memory leak. The percent memory usage dropped from 70.2% to 31.2% following a restart of ziti-edge-tunnel. The systemd logs show this just before restarting the service: Ap…

---

## [Issue with residual access after deleting a service](https://openziti.discourse.group/t/issue-with-residual-access-after-deleting-a-service/4430)

<div class="topic-metadata">

**Author:** [@Deemaalbinali](https://openziti.discourse.group/u/Deemaalbinali)\
**Replies:** 1\
**Last updated:** [April 28, 2025, 2:01pm UTC](https://openziti.discourse.group/t/issue-with-residual-access-after-deleting-a-service/4430 "2025-04-28T14:01:00Z")

</div>

Hello, We are students working on implementing an identity-based access control project using OpenZiti. We created a test website (HTTP-based) to test our setup. It worked correctly the first time, but later we wanted …

---

## [HA Controller Disconnected Functionality](https://openziti.discourse.group/t/ha-controller-disconnected-functionality/4404)

<div class="topic-metadata">

**Author:** [@cmbryner](https://openziti.discourse.group/u/cmbryner)\
**Replies:** 2\
**Last updated:** [April 22, 2025, 2:30pm UTC](https://openziti.discourse.group/t/ha-controller-disconnected-functionality/4404 "2025-04-22T14:30:49Z")

</div>

Been Playing with the HA Controller and it does everything I need it to do, Just out of curiosity though if a controller were to go disconnected could I make a policy change to it. I did try and it failed because the con…

---

## [Router connection load balancing](https://openziti.discourse.group/t/router-connection-load-balancing/4264)

<div class="topic-metadata">

**Author:** [@farmhouse](https://openziti.discourse.group/u/farmhouse)\
**Replies:** 3\
**Last updated:** [April 3, 2025, 6:22pm UTC](https://openziti.discourse.group/t/router-connection-load-balancing/4264 "2025-04-03T18:22:34Z")

</div>

Hi There, I have a question about Ziti Edge Tunnel connections to Edge Routers. I can't seem to find the answer in any documentation. I have a HA Ziti system consisting of 3 Controllers and 2 public Edge Routers. I'm r…

---

## [When do old terminators get removed?](https://openziti.discourse.group/t/when-do-old-terminators-get-removed/4265)

<div class="topic-metadata">

**Author:** [@farmhouse](https://openziti.discourse.group/u/farmhouse)\
**Replies:** 2\
**Last updated:** [April 2, 2025, 1:25pm UTC](https://openziti.discourse.group/t/when-do-old-terminators-get-removed/4265 "2025-04-02T13:25:26Z")

</div>

Hiya, I have a question about Terminators. I have a HA Ziti system consisting of 3 Controllers and 2 public Edge Routers. I'm running v1.5.0 on the infrastructure and ZET v1.5.4. In my POC system i am seeing Terminator…

---

## [HA - stuck without a leader](https://openziti.discourse.group/t/ha-stuck-without-a-leader/4228)

<div class="topic-metadata">

**Author:** [@blup66](https://openziti.discourse.group/u/blup66)\
**Replies:** 3\
**Last updated:** [March 28, 2025, 6:21am UTC](https://openziti.discourse.group/t/ha-stuck-without-a-leader/4228 "2025-03-28T06:21:50Z")

</div>

Giving HA a try.. I must have done something wrong here. Not exactly sure if its on the ctrl2 side or if it was while adding to the cluster from ctrl1. ctrl2 is online as a uninitialized node. Appreciative of any assista…

---

## [Multiple zrok shares on docker](https://openziti.discourse.group/t/multiple-zrok-shares-on-docker/3661)

<div class="topic-metadata">

**Author:** [@NinoV-2469197](https://openziti.discourse.group/u/NinoV-2469197)\
**Replies:** 10\
**Last updated:** [March 24, 2025, 1:33pm UTC](https://openziti.discourse.group/t/multiple-zrok-shares-on-docker/3661 "2025-03-24T13:33:34Z")

</div>

Hi! I want to have two shares, each from a seperate docker-compose. Each has there own unique name domain and a different target. I tried to use the same volume where .zrok is stored but then it overwrites the reserved …

---

## [JWT installs, shows connected, but cant connect](https://openziti.discourse.group/t/jwt-installs-shows-connected-but-cant-connect/4149)

<div class="topic-metadata">

**Author:** [@ChrisOSSTMM](https://openziti.discourse.group/u/ChrisOSSTMM)\
**Replies:** 1\
**Last updated:** [March 13, 2025, 2:35pm UTC](https://openziti.discourse.group/t/jwt-installs-shows-connected-but-cant-connect/4149 "2025-03-13T14:35:39Z")

</div>

We get the client installed, install the token, host shows up as connected. But 2 of the 4 hosts we did the same process for we cant connect to the remote hosts 22 or RDP (or anything we had set to allow). Are there any…

---

## [Unable to configure Controller with split API](https://openziti.discourse.group/t/unable-to-configure-controller-with-split-api/4132)

<div class="topic-metadata">

**Author:** [@control\_joe](https://openziti.discourse.group/u/control_joe)\
**Replies:** 5\
**Last updated:** [March 12, 2025, 10:29am UTC](https://openziti.discourse.group/t/unable-to-configure-controller-with-split-api/4132 "2025-03-12T10:29:05Z")

</div>

Hi all, I've been building a basic network with 1 controller and 1 router, following the guides for deployment on Linux. When deployed with the usual defaults, everything is working fine. However, before we put the sys…

---

## [Letsencrypt certificates](https://openziti.discourse.group/t/letsencrypt-certificates/4082)

<div class="topic-metadata">

**Author:** [@brandi](https://openziti.discourse.group/u/brandi)\
**Replies:** 4\
**Last updated:** [March 6, 2025, 11:36pm UTC](https://openziti.discourse.group/t/letsencrypt-certificates/4082 "2025-03-06T23:36:45Z")

</div>

Hi, I've a domain name example.com. I want to use \*.lan.example.com to access services behind Ziti overlay. From the few researches I've done on the doc + on this forum, it looks like I just need to provide the certifi…

---

## [Connecting through a corporate proxy - Ziti VS Chisel](https://openziti.discourse.group/t/connecting-through-a-corporate-proxy-ziti-vs-chisel/4081)

<div class="topic-metadata">

**Author:** [@sjakos](https://openziti.discourse.group/u/sjakos)\
**Replies:** 1\
**Last updated:** [March 6, 2025, 11:20pm UTC](https://openziti.discourse.group/t/connecting-through-a-corporate-proxy-ziti-vs-chisel/4081 "2025-03-06T23:20:54Z")

</div>

I have a use case where I’ll be hosting and connecting to/from a service in a corporate network environment which only allows http traffic. There is an alternative solution in place that uses Chisel proxy with another ZT…

---

## [Ziti Edge Desktop enrollment error](https://openziti.discourse.group/t/ziti-edge-desktop-enrollment-error/4057)

<div class="topic-metadata">

**Author:** [@brandi](https://openziti.discourse.group/u/brandi)\
**Replies:** 7\
**Last updated:** [March 5, 2025, 9:10pm UTC](https://openziti.discourse.group/t/ziti-edge-desktop-enrollment-error/4057 "2025-03-05T21:10:45Z")

</div>

Hey, I'm trying to enroll an identity on Ziti Edge Desktop on Windows (2.5.5.0). I'm getting this error: And an error appears on the logs : \[2025-03-04T22:19:36.562Z\] ERROR ZitiDesktopEdge.ServiceClient.DataClient …

[Previous page](https://openziti.discourse.group/c/support/general-questions/7.md?page=1)

[Next page](https://openziti.discourse.group/c/support/general-questions/7.md?page=3)
