# Ziti Overlay

**URL:** https://openziti.discourse.group/c/ziti-overlay/8.md

[Latest](https://openziti.discourse.group/latest.md) · [Categories](https://openziti.discourse.group/categories.md)

---

## [About the Ziti Overlay category](https://openziti.discourse.group/t/about-the-ziti-overlay-category/185)

<div class="topic-metadata">

**Author:** [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Replies:** 0\
**Last updated:** [September 7, 2021, 2:47pm UTC](https://openziti.discourse.group/t/about-the-ziti-overlay-category/185 "2021-09-07T14:47:01Z")

</div>

This category is where you would ask questions. More specifically, about the OpenZiti overlay itself. Configuring it, using it, links, etc. Using this category instead of "Support" would usually be fine. It's a bit more …

---

## [Controller advertised address is ignoring port](https://openziti.discourse.group/t/controller-advertised-address-is-ignoring-port/6101)

<div class="topic-metadata">

**Author:** [@duncan.simey](https://openziti.discourse.group/u/duncan.simey)\
**Replies:** 1\
**Last updated:** [September 21, 2026, 10:52am UTC](https://openziti.discourse.group/t/controller-advertised-address-is-ignoring-port/6101 "2026-09-21T10:52:31Z")

</div>

Hi - I'm using Ziti v1 and, it's great; but migrating to v2 is proving a challenge! Our primary controller and router are on a single host, accessed via Nginx on port 443 with proxy destination selected by hostname. We…

---

## [What rewrites and loads endpoints.yml when ctrl.endpointsFile is commented out?](https://openziti.discourse.group/t/what-rewrites-and-loads-endpoints-yml-when-ctrl-endpointsfile-is-commented-out/6091)

<div class="topic-metadata">

**Author:** [@montwepa](https://openziti.discourse.group/u/montwepa)\
**Replies:** 2\
**Last updated:** [September 21, 2026, 8:12am UTC](https://openziti.discourse.group/t/what-rewrites-and-loads-endpoints-yml-when-ctrl-endpointsfile-is-commented-out/6091 "2026-09-21T08:12:02Z")

</div>

Hi, We are running OpenZiti Router v2.0.4. Our controller is exposed through an nginx TCP/SNI proxy on public port 443; its internal listener uses port 1280. The router configuration contains: ctrl: endpoint: tls:co…

---

## [Posture Check Bypassed When Multiple Services Share the Same Identity and Router](https://openziti.discourse.group/t/posture-check-bypassed-when-multiple-services-share-the-same-identity-and-router/6080)

<div class="topic-metadata">

**Author:** [@shoaib-ziti](https://openziti.discourse.group/u/shoaib-ziti)\
**Replies:** 1\
**Last updated:** [September 15, 2026, 3:03pm UTC](https://openziti.discourse.group/t/posture-check-bypassed-when-multiple-services-share-the-same-identity-and-router/6080 "2026-09-15T15:03:48Z")

</div>

Hi OpenZiti team, I need help investigating a possible posture/session authorization issue in OpenZiti 1.7.0. Environment OpenZiti: 1.7.0 Client: Ziti Desktop Edge Identity: test-client Identity ID: 38iAeJ9CY Client OS:…

---

## [Proxmox Backup over Ziti fails on large datasets (HTTP/2.0 connection failed)](https://openziti.discourse.group/t/proxmox-backup-over-ziti-fails-on-large-datasets-http-2-0-connection-failed/5975)

<div class="topic-metadata">

**Author:** [@golden-monkey](https://openziti.discourse.group/u/golden-monkey)\
**Replies:** 10\
**Last updated:** [August 26, 2026, 11:41am UTC](https://openziti.discourse.group/t/proxmox-backup-over-ziti-fails-on-large-datasets-http-2-0-connection-failed/5975 "2026-08-26T11:41:04Z")

</div>

Hi community, we are experiencing an issue regarding our remote backups which uses a ziti overlay network to connect the source to our remote backup target. Currently, every scheduled backup we run fails. We are using …

---

## [OpenZiti identity with Entra-signed JWT cannot access resources](https://openziti.discourse.group/t/openziti-identity-with-entra-signed-jwt-cannot-access-resources/5997)

<div class="topic-metadata">

**Author:** [@carol](https://openziti.discourse.group/u/carol)\
**Replies:** 2\
**Last updated:** [August 11, 2026, 9:22am UTC](https://openziti.discourse.group/t/openziti-identity-with-entra-signed-jwt-cannot-access-resources/5997 "2026-08-11T09:22:16Z")

</div>

Hello everyone, I’m running OpenZiti, and overall everything is working fine. Last week, I tried to configure network access through identity, but it’s not working as expected. Sometimes I can log in to the UI console…

---

## [K8S controller pod crashes with webBindingPki enabled](https://openziti.discourse.group/t/k8s-controller-pod-crashes-with-webbindingpki-enabled/5962)

<div class="topic-metadata">

**Author:** [@1VeryNaughtyCat](https://openziti.discourse.group/u/1VeryNaughtyCat)\
**Replies:** 3\
**Last updated:** [July 28, 2026, 4:23am UTC](https://openziti.discourse.group/t/k8s-controller-pod-crashes-with-webbindingpki-enabled/5962 "2026-07-28T04:23:58Z")

</div>

Hello, I am getting back to my project using openziti, this is new green fields deployment. Congrats on version 2.0 :slight\_smile: yay! My Environment: K3S OpenZiti helm chart version: ziti-controller-3.2.0 Openziti …

---

## [Multiple ext-jwt-signers with overlapping JWKS kids cause intermittent primary auth failures (GetIssuerByKid collision)](https://openziti.discourse.group/t/multiple-ext-jwt-signers-with-overlapping-jwks-kids-cause-intermittent-primary-auth-failures-getissuerbykid-collision/5913)

<div class="topic-metadata">

**Author:** [@msbusk](https://openziti.discourse.group/u/msbusk)\
**Replies:** 6\
**Last updated:** [July 20, 2026, 6:20am UTC](https://openziti.discourse.group/t/multiple-ext-jwt-signers-with-overlapping-jwks-kids-cause-intermittent-primary-auth-failures-getissuerbykid-collision/5913 "2026-07-20T06:20:27Z")

</div>

Ziti version: v2.0.0 Summary When two ext-jwt-signers are configured whose JWKS endpoints expose overlapping key IDs (kid), primary external-JWT authentication fails intermittently for valid tokens. The same token and …

---

## [Disable the Identity, BUT tunneler still able to connect to overlay network](https://openziti.discourse.group/t/disable-the-identity-but-tunneler-still-able-to-connect-to-overlay-network/5921)

<div class="topic-metadata">

**Author:** [@cao](https://openziti.discourse.group/u/cao)\
**Replies:** 2\
**Last updated:** [June 30, 2026, 7:07am UTC](https://openziti.discourse.group/t/disable-the-identity-but-tunneler-still-able-to-connect-to-overlay-network/5921 "2026-06-30T07:07:25Z")

</div>

Hey Openziti Supports, I'm looking for a feature time based access policy for the Identity, but current OpenZiti doesn't seems have this feature. As an alternative, i set up a external scheduler job to invoke ziti API t…

---

## [Router v2.0.0-pre10 and V2.0.0 stable deletes all terminators after ~ 12 minutes](https://openziti.discourse.group/t/router-v2-0-0-pre10-and-v2-0-0-stable-deletes-all-terminators-after-12-minutes/5901)

<div class="topic-metadata">

**Author:** [@Gazlar83](https://openziti.discourse.group/u/Gazlar83)\
**Replies:** 2\
**Last updated:** [June 18, 2026, 7:45pm UTC](https://openziti.discourse.group/t/router-v2-0-0-pre10-and-v2-0-0-stable-deletes-all-terminators-after-12-minutes/5901 "2026-06-18T19:45:23Z")

</div>

My issue is basically the same as router v2.0.0-pre6 deletes all terminators after ~ 12 minutes The details are below but this was also the same for v2.0.0-pre10. Environment Controllers: OpenZiti v2.0.0 (apt -stable)…

---

## [Hosting AD-related services via ziti-edge-tunnel on any domain-joined Windows host (DC or member server) breaks Cloud Kerberos Trust ticket issuance for Entra ID–joined dial clients; same configuration on an Edge Router works](https://openziti.discourse.group/t/hosting-ad-related-services-via-ziti-edge-tunnel-on-any-domain-joined-windows-host-dc-or-member-server-breaks-cloud-kerberos-trust-ticket-issuance-for-entra-id-joined-dial-clients-same-configuration-on-an-edge-router-works/5843)

<div class="topic-metadata">

**Author:** [@msbusk](https://openziti.discourse.group/u/msbusk)\
**Replies:** 4\
**Last updated:** [June 9, 2026, 6:07pm UTC](https://openziti.discourse.group/t/hosting-ad-related-services-via-ziti-edge-tunnel-on-any-domain-joined-windows-host-dc-or-member-server-breaks-cloud-kerberos-trust-ticket-issuance-for-entra-id-joined-dial-clients-same-configuration-on-an-edge-router-works/5843 "2026-06-09T18:07:54Z")

</div>

Summary When an OpenZiti service intercepting Active Directory traffic (DNS on 53, Kerberos on 88, LDAP on 389/636, SMB on 445) is bound by ziti-edge-tunnel running on any domain-joined Windows host — whether that host i…

---

## [DHCP+Ziti Port 67 cannot be recognized](https://openziti.discourse.group/t/dhcp-ziti-port-67-cannot-be-recognized/5834)

<div class="topic-metadata">

**Author:** [@McGonagall666](https://openziti.discourse.group/u/McGonagall666)\
**Replies:** 0\
**Last updated:** [May 18, 2026, 10:32am UTC](https://openziti.discourse.group/t/dhcp-ziti-port-67-cannot-be-recognized/5834 "2026-05-18T10:32:42Z")

</div>

Hello, I'm currently using DHCP+Ziti mode, but the external switch can only recognize port 67, while the tunnel router's backhaul port is 45553, not port 67, so it can't be recognized correctly. How can I set the port of…

---

## [HA cluster behind NLB: enrollment token consumption fails on followers — forwarding not working for enrollment?](https://openziti.discourse.group/t/ha-cluster-behind-nlb-enrollment-token-consumption-fails-on-followers-forwarding-not-working-for-enrollment/5823)

<div class="topic-metadata">

**Author:** [@ziti\_ops](https://openziti.discourse.group/u/ziti_ops)\
**Replies:** 1\
**Last updated:** [May 11, 2026, 2:10pm UTC](https://openziti.discourse.group/t/ha-cluster-behind-nlb-enrollment-token-consumption-fails-on-followers-forwarding-not-working-for-enrollment/5823 "2026-05-11T14:10:16Z")

</div>

First, thanks for making OpenZiti. We're running a 3-node HA controller cluster (v2.0.0-pre10) behind an AWS NLB. All three nodes are healthy, fully connected, and Raft consensus is working correctly (ziti agent cluster…

---

## [How to migrate a self-hosted controller and router to a new VM and domain?](https://openziti.discourse.group/t/how-to-migrate-a-self-hosted-controller-and-router-to-a-new-vm-and-domain/5820)

<div class="topic-metadata">

**Author:** [@lex529](https://openziti.discourse.group/u/lex529)\
**Replies:** 3\
**Last updated:** [May 11, 2026, 1:48pm UTC](https://openziti.discourse.group/t/how-to-migrate-a-self-hosted-controller-and-router-to-a-new-vm-and-domain/5820 "2026-05-11T13:48:59Z")

</div>

Hi all, I'm running a self-hosted OpenZiti deployment on a single Azure VM, where the controller and the edge router live together, it was setup using the install script, i'm planning to switch that do docker. The VM cu…

---

## [OpenZiti Wildcard Intercepts Not Working with SDK - Router Tries to Dial Pattern Instead of Actual Hostname](https://openziti.discourse.group/t/openziti-wildcard-intercepts-not-working-with-sdk-router-tries-to-dial-pattern-instead-of-actual-hostname/5780)

<div class="topic-metadata">

**Author:** [@shoaib-ziti](https://openziti.discourse.group/u/shoaib-ziti)\
**Replies:** 3\
**Last updated:** [April 20, 2026, 6:16pm UTC](https://openziti.discourse.group/t/openziti-wildcard-intercepts-not-working-with-sdk-router-tries-to-dial-pattern-instead-of-actual-hostname/5780 "2026-04-20T18:16:22Z")

</div>

Problem Description We're using OpenZiti SDK (embedded in our client application) to intercept traffic to a SaaS provider (Atlassian) that has multiple unknown subdomains (\*.atlassian.net). We configured a wildcard inte…

---

## [How to change sni?](https://openziti.discourse.group/t/how-to-change-sni/5759)

<div class="topic-metadata">

**Author:** [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Replies:** 7\
**Last updated:** [April 19, 2026, 8:19pm UTC](https://openziti.discourse.group/t/how-to-change-sni/5759 "2026-04-19T20:19:23Z")

</div>

I am looking for guidance on the proper way to make Ziti use a new SNI hostname. After updating the advertise hostname in the router configuration, the router fails to start. I modified the configuration as follows: …

---

## [Expired certs renewed using same keys are giving TLS errors](https://openziti.discourse.group/t/expired-certs-renewed-using-same-keys-are-giving-tls-errors/5739)

<div class="topic-metadata">

**Author:** [@nenkoru](https://openziti.discourse.group/u/nenkoru)\
**Replies:** 6\
**Last updated:** [April 7, 2026, 5:59pm UTC](https://openziti.discourse.group/t/expired-certs-renewed-using-same-keys-are-giving-tls-errors/5739 "2026-04-07T17:59:37Z")

</div>

Hello there! Long time no see(posting)…. So I have my Openziti PKI setup manually as per my guide here GitHub - nenkoru/openziti\_manual\_pki: Bootstrap PKI for OpenZiti manually · GitHub And today certs have expired …

---

## [Solution to Integrate with IPS/IDS](https://openziti.discourse.group/t/solution-to-integrate-with-ips-ids/5727)

<div class="topic-metadata">

**Author:** [@cao](https://openziti.discourse.group/u/cao)\
**Replies:** 4\
**Last updated:** [March 31, 2026, 8:59am UTC](https://openziti.discourse.group/t/solution-to-integrate-with-ips-ids/5727 "2026-03-31T08:59:04Z")

</div>

While using OpenZiti Overlay Network for Enterprise, Is there a way to integrate with IPS/IDS? Architecture: Client → Ziti Edge Tunneler → Ziti Overlay Network → Ziti Edge Tunneler → Service Application traffics are T…

---

## [Multiple links between two routers](https://openziti.discourse.group/t/multiple-links-between-two-routers/5723)

<div class="topic-metadata">

**Author:** [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Replies:** 6\
**Last updated:** [March 29, 2026, 1:43pm UTC](https://openziti.discourse.group/t/multiple-links-between-two-routers/5723 "2026-03-29T13:43:39Z")

</div>

I’m trying to establish multiple links between two routers and would appreciate some clarification on the expected behavior. From what I understand, it is possible to configure multiple listeners on a router by simply a…

---

## [TCP Retransmissions on Loopback Interface](https://openziti.discourse.group/t/tcp-retransmissions-on-loopback-interface/5726)

<div class="topic-metadata">

**Author:** [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Replies:** 0\
**Last updated:** [March 26, 2026, 8:02pm UTC](https://openziti.discourse.group/t/tcp-retransmissions-on-loopback-interface/5726 "2026-03-26T20:02:37Z")

</div>

I am observing an overwhelming flow of TCP retransmissions on the loopback interface. It seems that the application is not reading fast enough, causing repeated retransmissions, even though the receiver’s advertised wind…

---

## [Problem: Automating Identity Creation for OpenZiti via Authentik](https://openziti.discourse.group/t/problem-automating-identity-creation-for-openziti-via-authentik/4943)

<div class="topic-metadata">

**Author:** [@poithar](https://openziti.discourse.group/u/poithar)\
**Replies:** 6\
**Last updated:** [March 26, 2026, 1:16pm UTC](https://openziti.discourse.group/t/problem-automating-identity-creation-for-openziti-via-authentik/4943 "2026-03-26T13:16:47Z")

</div>

I'm currently experimenting with OpenZiti, with the goal of securing my SaaS application for future use. My setup involves a controller in Kubernetes, a separate VM running Browzer, and integration with Authentik as my i…

---

## ["enrollToTokenEnabled" not creating user with JIT](https://openziti.discourse.group/t/enrolltotokenenabled-not-creating-user-with-jit/5434)

<div class="topic-metadata">

**Author:** [@astro](https://openziti.discourse.group/u/astro)\
**Replies:** 7\
**Last updated:** [March 26, 2026, 12:26pm UTC](https://openziti.discourse.group/t/enrolltotokenenabled-not-creating-user-with-jit/5434 "2026-03-26T12:26:52Z")

</div>

Hello, new here, I just installed the ziti-controller (v1.8.0) on Kubernetes with the Helm chart. I also currently have a Let's Encrypt certificate for the webBindingPki. I’m trying to setup my IDP (Authentik) to work w…

---

## [Is it necessary to allow ICMP for OpenZiti? (PMTUD)](https://openziti.discourse.group/t/is-it-necessary-to-allow-icmp-for-openziti-pmtud/5712)

<div class="topic-metadata">

**Author:** [@golden-monkey](https://openziti.discourse.group/u/golden-monkey)\
**Replies:** 3\
**Last updated:** [March 23, 2026, 10:55am UTC](https://openziti.discourse.group/t/is-it-necessary-to-allow-icmp-for-openziti-pmtud/5712 "2026-03-23T10:55:41Z")

</div>

Hey everyone, First, thanks for creating OpenZiti! It is crazy amazing! I’m currently reviewing my firewall rules for a setup involving pfSense, Proxmox, and OpenZiti. My default thought would be to not allow ICMP on m…

---

## [Router v2.0.0-pre6 deletes all terminators after ~12 minutes due to post-create inspect timeout with stable SDK clients](https://openziti.discourse.group/t/router-v2-0-0-pre6-deletes-all-terminators-after-12-minutes-due-to-post-create-inspect-timeout-with-stable-sdk-clients/5711)

<div class="topic-metadata">

**Author:** [@msbusk](https://openziti.discourse.group/u/msbusk)\
**Replies:** 3\
**Last updated:** [March 21, 2026, 7:17am UTC](https://openziti.discourse.group/t/router-v2-0-0-pre6-deletes-all-terminators-after-12-minutes-due-to-post-create-inspect-timeout-with-stable-sdk-clients/5711 "2026-03-21T07:17:32Z")

</div>

Environment: Controller: openziti/ziti-controller:2.0.0-pre6 (Docker) Router: openziti/ziti-router:2.0.0-pre6 (Docker) SDK clients: ziti-edge-tunnel v1.11.1 (Windows, latest stable) + ziti-sdk-c on Linux hosts Deployme…

---

## [Node.js SDK enrollment fails with TLS handshake error — Let's Encrypt + Internal PKI separation](https://openziti.discourse.group/t/node-js-sdk-enrollment-fails-with-tls-handshake-error-lets-encrypt-internal-pki-separation/5678)

<div class="topic-metadata">

**Author:** [@franciscoarruda](https://openziti.discourse.group/u/franciscoarruda)\
**Replies:** 1\
**Last updated:** [March 9, 2026, 11:57am UTC](https://openziti.discourse.group/t/node-js-sdk-enrollment-fails-with-tls-handshake-error-lets-encrypt-internal-pki-separation/5678 "2026-03-09T11:57:38Z")

</div>

Hi, I'm deploying OpenZiti with Docker Compose using openziti/ziti-controller and openziti/ziti-router (non-quickstart images). I'm using the Node.js SDK (@openziti/ziti-sdk-nodejs) in an Electron app to enroll a client…

---

## [MacOS connection refused error](https://openziti.discourse.group/t/macos-connection-refused-error/5474)

<div class="topic-metadata">

**Author:** [@msbusk](https://openziti.discourse.group/u/msbusk)\
**Replies:** 32\
**Last updated:** [March 3, 2026, 1:58pm UTC](https://openziti.discourse.group/t/macos-connection-refused-error/5474 "2026-03-03T13:58:02Z")

</div>

I’m experiencing a rather strange issue. I’m running an OpenZiti controller and router version 1.8.0-pre4 with the latest client. On my macOS clients, I get “connection refused” to some services unless I stop the edge t…

---

## [Local Docker Deployment: Windows Client fails to connect to Edge Router (TLS Handshake Failed / Invalid Grant)](https://openziti.discourse.group/t/local-docker-deployment-windows-client-fails-to-connect-to-edge-router-tls-handshake-failed-invalid-grant/5551)

<div class="topic-metadata">

**Author:** [@barta50](https://openziti.discourse.group/u/barta50)\
**Replies:** 3\
**Last updated:** [February 27, 2026, 6:29pm UTC](https://openziti.discourse.group/t/local-docker-deployment-windows-client-fails-to-connect-to-edge-router-tls-handshake-failed-invalid-grant/5551 "2026-02-27T18:29:26Z")

</div>

Hi everyone, I am trying to set up a local OpenZiti stack using Docker Compose on a VM. My goal is to use it within my local home network. I am facing persistent connection issues where the Windows Client enrolls succe…

---

## [Router OIDC Support](https://openziti.discourse.group/t/router-oidc-support/5654)

<div class="topic-metadata">

**Author:** [@McGonagall666](https://openziti.discourse.group/u/McGonagall666)\
**Replies:** 5\
**Last updated:** [February 27, 2026, 12:51pm UTC](https://openziti.discourse.group/t/router-oidc-support/5654 "2026-02-27T12:51:04Z")

</div>

I'd like to ask if the router currently supports Keycloak authentication.If it's supported, how do I do it？

---

## [Android SDK and bindUsingEdgeIdentity](https://openziti.discourse.group/t/android-sdk-and-bindusingedgeidentity/5575)

<div class="topic-metadata">

**Author:** [@Mathis](https://openziti.discourse.group/u/Mathis)\
**Replies:** 0\
**Last updated:** [February 19, 2026, 10:22am UTC](https://openziti.discourse.group/t/android-sdk-and-bindusingedgeidentity/5575 "2026-02-19T10:22:58Z")

</div>

Hello I am trying to make a basic app using the Android SDK and flutter, I managed to have the SDK running, enrollment works fine, but then I can't manage to connect to a service. Knowing our network uses "bindUsingEdg…

---

## [Controller v1.6.8 disconnects tunnelers](https://openziti.discourse.group/t/controller-v1-6-8-disconnects-tunnelers/5195)

<div class="topic-metadata">

**Author:** [@dmuensterer](https://openziti.discourse.group/u/dmuensterer)\
**Replies:** 42\
**Last updated:** [February 19, 2026, 8:31am UTC](https://openziti.discourse.group/t/controller-v1-6-8-disconnects-tunnelers/5195 "2026-02-19T08:31:53Z")

</div>

Hi, we’ve upgrade our controllers, routers and all ziti-edge-tunnels to the newest version yesterday. controller: v1.6.8 router: v1.6.8 ziti-edge-tunnel: v1.7.12 This morning we got random alerts that many of our zi…

[Next page](https://openziti.discourse.group/c/ziti-overlay/8.md?page=1)
