I have just installed a fresh Ubuntu and then the TomSparksBox and then tried to install the Media containers. I am not having any luck getting the VPN to work. I have Nord VPN. I am using the manual connection credentials for open vpn, the logs seem to indicate it connects fine, but then it closes the connection. I am at my wits end. Please can someone try to assist me in getting this to work. Portion of the log file below: 2026-08-15T06:07:17.941957299Z 2026-08-15T06:07:17Z INFO [ip getter] Public IP address is 187.15.xxx.xxx (Australia, New South Wales, Sydney - source: ipinfo+ifconfig.co+ip2location+cloudflare) 2026-08-15T06:07:18.693155347Z 2026-08-15T06:07:18Z INFO [vpn] You are running the latest release v3.41.3 2026-08-15T06:10:25.865931417Z 2026-08-15T06:10:25.865964683Z 2026-08-15T06:10:25Z WARN Caught OS signal terminated, shutting down 2026-08-15T06:10:25.866364802Z 2026-08-15T06:10:25Z INFO dns ticker: terminated ✔️ 2026-08-15T06:10:25.866387814Z 2026-08-15T06:10:25Z INFO http server: terminated ✔️ 2026-08-15T06:10:25.866394481Z 2026-08-15T06:10:25Z INFO updater ticker: terminated ✔️ 2026-08-15T06:10:25.866399519Z 2026-08-15T06:10:25Z INFO control: terminated ✔️ 2026-08-15T06:10:25.866404191Z 2026-08-15T06:10:25Z INFO updater: terminated ✔️ 2026-08-15T06:10:25.866408851Z 2026-08-15T06:10:25Z INFO tickers: terminated ✔️ 2026-08-15T06:10:25.866413407Z 2026-08-15T06:10:25Z INFO HTTP health server: terminated ✔️ 2026-08-15T06:10:25.877688787Z 2026-08-15T06:10:25Z INFO vpn: terminated ✔️ 2026-08-15T06:10:25.877717914Z 2026-08-15T06:10:25Z INFO shadowsocks proxy: terminated ✔️ 2026-08-15T06:10:25.877724480Z 2026-08-15T06:10:25Z INFO http proxy: terminated ✔️ 2026-08-15T06:10:25.877729559Z 2026-08-15T06:10:25Z INFO dns: terminated ✔️ 2026-08-15T06:10:25.877734213Z 2026-08-15T06:10:25Z INFO other: terminated ✔️ 2026-08-15T06:10:25.877738729Z 2026-08-15T06:10:25Z INFO [routing] routing cleanup...
30 replies
Wulf_Man wrote:
I just tried reinstalling Ubuntu and then reinstalled Tomsparkbox, then went to download Media again and set it up with Surfshar Wireguard this time and am still getting a VPN failure.
Wulf_Man wrote:
Restart failed — settings were saved, but the media stack did not come back up cleanly. Most likely cause: • The tunnel connects, but nothing inside it can look up an address — so the VPN's own health check times out and it restarts, over and over. Fix: Try this first: turn off the "encrypted DNS (DoT)" option in VPN settings and save. It is ON by default and some VPN servers block it; your traffic still goes through the VPN either way. If that changes nothing, the tunnel isn't carrying traffic at all — re-check your VPN key and address, and on WireGuard try putting 1280 in the "WireGuard MTU" box (then 1220).
Wulf_Man wrote:
I tried disabling all of the firewall settings on my router, (Asus ZenWifi), it made no difference.
Chris wrote:
Good news is this isn't your router — your log shows the tunnel itself connects and gets a public IP, then its own health check times out trying to look up an address inside it. Encrypted DNS (DoT) is on by default and some VPN servers block it, so rule that out first: sudo sparkbox set-env VPNDOT off then sudo sparkbox restart media. If it still cycles, lower the WireGuard packet size: sudo sparkbox set-env WIREGUARDMTU 1280 (then 1220), restarting after each. Both are safe — traffic still rides the VPN. Try those and paste what the log says after.
Wulf_Man wrote:
I tried all of the things you suggested, but none if it worked. So then I reinstalled Ubuntu and then Sparkbox to start from scratch. Now when I try to install the media center I get an error saying it looks like I am using a complete wireguard file instead of just the private key. I am only pasting the 44 character private key into the installation prompt and then selecting the appropriate country and city.
Chris wrote:
This one's the installer's safety check, not a broken setup — easy to get past. That message fires when the box thinks what you pasted contains more than just the key, and it watches for config-file words like PrivateKey, [Interface] or Endpoint. Even a hidden line break can drag the rest of the file in. So open the Surfshark config in a text editor, find the PrivateKey line, and copy only the 44-character value after the = (it ends in =) — no spaces, no line breaks. Paste just that into the private key box.
Wulf_Man wrote:
That is exactly what I am doing. I have the config file open in notepad and am copying just the 44 character private key and pasting it into the private key box.
Chris wrote:
Let us pin down which of the three installer checks is tripping — each one prints a different message. Try this: open a brand-new empty Notepad window, paste the key there, and look at it before copying again. You should see exactly one line of 44 characters ending in =. If you spot the word PrivateKey, a second line, or any stray space, that is the extra the installer is catching. Then copy just that one clean line. If it still refuses, paste the exact error wording — it may even print a character count — and I will tell you which check it is.
Wulf_Man wrote:
I tried again but this time did not select a city in the config and it installed successfully. I still need to confirm if the Gluetun container will successfully connect. I will report back shortly.
Chris wrote:
That's the milestone we wanted — the install going through cleanly means the key and config were accepted at last. Now there's just one thing left to confirm: give the container a minute or two, and if the tunnel connects and holds, you're done. If it cycles again — connects, then its own health check times out and it restarts — grab the fresh log and paste it here, and I'll take it from there. No rush; I'm here either way.
Wulf_Man wrote:
So I am still having the same issue with the vpn failing to connect. I have tried the things you suggested earlier already. I have turned the encrypted DNS off, I have slowed the wireguard mtu down to 1280 and then 1220 and still am getting the same errors. I have added the logs for Gluetun below. Connecting... 2026-08-16T05:53:47.828528917Z 2026-08-16T05:53:47Z INFO [wireguard] Connecting to 45.248.76.227:51820 2026-08-16T05:53:47.829974296Z 2026-08-16T05:53:47Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T05:53:53.928028765Z 2026-08-16T05:53:53Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T05:53:53.928043447Z 2026-08-16T05:53:53Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T05:53:53.928045562Z 2026-08-16T05:53:53Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T05:53:53.928046948Z 2026-08-16T05:53:53Z INFO [vpn] stopping 2026-08-16T05:53:53.999098979Z 2026-08-16T05:53:53Z INFO [vpn] starting 2026-08-16T05:53:53.999120954Z 2026-08-16T05:53:53Z INFO [firewall] allowing VPN connection... 2026-08-16T05:53:54.032416749Z 2026-08-16T05:53:54Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T05:53:54.033088821Z 2026-08-16T05:53:54Z INFO [wireguard] Connecting to 195.86.27.12:51820 2026-08-16T05:53:54.033729114Z 2026-08-16T05:53:54Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T05:54:00.134719737Z 2026-08-16T05:54:00Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T05:54:00.134841468Z 2026-08-16T05:54:00Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T05:54:00.134852740Z 2026-08-16T05:54:00Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T05:54:00.134858407Z 2026-08-16T05:54:00Z INFO [vpn] stopping 2026-08-16T05:54:00.201347891Z 2026-08-16T05:54:00Z INFO [vpn] starting 2026-08-16T05:54:00.201564208Z 2026-08-16T05:54:00Z INFO [firewall] allowing VPN connection... 2026-08-16T05:54:00.243907836Z 2026-08-16T05:54:00Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T05:54:00.245514677Z 2026-08-16T05:54:00Z INFO [wireguard] Connecting to 124.150.139.61:51820 2026-08-16T05:54:00.247090352Z 2026-08-16T05:54:00Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T05:54:06.344954755Z 2026-08-16T05:54:06Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T05:54:06.345005721Z 2026-08-16T05:54:06Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T05:54:06.345015492Z 2026-08-16T05:54:06Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T05:54:06.345022046Z 2026-08-16T05:54:06Z INFO [vpn] stopping 2026-08-16T05:54:06.406440726Z 2026-08-16T05:54:06Z INFO [vpn] starting 2026-08-16T05:54:06.406652020Z 2026-08-16T05:54:06Z INFO [firewall] allowing VPN connection... 2026-08-16T05:54:06.456751197Z 2026-08-16T05:54:06Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T05:54:06.458520007Z 2026-08-16T05:54:06Z INFO [wireguard] Connecting to 86.38.100.18:51820 2026-08-16T05:54:06.460173615Z 2026-08-16T05:54:06Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T05:54:12.558174642Z 2026-08-16T05:54:12Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T05:54:12.558216141Z 2026-08-16T05:54:12Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T05:54:12.558225543Z 2026-08-16T05:54:12Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T05:54:12.558232733Z 2026-08-16T05:54:12Z INFO [vpn] stopping 2026-08-16T05:54:12.624529866Z 2026-08-16T05:54:12Z INFO [vpn] starting 2026-08-16T05:54:12.624695462Z 2026-08-16T05:54:12Z INFO [firewall] allowing VPN connection... 2026-08-16T05:54:12.681700766Z 2026-08-16T05:54:12Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T05:54:12.683475195Z 2026-08-16T05:54:12Z INFO [wireguard] Connecting to 86.38.100.10:51820 2026-08-16T05:54:12.685177482Z 2026-08-16T05:54:12Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T05:54:18.782308575Z 2026-08-16T05:54:18Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T05:54:18.782354492Z 2026-08-16T05:54:18Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T05:54:18.782363437Z 2026-08-16T05:54:18Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T05:54:18.782368462Z 2026-08-16T05:54:18Z INFO [vpn] stopping 2026-08-16T05:54:18.847377885Z 2026-08-16T05:54:18Z INFO [vpn] starting 2026-08-16T05:54:18.847544405Z 2026-08-16T05:54:18Z INFO [firewall] allowing VPN connection... 2026-08-16T05:54:18.892711432Z 2026-08-16T05:54:18Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T05:54:18.894377016Z 2026-08-16T05:54:18Z INFO [wireguard] Connecting to 124.150.139.83:51820 2026-08-16T05:54:18.895923467Z 2026-08-16T05:54:18Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T05:54:24.994405880Z 2026-08-16T05:54:24Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T05:54:24.994450296Z 2026-08-16T05:54:24Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T05:54:24.994459301Z 2026-08-16T05:54:24Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T05:54:24.994464382Z 2026-08-16T05:54:24Z INFO [vpn] stopping 2026-08-16T05:54:25.064367667Z 2026-08-16T05:54:25Z INFO [vpn] starting 2026-08-16T05:54:25.064591708Z 2026-08-16T05:54:25Z INFO [firewall] allowing VPN connection... 2026-08-16T05:54:25.119645312Z 2026-08-16T05:54:25Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T05:54:25.121296099Z 2026-08-16T05:54:25Z INFO [wireguard] Connecting to 149.88.101.2:51820 2026-08-16T05:54:25.122789260Z 2026-08-16T05:54:25Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T05:54:31.220365016Z 2026-08-16T05:54:31Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T05:54:31.220432327Z 2026-08-16T05:54:31Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T05:54:31.220442610Z 2026-08-16T05:54:31Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T05:54:31.220447804Z 2026-08-16T05:54:31Z INFO [vpn] stopping 2026-08-16T05:54:31.287393357Z 2026-08-16T05:54:31Z INFO [vpn] starting 2026-08-16T05:54:31.287649440Z 2026-08-16T05:54:31Z INFO [firewall] allowing VPN connection... 2026-08-16T05:54:31.333770664Z 2026-08-16T05:54:31Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T05:54:31.335589880Z 2026-08-16T05:54:31Z INFO [wireguard] Connecting to 103.192.80.131:51820 2026-08-16T05:54:31.337203382Z 2026-08-16T05:54:31Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors in
Chris wrote:
Thanks for the fresh log — it actually pinpoints the problem. Your tunnel comes up, but nothing inside it can resolve a name, so gluetun's own health check keeps timing out and restarting it. There's one step built for exactly this that hasn't been tried yet: sudo sparkbox refresh-vpn-servers. The box saves your provider's server list the first time it starts, and a rotated key in that list makes the tunnel connect while carrying zero traffic — which is what your log shows. Run that, let it restart the media apps, then paste what the log says. If it's still cycling after that, I'll get it escalated.
Wulf_Man wrote:
Still not having any luck. :( 2026-08-16T06:26:48.713902267Z 2026-08-16T06:26:48Z INFO [storage] merging by most recent 20957 hardcoded servers and 20957 servers read from /gluetun/servers.json 2026-08-16T06:26:48.922318036Z 2026-08-16T06:26:48Z INFO Alpine version: 3.22.5 2026-08-16T06:26:48.925207234Z 2026-08-16T06:26:48Z INFO OpenVPN version: 2.6.20 2026-08-16T06:26:48.925789839Z 2026-08-16T06:26:48Z INFO IPtables version: v1.8.11 2026-08-16T06:26:48.925893997Z 2026-08-16T06:26:48Z INFO Settings summary: 2026-08-16T06:26:48.925897272Z ├── VPN settings: 2026-08-16T06:26:48.925899099Z | ├── VPN provider settings: 2026-08-16T06:26:48.925900274Z | | ├── Name: surfshark 2026-08-16T06:26:48.925909854Z | | └── Server selection settings: 2026-08-16T06:26:48.925911246Z | | ├── VPN type: wireguard 2026-08-16T06:26:48.925912361Z | | ├── Countries: australia 2026-08-16T06:26:48.925913479Z | | └── Wireguard selection settings: 2026-08-16T06:26:48.925914578Z | └── Wireguard settings: 2026-08-16T06:26:48.925915642Z | ├── Private key: iBW...Vw= 2026-08-16T06:26:48.925916729Z | ├── Interface addresses: 2026-08-16T06:26:48.925917791Z | | └── 10.14.0.2/16 2026-08-16T06:26:48.925918932Z | ├── Allowed IPs: 2026-08-16T06:26:48.925920032Z | | ├── 0.0.0.0/0 2026-08-16T06:26:48.925921123Z | | └── ::/0 2026-08-16T06:26:48.925922219Z | └── Network interface: tun0 2026-08-16T06:26:48.925923299Z | └── MTU: 1220 2026-08-16T06:26:48.925924347Z ├── DNS settings: 2026-08-16T06:26:48.925925484Z | ├── Keep existing nameserver(s): no 2026-08-16T06:26:48.925926588Z | ├── DNS server address to use: 127.0.0.1 2026-08-16T06:26:48.925927882Z | └── DNS forwarder server enabled: no 2026-08-16T06:26:48.925929011Z ├── Firewall settings: 2026-08-16T06:26:48.925930111Z | ├── Enabled: yes 2026-08-16T06:26:48.925931223Z | ├── Input ports: 2026-08-16T06:26:48.925932264Z | | ├── 8989 2026-08-16T06:26:48.925933305Z | | ├── 7878 2026-08-16T06:26:48.925934354Z | | ├── 9696 2026-08-16T06:26:48.925935388Z | | ├── 8686 2026-08-16T06:26:48.925936486Z | | ├── 8080 2026-08-16T06:26:48.925937582Z | | ├── 8081 2026-08-16T06:26:48.925938666Z | | ├── 8191 2026-08-16T06:26:48.925939753Z | | └── 6767 2026-08-16T06:26:48.925940805Z | └── Outbound subnets: 2026-08-16T06:26:48.925941913Z | ├── 192.168.0.0/16 2026-08-16T06:26:48.925943025Z | ├── 10.0.0.0/8 2026-08-16T06:26:48.925944093Z | └── 172.16.0.0/12 2026-08-16T06:26:48.925945243Z ├── Log settings: 2026-08-16T06:26:48.925946349Z | └── Log level: info 2026-08-16T06:26:48.925947455Z ├── Health settings: 2026-08-16T06:26:48.925948583Z | ├── Server listening address: 127.0.0.1:9999 2026-08-16T06:26:48.925949700Z | ├── Target addresses: 2026-08-16T06:26:48.925951110Z | | ├── cloudflare.com:443 2026-08-16T06:26:48.925952360Z | | └── github.com:443 2026-08-16T06:26:48.925964034Z | ├── Small health check type: ICMP echo request 2026-08-16T06:26:48.925965965Z | | └── ICMP target IPs: 2026-08-16T06:26:48.925967197Z | | ├── 1.1.1.1 2026-08-16T06:26:48.925968309Z | | └── 8.8.8.8 2026-08-16T06:26:48.925969429Z | └── Restart VPN on healthcheck failure: yes 2026-08-16T06:26:48.925970587Z ├── Shadowsocks server settings: 2026-08-16T06:26:48.925971768Z | └── Enabled: no 2026-08-16T06:26:48.925972864Z ├── HTTP proxy settings: 2026-08-16T06:26:48.925973962Z | └── Enabled: no 2026-08-16T06:26:48.925975048Z ├── Control server settings: 2026-08-16T06:26:48.925976182Z | ├── Listening address: :8000 2026-08-16T06:26:48.925977272Z | ├── Logging: yes 2026-08-16T06:26:48.925978396Z | └── Authentication file path: /gluetun/auth/config.toml 2026-08-16T06:26:48.925979583Z ├── Storage settings: 2026-08-16T06:26:48.925980797Z | └── Filepath: /gluetun/servers.json 2026-08-16T06:26:48.925981981Z ├── OS Alpine settings: 2026-08-16T06:26:48.925983494Z | ├── Process UID: 1000 2026-08-16T06:26:48.925984612Z | ├── Process GID: 1000 2026-08-16T06:26:48.925985723Z | └── Timezone: etc/utc 2026-08-16T06:26:48.925986805Z ├── Public IP settings: 2026-08-16T06:26:48.925987913Z | ├── IP file path: /tmp/gluetun/ip 2026-08-16T06:26:48.925989114Z | ├── Public IP data base API: ipinfo 2026-08-16T06:26:48.925990309Z | └── Public IP data backup APIs: 2026-08-16T06:26:48.925991509Z | ├── ifconfigco 2026-08-16T06:26:48.925992606Z | ├── ip2location 2026-08-16T06:26:48.925993704Z | └── cloudflare 2026-08-16T06:26:48.925994794Z ├── Server data updater settings: 2026-08-16T06:26:48.925995944Z | ├── Update period: 360h0m0s 2026-08-16T06:26:48.925997050Z | ├── Minimum ratio: 0.8 2026-08-16T06:26:48.925998134Z | └── Providers to update: surfshark 2026-08-16T06:26:48.925999305Z └── Version settings: 2026-08-16T06:26:48.926000429Z └── Enabled: yes 2026-08-16T06:26:48.936259776Z 2026-08-16T06:26:48Z INFO [routing] default route found: interface eth1, gateway 172.20.0.1, assigned IP 172.20.0.9 and family v4 2026-08-16T06:26:48.936282905Z 2026-08-16T06:26:48Z INFO [routing] adding route for 0.0.0.0/0 2026-08-16T06:26:48.936408808Z 2026-08-16T06:26:48Z INFO [firewall] setting allowed subnets... 2026-08-16T06:26:48.939018921Z 2026-08-16T06:26:48Z INFO [routing] default route found: interface eth1, gateway 172.20.0.1, assigned IP 172.20.0.9 and family v4 2026-08-16T06:26:48.939049866Z 2026-08-16T06:26:48Z INFO [routing] adding route for 192.168.0.0/16 2026-08-16T06:26:48.939194931Z 2026-08-16T06:26:48Z INFO [routing] adding route for 10.0.0.0/8 2026-08-16T06:26:48.939317606Z 2026-08-16T06:26:48Z INFO [routing] adding route for 172.16.0.0/12 2026-08-16T06:26:48.939556715Z 2026-08-16T06:26:48Z INFO [firewall] setting allowed input port 8989 through interface eth1... 2026-08-16T06:26:48.944026427Z 2026-08-16T06:26:48Z INFO [firewall] setting allowed input port 7878 through interface eth1... 2026-08-16T06:26:48.947194337Z 2026-08-16T06:26:48Z INFO [firewall] setting allowed input port 9696 through interface eth1... 2026-08-16T06:26:48.950323666Z 2026-08-16T06:26:48Z INFO [firewall] setting allowed input port 8686 through interface eth1... 2026-08-16T06:26:48.953564400Z 2026-08-16T06:26:48Z INFO [firewall] setting allowed input port 8080 through interface eth1... 2026-08-16T06:26:48.956695068Z 2026-08-16T06:26:48Z INFO [firewall] setting allowed input port 8081 through interface eth1... 2026-08-16T06:26:48.959753887Z 2026-08-16T06:26:48Z INFO [firewall] setting allowed input port 8191 through interface eth1... 2026-08-16T06:26:48.962915508Z 2026-08-16T06:26:48Z INFO [firewall] setting allowed input port 6767 through interface eth1... 2026-08-16T06:26:48.966227800Z 2026-08-16T06:26:48Z INFO [dns] using plaintext DNS at address 1.1.1.1 2026-08-16T06:26:48.966244581Z 2026-08-16T06:26:48Z INFO [healthcheck] listening on 127.0.0.1:9999 2026-08-16T06:26:48.966368339Z 2026-08-16T06:26:48Z INFO [http server] http server listening on [::]:8000 2026-08-16T06:26:48.966442106Z 2026-08-16T06:26:48Z INFO [firewall] allowing VPN connection... 2026-08-16T06:26:48.968634817Z 2026-08-16T06:26:48Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T06:26:48.969149662Z 2026-08-16T06:26:48Z INFO [wireguard] Connecting to 103.192.80.243:51820 2026-08-16T06:26:49.012780670Z 2026-08-16T06:26:49Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T06:26:55.069635472Z 2026-08-16T06:26:55Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T06:26:55.069649784Z 2026-08-16T06:26:55Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T06:26:55.069651805Z 2026-08-16T06:26:55Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T06:26:55.069653106Z 2026-08-16T06:26:55Z INFO [vpn] stopping 2026-08-16T06:26:55.129971980Z 2026-08-16T06:26:55Z INFO [vpn] starting 2026-08-16T06:26:55.130021568Z 2026-08-16T06:26:55Z INFO [firewall] allowing VPN connection... 2026-08-16T06:26:55.153936790Z 2026-08-16T06:26:55Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T06:26:55.154385699Z 2026-08-16T06:26:55Z INFO [wireguard] Connecting to 45.248.76.211:51820 2026-08-16T06:26:55.154781124Z 2026-08-16T06:26:55Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T06:27:01.254639472Z 2026-08-16T06:27:01Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T06:27:01.254655391Z 2026-08-16T06:27:01Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T06:27:01.254657557Z 2026-08-16T06:27:01Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T06:27:01.254658971Z 2026-08-16T06:27:01Z INFO [vpn] stopping 2026-08-16T06:27:01.315279836Z 2026-08-16T06:27:01Z INFO [vpn] starting 2026-08-16T06:27:01.315495461Z 2026-08-16T06:27:01Z INFO [firewall] allowing VPN connection... 2026-08-16T06:27:01.338268546Z 2026-08-16T06:27:01Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T06:27:01.338719692Z 2026-08-16T06:27:01Z INFO [wireguard] Connecting to 103.192.80.133:51820 2
Chris wrote:
I hear you — this has gone more rounds than it should, and I'm sorry it's still cycling. One more thing is worth trying while I flag it: your box has only ever used Australian servers. A different country is the one documented fix we haven't tried. Switch it: sudo sparkbox set-env SERVERCOUNTRIES United States then sudo sparkbox restart media. If it connects there, it was the servers; if it still cycles, it's deeper. I've flagged this with Tom — no more steps from you for now, and I'll come back with his read.
Wulf_Man wrote:
So far I have tried everything you have suggested with no luck. I set the country variable as suggested in your previous post and got the same failure again. I have also tried 2 VPN's as I already had Nord, but paid for Surfshark as it is suggested as the preference for this project. I have also tried openvpn and wireguard, neither have worked for me. Before trying this with Tomsparkbox, I was using ZimaOS and was also having the same issues with VPN not connecting successfully. What else in my environment should I be looking at as a possible cause?
Chris wrote:
The ZimaOS detail is the most useful clue yet — the identical failure on a completely different platform, across two VPNs and both protocols, points at your network path rather than the box. So let's stop changing SparkBox settings and test the pipe itself. One check: connect this machine through your phone's mobile hotspot and try the tunnel through that. If it holds there, your home router or ISP is the blocker; if it fails there too, it's the machine. That single result tells us where to look next, and it's already with Tom — I'll add this to what he's seeing.
Wulf_Man wrote:
While using the phone's hotspot it is still not working. Logs below: 2026-08-16T09:41:44.250298966Z 2026-08-16T09:41:44Z INFO [wireguard] Connecting to 149.102.254.12:51820 2026-08-16T09:41:44.251025780Z 2026-08-16T09:41:44Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T09:41:50.351193585Z 2026-08-16T09:41:50Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T09:41:50.351241258Z 2026-08-16T09:41:50Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T09:41:50.351249511Z 2026-08-16T09:41:50Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T09:41:50.351254600Z 2026-08-16T09:41:50Z INFO [vpn] stopping 2026-08-16T09:41:50.418206467Z 2026-08-16T09:41:50Z INFO [vpn] starting 2026-08-16T09:41:50.418624244Z 2026-08-16T09:41:50Z INFO [firewall] allowing VPN connection... 2026-08-16T09:41:50.457555248Z 2026-08-16T09:41:50Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T09:41:50.458359928Z 2026-08-16T09:41:50Z INFO [wireguard] Connecting to 89.187.187.68:51820 2026-08-16T09:41:50.459264498Z 2026-08-16T09:41:50Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T09:41:56.558050986Z 2026-08-16T09:41:56Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T09:41:56.558097532Z 2026-08-16T09:41:56Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T09:41:56.558110872Z 2026-08-16T09:41:56Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T09:41:56.558116571Z 2026-08-16T09:41:56Z INFO [vpn] stopping 2026-08-16T09:41:56.619907988Z 2026-08-16T09:41:56Z INFO [vpn] starting 2026-08-16T09:41:56.620000113Z 2026-08-16T09:41:56Z INFO [firewall] allowing VPN connection... 2026-08-16T09:41:56.647228002Z 2026-08-16T09:41:56Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T09:41:56.647948513Z 2026-08-16T09:41:56Z INFO [wireguard] Connecting to 64.44.86.155:51820 2026-08-16T09:41:56.648464934Z 2026-08-16T09:41:56Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T09:42:02.749364600Z 2026-08-16T09:42:02Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout 2026-08-16T09:42:02.749420044Z 2026-08-16T09:42:02Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T09:42:02.749431602Z 2026-08-16T09:42:02Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T09:42:02.749438834Z 2026-08-16T09:42:02Z INFO [vpn] stopping 2026-08-16T09:42:02.830696141Z 2026-08-16T09:42:02Z INFO [vpn] starting 2026-08-16T09:42:02.831760347Z 2026-08-16T09:42:02Z INFO [firewall] allowing VPN connection... 2026-08-16T09:42:02.858077707Z 2026-08-16T09:42:02Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T09:42:02.858605191Z 2026-08-16T09:42:02Z INFO [wireguard] Connecting to 2.56.189.88:51820 2026-08-16T09:42:02.858993007Z 2026-08-16T09:42:02Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T09:42:08.959103835Z 2026-08-16T09:42:08Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T09:42:08.959118371Z 2026-08-16T09:42:08Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T09:42:08.959120944Z 2026-08-16T09:42:08Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T09:42:08.959123155Z 2026-08-16T09:42:08Z INFO [vpn] stopping 2026-08-16T09:42:09.022053983Z 2026-08-16T09:42:09Z INFO [vpn] starting 2026-08-16T09:42:09.022166342Z 2026-08-16T09:42:09Z INFO [firewall] allowing VPN connection... 2026-08-16T09:42:09.048039639Z 2026-08-16T09:42:09Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T09:42:09.049295511Z 2026-08-16T09:42:09Z INFO [wireguard] Connecting to 89.187.187.78:51820 2026-08-16T09:42:09.050278299Z 2026-08-16T09:42:09Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T09:42:15.149061386Z 2026-08-16T09:42:15Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T09:42:15.149108904Z 2026-08-16T09:42:15Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T09:42:15.149118180Z 2026-08-16T09:42:15Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T09:42:15.149123885Z 2026-08-16T09:42:15Z INFO [vpn] stopping 2026-08-16T09:42:15.215217482Z 2026-08-16T09:42:15Z INFO [vpn] starting 2026-08-16T09:42:15.215755796Z 2026-08-16T09:42:15Z INFO [firewall] allowing VPN connection... 2026-08-16T09:42:15.260730566Z 2026-08-16T09:42:15Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T09:42:15.262009482Z 2026-08-16T09:42:15Z INFO [wireguard] Connecting to 212.102.61.152:51820 2026-08-16T09:42:15.263012248Z 2026-08-16T09:42:15Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T09:42:21.361645253Z 2026-08-16T09:42:21Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T09:42:21.361694435Z 2026-08-16T09:42:21Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T09:42:21.361727998Z 2026-08-16T09:42:21Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T09:42:21.361734196Z 2026-08-16T09:42:21Z INFO [vpn] stopping 2026-08-16T09:42:21.429298934Z 2026-08-16T09:42:21Z INFO [vpn] starting 2026-08-16T09:42:21.429580244Z 2026-08-16T09:42:21Z INFO [firewall] allowing VPN connection... 2026-08-16T09:42:21.468857971Z 2026-08-16T09:42:21Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T09:42:21.470387162Z 2026-08-16T09:42:21Z INFO [wireguard] Connecting to 165.140.84.37:51820 2026-08-16T09:42:21.471732173Z 2026-08-16T09:42:21Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T09:42:27.569817791Z 2026-08-16T09:42:27Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-16T09:42:27.569873659Z 2026-08-16T09:42:27Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-16T09:42:27.569915284Z 2026-08-16T09:42:27Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-16T09:42:27.569924240Z 2026-08-16T09:42:27Z INFO [vpn] stopping 2026-08-16T09:42:27.646291176Z 2026-08-16T09:42:27Z INFO [vpn] starting 2026-08-16T09:42:27.646567134Z 2026-08-16T09:42:27Z INFO [firewall] allowing VPN connection... 2026-08-16T09:42:27.694787134Z 2026-08-16T09:42:27Z INFO [wireguard] Using available kernelspace implementation 2026-08-16T09:42:27.696368986Z 2026-08-16T09:42:27Z INFO [wireguard] Connecting to 145.223.7.41:51820 2026-08-16T09:42:27.697660101Z 2026-08-16T09:42:27Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-16T09:42:33.795325774Z 2026-08-16T09:42:33Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, par
Chris wrote:
That settles it — the same timeout on a phone's mobile data means your router and ISP aren't the problem, so this isn't a setting you've missed on your end. The box connects the tunnel but the traffic inside it never starts flowing, and that's a deeper issue we need to fix, not something you can. Tom has your full thread and every log you've shared, and I've added this latest result to it. Please leave everything exactly as it is — no more reinstalls or setting changes — so the picture stays clean while he works through it. I'm sorry it's taken this long, and I'm on it with you.
Wulf_Man wrote:
Ah bugger, I was too hasty and already re-installed fresh Ubuntu Server and Sparkbox. Sorry about that. 😅 Hopefully we can still get to the bottom of this. My hardware I am installing all of this on is as follows: HP Z1 Entry Tower G5 Intel i5 9600K 32gb RAM 256gb SSD No GPU
Chris wrote:
No apology needed — a fresh install is a helpful clean slate: it rules out leftover config from all the earlier attempts. Your hardware is a good data point too — an i5-9600K with 32GB is far more than SparkBox needs, so this isn't a resource issue. It keeps the focus on the tunnel's DNS layer, which is exactly what's already sitting with Tom. Every log, both VPNs, both protocols, and the hotspot test are in his notes. I'll post back here the moment there's a read.
Wulf_Man wrote:
I have some more info. I used and old laptop I have to install the same version of Ubuntu Server on, the latest version, then installed the sparkbox, installed Media and use the exact same SurfShark WireGuard private key, and lo and behold it works. So now the question is, why does the other PC not allow the VPN to work?
Chris wrote:
That result on the laptop is exactly what we needed, WulfMan — the key, the config, the Ubuntu version, and Surfshark are all fine. The difference now comes down to the tower's network hardware or its driver, since the same setup works on one machine and not the other. One detail would help: is the tower plugged in with an Ethernet cable or Wi-Fi, and does it have more than one network port? When everything else is identical, the adapter is usually where the answer sits. I'm putting this finding in front of Tom now, and I'll reply here with his read.
Wulf_Man wrote:
I unplugged the network cable from the tower to use on the laptop, so it is exactly the same connection. :) The ethernet port on the tower is the onboard ethernet port on the motherboard.
Chris wrote:
That removes the last variable — same cable, same key, same Ubuntu, and the laptop connects while the tower won't. What's left is the tower's own network adapter: certain controller chipsets are known to drop WireGuard's UDP traffic exactly like this, which is why no setting you changed (MTU, DNS, country, even a different VPN) made a difference. There's nothing further to chase on the software side, so you can stop here. One small thing that would help: the network adapter model from the HP Z1's spec sheet, if it's easy to find. Tom is already on this thread, and I'll post back the moment he's weighed in.
Wulf_Man wrote:
description: Ethernet interface product: Ethernet Connection (7) I219-LM vendor: Intel Corporation
Chris wrote:
Thanks WulfMan — Intel Ethernet Connection (7) I219-LM, got it. I've added the adapter model to the notes on your thread so Tom has the full picture now: both machines, both VPNs, the hotspot result, and this. It's a common adapter, which is why I don't want to guess at a driver quirk from here. Nothing more for you to do — I'll update this thread when there's a read.
Wulf_Man wrote:
Thank you. Once this has been solved I will become a backer as poking around this platform I really like it!
Chris wrote:
WulfMan, we finally have it pinned down. It is the network adapter in your tower, not anything you configured wrong. The onboard Intel I219-LM runs on the e1000e driver, which is known to drop WireGuard UDP traffic when its hardware offloads misbehave. The laptop working with the same key, cable and OS seals it: a quirk of that NIC, not a SparkBox bug we can patch. First, turn the offloads off, then retry the VPN: sudo ethtool -K eno1 tso off gso off gro off tx off rx off (swap eno1 for your interface name from ip link) To make that survive a reboot, save the same command in a small systemd oneshot service. If offloads do not clear it, update the HP Z1 BIOS, or use a USB3 Ethernet adapter to bypass the onboard NIC entirely — the laptop already proved the rest of your setup works.
Wulf_Man wrote:
I updated the system's BIOS to the latest version and now the tunnel establishes and stays up. Thank you very much for the help.
Chris wrote:
That's exactly what we wanted to see — the BIOS update sorted the adapter and the tunnel's now holding steady. Thanks for sticking with it through all those rounds; really glad it's sorted. Enjoy the box!