qBittorrent + ProtonVPN
Posted by Big_Totoro
Hey Tom, I'm getting firewalled and very low DHT and download speeds. On occasion it will be not firewalled and I'll get that green globe and my DHT will go up a bit (never really breaking 250 or so). I'm wondering if it is because of the DoT being set to on? I've read that setting this to off may help with this issue, but im no expert. Any advice is appreciated! Gluetun: P2026-06-10T04:47:43.790309880Z 2026-06-09T21:47:43-07:00 INFO Settings summary: 72026-06-10T04:47:43.790345614Z ├── VPN settings: D2026-06-10T04:47:43.790357168Z | ├── VPN provider settings: A2026-06-10T04:47:43.790365405Z | | ├── Name: protonvpn L2026-06-10T04:47:43.790373415Z | | └── Server selection settings: I2026-06-10T04:47:43.790381182Z | | ├── VPN type: wireguard W2026-06-10T04:47:43.790388875Z | | ├── Countries: canada, united states Q2026-06-10T04:47:43.790396652Z | | ├── Cities: vancouver, seattle S2026-06-10T04:47:43.790404439Z | | └── Wireguard selection settings: A2026-06-10T04:47:43.790412199Z | └── Wireguard settings: H2026-06-10T04:47:43.790420106Z | ├── Private key: [REDACTED] F2026-06-10T04:47:43.790428280Z | ├── Interface addresses: A2026-06-10T04:47:43.790435860Z | | └── [REDACTED] 2026-06-10T04:47:43.790443437Z | ├── Allowed IPs: ?2026-06-10T04:47:43.790450937Z | | ├── 0.0.0.0/0 :2026-06-10T04:47:43.790458420Z | | └── ::/0 I2026-06-10T04:47:43.790495815Z | └── Network interface: tun0 ?2026-06-10T04:47:43.790506142Z | └── MTU: 1320 72026-06-10T04:47:43.790513959Z ├── DNS settings: M2026-06-10T04:47:43.790521642Z | ├── Keep existing nameserver(s): no R2026-06-10T04:47:43.790529596Z | ├── DNS server address to use: 127.0.0.1 O2026-06-10T04:47:43.790537319Z | ├── DNS forwarder server enabled: yes I2026-06-10T04:47:43.790544976Z | ├── Upstream resolver type: dot A2026-06-10T04:47:43.790552850Z | ├── Upstream resolvers: <2026-06-10T04:47:43.790560673Z | | └── cloudflare :2026-06-10T04:47:43.790568263Z | ├── Caching: yes 62026-06-10T04:47:43.790575734Z | ├── IPv6: no J2026-06-10T04:47:43.790583124Z | ├── Update period: every 24h0m0s E2026-06-10T04:47:43.790590694Z | └── DNS filtering settings: E2026-06-10T04:47:43.790598204Z | ├── Block malicious: no ?2026-06-10T04:47:43.790605784Z | ├── Block ads: no H2026-06-10T04:47:43.790613231Z | └── Block surveillance: no <2026-06-10T04:47:43.790620921Z ├── Firewall settings: :2026-06-10T04:47:43.790628388Z | ├── Enabled: yes :2026-06-10T04:47:43.790635765Z | ├── Input ports: 62026-06-10T04:47:43.790643805Z | | ├── 8989 62026-06-10T04:47:43.790651182Z | | ├── 7878 62026-06-10T04:47:43.790658879Z | | ├── 9696 62026-06-10T04:47:43.790666213Z | | ├── 8686 62026-06-10T04:47:43.790673493Z | | ├── 8080 62026-06-10T04:47:43.790681093Z | | ├── 8191 62026-06-10T04:47:43.790688430Z | | └── 6767 ?2026-06-10T04:47:43.790696263Z | └── Outbound subnets: @2026-06-10T04:47:43.790703797Z | ├── [REDACTED] <2026-06-10T04:47:43.790711857Z | ├── [REDACTED] ?2026-06-10T04:47:43.790720347Z | └── [REDACTED] 72026-06-10T04:47:43.790727904Z ├── Log settings: =2026-06-10T04:47:43.790735288Z | └── Log level: info :2026-06-10T04:47:43.790742618Z ├── Health settings: V2026-06-10T04:47:43.790750032Z | ├── Server listening address: 127.0.0.1:9999 ?2026-06-10T04:47:43.790757598Z | ├── Target addresses: D2026-06-10T04:47:43.790764939Z | | ├── cloudflare.com:443 @2026-06-10T04:47:43.790772302Z | | └── github.com:443 X2026-06-10T04:47:43.790779599Z | ├── Small health check type: ICMP echo request B2026-06-10T04:47:43.790787066Z | | └── ICMP target IPs: =2026-06-10T04:47:43.790804760Z | | ├── 1.1.1.1 =2026-06-10T04:47:43.790813983Z | | └── 8.8.8.8 U2026-06-10T04:47:43.790821760Z | └── Restart VPN on healthcheck failure: yes F2026-06-10T04:47:43.790831470Z ├── Shadowsocks server settings: 92026-06-10T04:47:43.790839997Z | └── Enabled: no 2026-06-10T04:47:43.790847458Z ├── HTTP proxy settings: 92026-06-10T04:47:43.790854931Z | └── Enabled: no B2026-06-10T04:47:43.790862281Z ├── Control server settings: F2026-06-10T04:47:43.790869685Z | ├── Listening address: :8000 :2026-06-10T04:47:43.790877145Z | ├── Logging: yes a2026-06-10T04:47:43.790884612Z | └── Authentication file path: /gluetun/auth/config.toml ;2026-06-10T04:47:43.790892492Z ├── Storage settings: M2026-06-10T04:47:43.790899839Z | └── Filepath: /gluetun/servers.json =2026-06-10T04:47:43.790907299Z ├── OS Alpine settings: ?2026-06-10T04:47:43.790914683Z | ├── Process UID: 1000 ?2026-06-10T04:47:43.790922116Z | ├── Process GID: 1000 I2026-06-10T04:47:43.790929436Z | └── Timezone: america/vancouver =2026-06-10T04:47:43.790936783Z ├── Public IP settings: K2026-06-10T04:47:43.790944190Z | ├── IP file path: /tmp/gluetun/ip M2026-06-10T04:47:43.790951657Z | ├── Public IP data base API: ipinfo I2026-06-10T04:47:43.790959141Z | └── Public IP data backup APIs: <2026-06-10T04:47:43.790966491Z | ├── ifconfigco =2026-06-10T04:47:43.790973791Z | ├── ip2location <2026-06-10T04:47:43.790981228Z | └── cloudflare ;2026-06-10T04:47:43.791014862Z └── Version settings: :2026-06-10T04:47:43.791032412Z └── Enabled: yes �2026-06-10T04:47:43.807549158Z 2026-06-09T21:47:43-07:00 INFO [routing] default route found: interface eth1, gateway [REDACTED] , assigned [REDACTED] and family v4 c2026-06-10T04:47:43.807787452Z 2026-06-09T21:47:43-07:00 INFO [routing] adding route for 0.0.0.0/0 d2026-06-10T04:47:43.807932025Z 2026-06-09T21:47:43-07:00 INFO [firewall] setting allowed subnets... �2026-06-10T04:47:43.816788703Z 2026-06-09T21:47:43-07:00 INFO [routing] default route found: interface eth1, gateway [REDACTED] , assigned IP [REDACTED] and family v4 h2026-06-10T04:47:43.816806512Z 2026-06-09T21:47:43-07:00 INFO [routing] adding route for 192.168.0.0/16 d2026-06-10T04:47:43.817133026Z 2026-06-09T21:47:43-07:00 INFO [routing] adding route for 10.0.0.0/8 g2026-06-10T04:47:43.817510878Z 2026-06-09T21:47:43-07:00 INFO [routing] adding route for 172.16.0.0/12 �2026-06-10T04:47:43.818344268Z 2026-06-09T21:47:43-07:00 INFO [firewall] setting allowed input port 8989 through interface eth1... �2026-06-10T04:47:43.876932760Z 2026-06-09T21:47:43-07:00 INFO [firewall] setting allowed input port 7878 through interface eth1... �2026-06-10T04:47:43.893283187Z 2026-06-09T21:47:43-07:00 INFO [firewall] setting allowed input port 9696 through interface eth1... �2026-06-10T04:47:43.906226981Z 2026-06-09T21:47:43-07:00 INFO [firewall] setting allowed input port 8686 through interface eth1... �2026-06-10T04:47:43.974051483Z 2026-06-09T21:47:43-07:00 INFO [firewall] setting allowed input port 8080 through interface eth1... �2026-06-10T04:47:43.994244084Z 2026-06-09T21:47:43-07:00 INFO [firewall] setting allowed input port 8191 through interface eth1... �2026-06-10T04:47:44.012519747Z 2026-06-09T21:47:44-07:00 INFO [firewall] setting allowed input port 6767 through interface eth1... o2026-06-10T04:47:44.025065162Z 2026-06-09T21:47:44-07:00 INFO [http server] http server listening on [::]:8000 k2026-06-10T04:47:44.025080424Z 2026-06-09T21:47:44-07:00 INFO [dns] using plaintext DNS at address 1.1.1.1 h2026-06-10T04:47:44.025085039Z 2026-06-09T21:47:44-07:00 INFO [healthcheck] listening on 127.0.0.1:9999 d2026-06-10T04:47:44.064593938Z 2026-06-09T21:47:44-07:00 INFO [firewall] allowing VPN connection... u2026-06-10T04:47:44.073882286Z 2026-06-09T21:47:44-07:00 INFO [wireguard] Using available kernelspace implementation l2026-06-10T04:47:44.076300992Z 2026-06-09T21:47:44-07:00 INFO [wireguard] Connecting to 79.127.254.92:51820 2026-06-10T04:47:44.077860004Z 2026-06-09T21:47:44-07:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. J2026-06-10T04:47:50.174828316Z 2026-06-09T21:47:50-07:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout �2026-06-10T04:47:50.174853347Z 2026-06-09T21:47:50-07:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md �2026-06-10T04:47:50.174860236Z 2026-06-09T21:47:50-07:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION M2026-06-10T04:47:50.174872742Z 2026-06-09T21:47:50-07:00 INFO [vpn] stopping M2026-06-10T04:47:50.339319689Z 2026-06-09T21:47:50-07:00 INFO [vpn] starting d2026-06-10T04:47:50.339474139Z 2026-06-09T21:47:50-07:00 INFO [firewall] allowing VPN connection... u2026-06-10T04:47:50.446659718Z 2026-06-09T21:47:50-07:00 INFO [wireguard] Using available kernelspace implementation n2026-06-10T04:47:50.447588523Z 2026-06-09T21:47:50-07:00 INFO [wireguard] Connecting to 185.159.156.179:51820 2026-06-10T04:47:50.451593590Z 2026-06-09T21:47:50-07:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. B2026-06-10T04:47:56.550234587Z 2026-06-09T21:47:56-07:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: running TLS handshake: context deadline exceeded, parallel attempt 2/2 failed: running TLS handshake: context deadline exceeded �2026-06-10T04:47:56.550397426Z 2026-06-09T21:47:56-07:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md �2026-06-10T04:47:56.550406058Z 2026-06-09T21:47:56-07:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION M2026-06-10T04:47:56.550409960Z 2026-06-09T21:47:56-07:00 INFO [vpn] stopping M2026-06-10T04:47:56.671504865Z 2026-06-09T21:47:56-07:00 INFO [vpn] starting d2026-06-10T04:47:56.672553622Z 2026-06-09T21:47:56-07:00 INFO [firewall] allowing VPN connection... u2026-06-10T04:47:56.752496353Z 2026-06-09T21:47:56-07:00 INFO [wireguard] Using available kernelspace implementation m2026-06-10T04:47:56.752529129Z 2026-06-09T21:47:56-07:00 INFO [wireguard] Connecting to 79.127.254.119:51820 2026-06-10T04:47:56.752534238Z 2026-06-09T21:47:56-07:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. m2026-06-10T04:47:56.933272140Z 2026-06-09T21:47:56-07:00 INFO [dns] downloading hostnames and IP block lists d2026-06-10T04:47:56.948609709Z 2026-06-09T21:47:56-07:00 INFO [dns] DNS server listening on [::]:53 J2026-06-10T04:47:57.458897166Z 2026-06-09T21:47:57-07:00 INFO [dns] ready �2026-06-10T04:47:57.983163896Z 2026-06-09T21:47:57-07:00 INFO [ip getter] [REDACTED] source: ipinfo+ifconfig.co+ip2location+cloudflare) o2026-06-10T04:47:58.719942731Z 2026-06-09T21:47:58-07:00 INFO [vpn] You are running the latest release v3.41.1 qbittorrent: 2026-06-10T05:00:46.514624063Z ╔═════════════════════════════════════════════════════════════════════════╗ o2026-06-10T05:00:46.514700775Z ║ ║ o2026-06-10T05:00:46.514717569Z ║ Some of the contents of the folder /custom-cont-init.d ║ o2026-06-10T05:00:46.514730186Z ║ are not owned by root, which is a security risk. ║ o2026-06-10T05:00:46.514742337Z ║ ║ o2026-06-10T05:00:46.514754257Z ║ Please review the permissions of this folder and its contents to make ║ o2026-06-10T05:00:46.514765974Z ║ sure they are owned by root, and can only be modified by root. ║ o2026-06-10T05:00:46.514778004Z ║ ║ 2026-06-10T05:00:46.514813905Z ╚═════════════════════════════════════════════════════════════════════════╝ S2026-06-10T05:00:46.523482056Z [custom-init] No custom services found, skipping... 42026-06-10T05:00:46.658037177Z [migrations] started @2026-06-10T05:00:46.658105489Z [migrations] no migrations found 32026-06-10T05:00:46.739656252Z usermod: no changes �2026-06-10T05:00:46.765079217Z ─────────────────────────────────────── 2026-06-10T05:00:46.765115958Z k2026-06-10T05:00:46.765165270Z ██╗ ███████╗██╗ ██████╗ p2026-06-10T05:00:46.765175323Z ██║ ██╔════╝██║██╔═══██╗ j2026-06-10T05:00:46.765184420Z ██║ ███████╗██║██║ ██║ j2026-06-10T05:00:46.765193110Z ██║ ╚════██║██║██║ ██║ z2026-06-10T05:00:46.765201717Z ███████╗███████║██║╚██████╔╝ u2026-06-10T05:00:46.765210151Z ╚══════╝╚══════╝╚═╝ ╚═════╝ 2026-06-10T05:00:46.765218451Z C2026-06-10T05:00:46.765225958Z Brought to you by linuxserver.io �2026-06-10T05:00:46.765233711Z ─────────────────────────────────────── 2026-06-10T05:00:46.766142339Z ?2026-06-10T05:00:46.766206468Z To support LSIO projects visit: B2026-06-10T05:00:46.766218345Z https://www.linuxserver.io/donate/ 2026-06-10T05:00:46.766226528Z �2026-06-10T05:00:46.766234232Z ─────────────────────────────────────── '2026-06-10T05:00:46.766244185Z GID/UID �2026-06-10T05:00:46.766251969Z ─────────────────────────────────────── 2026-06-10T05:00:46.777525576Z 12026-06-10T05:00:46.777569607Z User UID: 1000 12026-06-10T05:00:46.777580051Z User GID: 1000 �2026-06-10T05:00:46.777588431Z ─────────────────────────────────────── K2026-06-10T05:00:46.781753870Z Linuxserver.io version: 5.2.0v2.0.12-ls458 E2026-06-10T05:00:46.782233590Z Build-date: 2026-05-17T08:57:46+00:00 �2026-06-10T05:00:46.782262957Z ─────────────────────────────────────── $2026-06-10T05:00:46.782274628Z D2026-06-10T05:00:46.982425588Z [custom-init] Files found, executing T2026-06-10T05:00:46.987630235Z [custom-init] 00-set-admin-password.sh: executing... �2026-06-10T05:00:47.007963580Z [sparkbox-qbit-init] Detected broken quoted @ByteArray hash from old SparkBox version — rewriting unquoted. u2026-06-10T05:00:47.013337398Z [sparkbox-qbit-init] Rewrote /config/qBittorrent/qBittorrent.conf with unquoted hash. �2026-06-10T05:00:47.038832139Z [sparkbox-qbit-init] Injected admin password + LAN-access settings into /config/qBittorrent/qBittorrent.conf P2026-06-10T05:00:47.039532245Z [custom-init] 00-set-admin-password.sh: exited 0 i2026-06-10T05:00:47.484205949Z WebUI will be started shortly after internal preparations. Please wait... 2026-06-10T05:00:47.563890858Z =2026-06-10T05:00:47.563940570Z Information b2026-06-10T05:00:47.564187476Z To control qBittorrent, access the WebUI at: http://localhost:8080 a2026-06-10T05:00:48.163229553Z Connection to localhost (::1) 8080 port [tcp/http-alt] succeeded! 22026-06-10T05:00:48.193902060Z [ls.io-init] done. EDIT Seems like it came out of being firewalled for now, but as you can see my Speed is still painful and not alot of DHT Nodes.
5 replies
tomspark wrote:
Nothing's broken here. Those VPN 'restarting' lines at the top of your log are just the app trying a couple of servers before one answered — it connected fine right after. Being firewalled in qBittorrent mostly slows your uploads (seeding), not downloads, so it's usually not why downloads feel slow. Getting firewalled and very low DHT together is most often just a torrent that doesn't have many healthy seeders. Turning DoT off won't change the firewalled status, so you can leave it on. If you really want that green globe, that needs VPN 'port forwarding' — Proton supports it, but it's a more advanced setup. Happy to walk you through it if you'd like.
Big_Totoro wrote:
Tom, "VPN 'port forwarding' — Proton supports it, but it's a more advanced setup. Happy to walk you through it if you'd like." Id appreciate that. I've fumbled around for days now trying to get good speeds. Some swarms are in the thousands, but i'm only getting access to like 20 peers. I always test with the Alternate DL ubuntu images as they have large seeds/peers. Every change i make i test with the same file from the same torrent location to try and keep it as fair and accurate as possible.
tomspark wrote:
Let me level with you on this one. Port forwarding on Proton is the thing that can help here, but right now it's hit-or-miss — a couple of other folks and I are chasing a timeout bug with it, so I'd hold off rather than send you down another days-long rabbit hole. And honestly, port forwarding only boosts seeding, not your download speed. Getting only ~20 peers out of a swarm of thousands usually points at qBittorrent's connection limits or the VPN throttling, not forwarding. Quick check: in qBittorrent → Settings → Connection, what are your 'Global maximum connections' and 'Maximum connections per torrent' set to? Let's start there.
Big_Totoro wrote:
Hey Tom, I have those cranked up pretty high in the hopes of capturing more peers.
tomspark wrote:
With your connection limits already cranked up and Proton's port-forwarding still hit-or-miss on our end, only grabbing ~20 peers out of a huge swarm usually means the VPN server itself is the bottleneck — overloaded or throttling you. Easiest test: switch to a different Proton server (or city) and re-run the exact same torrent. If the peer count jumps, that was it. If you'd rather have port-forwarding that just works (it genuinely helps connectability and seeding), Surfshark has been the most reliable for our users and supports it — it's 87% off + 4 months free through our link: https://get.surfshark.net/affc?offerid=1126&affid=9447&affsub=hr52es