PUQ Mautic Skip to main content

21. Diagnostics

Overview

The Diagnostics section provides real-time monitoring, log viewing, and system integrity checking across all VPN protocols, traffic control, monitoring services, and the panel itself.

Navigate to Diagnostics in the main menu to access the following pages:

Diagnostics menu Diagnostics dropdown menu

Page Description
WireGuard WireGuard service status, wg show output, kernel logs
AmneziaWG AmneziaWG service status, awg show output, kernel logs
OpenVPN OpenVPN service status, certificates, instances, connection events, auth log, server logs
IKEv2 strongSwan service status, certificates, ipsec statusall output, IKEv2 logs
Traffic Control Overview of TC classes, per-interface bandwidth statistics with live throughput
Telegraf Telegraf service status, InfluxDB output config, inputs, Telegraf logs
System Server uptime, memory, disk usage, network interfaces, system logs
Panel PUQVPNCP application log viewer (puqvpncp.log)
Integrity Check Full system integrity audit — verifies firewall rules, ipset, routing, TC classes, interfaces

Permission: All diagnostics pages require the diagnostics:read permission. Integrity Check requires firewall:read (audit) and firewall:write (fix).

All log viewers feature:

  • Auto-refresh every 3 seconds
  • Pause / Resume button to stop auto-refresh
  • Line count selector (50, 100, 200, 500 lines)
  • Color-coded log entries (errors in red, warnings in yellow, connections in green)

WireGuard

Diagnostics: WireGuard Diagnostics: WireGuard — service status, wg show, kernel logs

Service Status

Field Description
WireGuard Installed WireGuard kernel module version
WireGuard Tools Installed wireguard-tools package version
Networks Number of WireGuard-enabled networks
Clients Total number of WireGuard clients
Online Number of currently connected WireGuard peers

If WireGuard or WireGuard Tools are not installed, or no networks are configured, a warning alert is displayed with instructions.

wg show

Displays the raw output of the wg show command — the standard WireGuard status tool. Shows all active WireGuard interfaces with their public keys, listening ports, and connected peers with handshake times and transfer statistics.

This section is collapsible. Click the header to expand/collapse.

WireGuard Kernel Logs

Displays WireGuard-related kernel messages from journalctl. These logs show low-level WireGuard events such as interface creation, peer handshake failures, and kernel module messages.


AmneziaWG

Diagnostics: AmneziaWG Diagnostics: AmneziaWG — service status, awg show, and kernel logs

Service Status

Field Description
AmneziaWG Installed AmneziaWG kernel module (DKMS) version
AmneziaWG Tools Installed amneziawg-tools package CLI version (awg)
Networks Number of AmneziaWG-enabled networks
Clients Total number of AmneziaWG clients
Online Number of currently connected AmneziaWG peers

If AmneziaWG or AmneziaWG Tools are not installed, or no networks are configured, an informative warning alert is displayed with repository and package installation instructions for Debian (with build-essential dkms linux-headers-$(uname -r)) and Ubuntu (add-apt-repository -y ppa:amnezia/ppa).

awg show

Displays the raw output of the awg show command — the standard AmneziaWG status tool. Shows all active AmneziaWG interfaces with obfuscation parameters (Jc, Jmin, Jmax, S1, S2, H1, H2, H3, H4), public keys, listening ports, and connected peers with handshake times and transfer statistics.

This section is collapsible. Click the header to expand/collapse.

AmneziaWG Kernel Logs

Displays AmneziaWG-related kernel messages from journalctl. These logs show low-level AmneziaWG events such as interface creation, handshake negotiations, and kernel module messages.


OpenVPN

Service Status and Certificates

Diagnostics: OpenVPN — status Diagnostics: OpenVPN — service status, certificates, instances

The page displays two cards side by side:

Service Status:

Field Description
OpenVPN Installed OpenVPN package version
easy-rsa Installed easy-rsa package version
Global Status Whether OpenVPN is globally enabled or disabled
Networks Number of OpenVPN-enabled networks
Online Number of currently connected OpenVPN clients

Certificates:

Field Description
CA Certificate Root CA certificate status (Valid / Not generated / Invalid)
Server Certificate Server TLS certificate status
DH Parameters Diffie-Hellman parameters status
TLS Auth Key HMAC authentication key status

Instances

Shows a table of all OpenVPN network instances:

Column Description
Network Network name (link to network edit page)
Port UDP/TCP port for this instance
Status Running (green) or Stopped (red)
PID Process ID (if running)

Each OpenVPN-enabled network runs as a separate openvpn process with its own PID file.

Connection Events

Diagnostics: OpenVPN — logs Diagnostics: OpenVPN — connection events and authentication log

Displays the OpenVPN connection log (/etc/openvpn/puqvpncp/logs/connections.log). Shows client connect and disconnect events with color coding:

  • Green — CONNECT events
  • Yellow — DISCONNECT events

Authentication Log

Displays the OpenVPN authentication log (/etc/openvpn/puqvpncp/logs/auth.log). Shows authentication attempts with color coding:

  • Green — AUTH OK events
  • Red — AUTH FAILED or AUTH ERROR events

Server Logs

Diagnostics: OpenVPN — server logs Diagnostics: OpenVPN — server logs from all network instances

Displays combined server logs from all OpenVPN network instances (/etc/openvpn/puqvpncp/logs/*.log). Each log line is prefixed with the network name in square brackets (e.g., [net1] ...).


IKEv2

Service Status and Certificates

Diagnostics: IKEv2 Diagnostics: IKEv2 — service status, certificates, ipsec statusall

The page displays two cards side by side:

Service Status:

Field Description
strongSwan Installed strongSwan version
Starter PID PID of the strongSwan starter process
Charon PID PID of the IKE daemon (charon)
Global Status Whether IKEv2 is globally enabled or disabled
Server Domain Domain configured for IKEv2 server certificates
Online Number of currently connected IKEv2 clients

Certificates:

Field Description
CA Certificate Root CA certificate status (Valid / Not generated / Invalid)
Server Certificate Server certificate status

ipsec statusall

Displays the raw output of the ipsec statusall command — the standard strongSwan status tool. Shows detailed information about:

  • IKE charon daemon status (version, uptime, memory, threads, plugins)
  • Virtual IP pools with size/online/offline counters
  • Active security associations (SAs)
  • Connection definitions

This section is collapsible.

IKEv2 / strongSwan Logs

Diagnostics: IKEv2 — logs Diagnostics: IKEv2 — strongSwan logs

Displays strongSwan logs from journalctl. Shows IKE negotiation events, connection establishments, certificate validations, and authentication messages. The system tries strongswan unit first, then falls back to charon syslog tag.


Traffic Control

Diagnostics: Traffic Control Diagnostics: Traffic Control — overview and per-interface TC classes

Overview

Field Description
Managed Interfaces Total number of network interfaces with TC rules
Total TC Classes Total number of HTB traffic control classes across all interfaces
Total Bytes Processed Sum of all bytes processed by TC classes
Total Drops Sum of all dropped packets (highlighted in red if > 0)

The overview auto-refreshes every 2 seconds.

Per-Interface Tables

Below the overview, each managed interface is displayed as a separate card showing all its TC classes:

Column Description
Handle TC class handle (e.g., 1:806e)
Type Class type — root for the root class, or direction + protocol (e.g., DL IPv4 #110, UL IPv6 #119)
Rate Configured bandwidth rate
Bytes Total bytes processed by this class
Packets Total packets processed
Drops Dropped packets (highlighted in red if > 0)
Overlimits Overlimit events (highlighted in yellow if > 0)
Throughput Real-time throughput calculated from byte deltas between refreshes

Interfaces include:

  • Gateway interfaces (e.g., ens18) — main server network interfaces
  • WireGuard interfaces (e.g., wg51824) — per-network WireGuard tunnel interfaces
  • OpenVPN interfaces (e.g., ovpn1197) — per-network OpenVPN tunnel interfaces
  • Upstream interfaces (e.g., wgup1) — upstream WireGuard tunnel interfaces

Telegraf

Diagnostics: Telegraf Diagnostics: Telegraf — service status, InfluxDB config, inputs, logs

Service Info

Three cards are displayed:

Telegraf Service:

Field Description
Version Installed Telegraf version
Status Running (with PID) or Stopped

InfluxDB Output:

Field Description
Enabled Whether InfluxDB output is enabled
URL InfluxDB server URL
Bucket InfluxDB bucket name
Organization InfluxDB organization

Inputs:

Field Description
Socket Listener Whether the Unix socket input is active (receives metrics from PUQVPNCP)
HTTP Metrics Whether the HTTP metrics endpoint is active

Telegraf Logs

Displays Telegraf service logs from journalctl with color coding:

  • Red — Error messages (E!)
  • Yellow — Warning messages (W!)
  • Gray — Debug messages (D!)

System

Diagnostics: System Diagnostics: System — uptime, memory, disk usage, interfaces

System Info Cards

Four cards are displayed:

Uptime — output of the uptime command showing server uptime, number of users, and load averages.

Memory — output of free -h showing total, used, free, shared, buffers/cache, and available memory for both RAM and swap.

Disk Usage — output of df -h showing mounted filesystem, size, used space, available space, and usage percentage for the root partition.

Interfaces — output of ip -br addr showing all network interfaces with their status (UP/DOWN) and assigned IP addresses. Includes physical interfaces, WireGuard interfaces, OpenVPN tunnel interfaces, and upstream tunnels.

System Logs (puqvpncp)

Diagnostics: System — logs Diagnostics: System — PUQVPNCP system logs

Displays PUQVPNCP service logs from journalctl (syslog tag puqvpncp). Shows application events such as API requests, system operations, network changes, and service lifecycle events.


Panel Log

Diagnostics: Panel Log Diagnostics: Panel Log — puqvpncp.log viewer

Displays the PUQVPNCP application log file (puqvpncp.log in the configured LogDir directory, default /var/log/puqvpncp/).

This is the application's own log file (separate from journalctl system logs). Log entries are color-coded by level:

  • Red — ERROR: messages
  • Yellow — WARN: messages
  • Gray — DEBUG: messages
  • Normal — INFO: messages

The log format is: timestamp LEVEL: message (e.g., 2026-03-11T17:18:00.000Z INFO: ReloadNetworks: setting iptables).


Integrity Check

Integrity Check Integrity Check — summary, log table, and last run info

The Integrity Check performs a comprehensive audit of the entire PUQVPNCP system configuration. It verifies that all firewall rules, routing tables, ipset entries, traffic control classes, and network interfaces are correctly configured and match the expected state.

Running a Check

Two buttons are available in the page header:

Button Description
Audit (magnifying glass) Run a read-only audit — checks all rules and reports issues without making changes
Audit & Fix (wrench) Run an audit and automatically fix any issues found

The check runs in the background. Results stream in real-time via Server-Sent Events (SSE), with automatic polling fallback if SSE disconnects.

Summary

The summary card shows counters for each check result:

Counter Color Description
Total — Total number of checks performed
OK Green Checks that passed
Failed Red Checks that failed (in audit mode, these need fixing)
Fixed Yellow Checks that were failed but successfully repaired (fix mode only)
Errors Blue Checks where the fix was applied but still failing
Skipped Gray Checks that were skipped (e.g., ipset not installed, mangle overflow)

A progress bar shows the proportion of each result type.

Filter Buttons

Filter the log table by status:

  • All — show all entries
  • Failed — show failed, fixed, error, and skipped entries (default)
  • Fixed — show only fixed entries
  • OK — show only passed entries
  • Skipped — show only skipped entries

Log Table

Column Description
Time Timestamp of the check
Status Result badge (OK / FAILED / FIXED / ERROR / SKIPPED)
Category Check category (see below)
Network Network and/or client name (if applicable)
Description What was checked
Detail Additional information (e.g., "Fixed", error message)

Check Categories

The integrity check performs 9 phases, covering all aspects of the system:

Category Phase What is Checked
System 1 IPv4 forwarding enabled, INPUT/FORWARD/OUTPUT chain policies, system_PUQVPNCP rule
Global Rules 2 Pre-filter rules, peering ACCEPT rules (A→B, B→A), intra-network ACCEPT, isolation DROP (ipset), post-filter rules
ipset 3 puq_vpn_nets ipset exists, each network subnet is a member
Chains 4 Per-network chains exist in filter (PQ_), nat SNAT (PQN_), nat DNAT (PQD_), mangle (PQM_) — plus jump rules from built-in chains
NAT 5 SNAT rules for each network's upstream IP
Mangle 5 Per-client mangle marks for download (dst) and upload (src) traffic
Network Rules 5 Route ACCEPT rules for custom routes
Policy Routing 6 Upstream WG tunnel ip rule / ip route table, WG/OpenVPN fwmark-based policy routing
CONNMARK 7 WG and OpenVPN CONNMARK rules in PREROUTING (mangle)
Traffic Control 8 Root HTB qdisc on gateway, VPN, and upstream interfaces; per-client TC classes
Interfaces 9 WireGuard interfaces are UP, upstream WG tunnel interfaces are UP

Last Run

The Last Run card shows information about the most recent integrity check:

Field Description
Mode audit or fix
Started When the check started
Duration How long the check took
Result Summary of OK, failed, fixed, errors, and skipped counts