Newly installed Nethserver Node has only 127.0.0.1 as Its IP Address

NethServer Version: 8

Hi,

i installed a new Nethserver instance and set up a cluster. While creating the cluster, I received a message stating that the VRN address was already in use, which is definitely not the case. After a reboot, I was able to log in to the admin console normally.
Now I notice that the IP address 192.168.154.1, which was assigned during installation, is not available in the node’s view.

The FQDN under which the server is accessible is also missing.
A certificate with the FQDN is not issued either, even though the appropriate port settings are configured.

Here’s a picture of another system to illustrate the difference.
I removed the FQDN from this image.

The shown IP 127.0.0.1 is normal after a fresh installation, after about a minute it should show the right interface IP and the FQDN.

Did you use the standard procedure or the pre-built image?

If you used the pre-built image or a Proxmox template, see Proxmox VM full or linked clone from template - #5 by davidep

Hi @mrmarkuz

I did it the traditional way.
I created a VM on Proxmox and booted from the Rocky 9.4 minimal ISO. I installed Rocky and applied all the updates.
I installed the Qemu Agent and configured it so that the service runs at startup

I then installed Nethserver as described in the instructions. Before that, I had already configured the necessary port forwarding settings on my gateway. The installation of NS 8 completed without any error messages. I then performed the initial setup (create cluster). I did not change the default VPN IP. The cluster installation aborted with an error message stating that the specified VPN IP was already in use. In addition, several other error messages appeared, which i unfortunately didn’t record.

I have now uninstalled Netherver according to the instructions. Attached are the messages as I see them in PuTTY.

Deleting rootless module traefik1…
Deleting rootless module metrics1…
Deleting rootless module ldapproxy1…
Deleting rootless module samba1…
Clean up firewalld core rules
cockpit no need to be removed
dhcpv6-client no need to be removed
success
ssh no need to be removed
Warning: NOT_ENABLED: 10.5.4.0/24
success
Stopping the core services and timers
Removed “/etc/systemd/system/multi-user.target.wants/api-server.service”.
Removed “/etc/systemd/system/timers.target.wants/password-warning.timer”.
Removed “/etc/systemd/system/default.target.wants/redis.service”.
removed ‘/etc/wireguard/wg0.conf’
userdel: api-server mail spool (/var/spool/mail/api-server) not found
Cannot find device “wg0”
Wipe Redis DB
redis-data
Deleting cluster and agent core modules
Removed “/etc/systemd/system/default.target.wants/agent@cluster.service”.
Removed “/etc/systemd/system/default.target.wants/agent@node.service”.
Removing main directories
Uninstalling the core image files
removed ‘/etc/containers/containers.conf’
removed ‘/etc/containers/registries.conf.d/800-nethserver.conf’
removed ‘/etc/profile.d/api-cli.sh’
removed ‘/etc/profile.d/nethserver.sh’
removed ‘/etc/profile.d/runagent.sh’
removed ‘/etc/profile.d/volumectl.sh’
removed ‘/etc/systemd/system-generators/limit-load’
removed ‘/etc/systemd/system/agent@.service’
removed ‘/etc/systemd/system/api-server-motd.service’
removed ‘/etc/systemd/system/api-server.service’
removed ‘/etc/systemd/system/apply-updates.service’
removed ‘/etc/systemd/system/apply-updates.timer’
removed ‘/etc/systemd/system/backup-timers.service’
removed ‘/etc/systemd/system/check-subscription.service’
removed ‘/etc/systemd/system/dnf-automatic-download.service.d/10-ns8.conf’
removed ‘/etc/systemd/system/dnf-automatic-install.service.d/10-ns8.conf’
removed ‘/etc/systemd/system/dnf-automatic-notifyonly.service.d/10-ns8.conf’
removed ‘/etc/systemd/system/dnf-automatic.service.d/10-ns8.conf’
removed ‘/etc/systemd/system/fix-xdg-state@.service’
removed ‘/etc/systemd/system/node_exporter.service’
removed ‘/etc/systemd/system/overlay-cleanup.service’
removed ‘/etc/systemd/system/password-warning.service’
removed ‘/etc/systemd/system/password-warning.timer’
removed ‘/etc/systemd/system/phonehome.service’
removed ‘/etc/systemd/system/phonehome.timer’
removed ‘/etc/systemd/system/promtail.service’
removed ‘/etc/systemd/system/rclone-gateway.service’
removed ‘/etc/systemd/system/redis.service’
removed ‘/etc/systemd/system/refresh-node-info.service’
removed ‘/etc/systemd/system/send-backup.service’
removed ‘/etc/systemd/system/send-backup.timer’
removed ‘/etc/systemd/system/send-heartbeat.service’
removed ‘/etc/systemd/system/send-inventory.service’
removed ‘/etc/systemd/system/send-inventory.timer’
removed ‘/etc/systemd/system/support.service’
removed ‘/etc/systemd/system/tun-manager@.service’
removed ‘/etc/systemd/system/user@.service.d/20-after-redis.conf’
removed ‘/etc/systemd/system/user@.service.d/30-fix-xdg-state.conf’
removed ‘/etc/systemd/system/user@0.service.d/20-after-redis.conf’
removed ‘/etc/systemd/system/wg-quick@wg0.service.d/10-ns8.conf’
removed ‘/etc/systemd/user/agent.service’
removed ‘/etc/systemd/user/api-moduled.service’
removed ‘/etc/systemd/user/transfer-state.target’
removed ‘/usr/local/bin/acl-load’
removed ‘/usr/local/bin/agent’
removed ‘/usr/local/bin/api-cli’
removed ‘/usr/local/bin/api-moduled’
removed ‘/usr/local/bin/api-server’
removed ‘/usr/local/bin/api-server-logs’
removed ‘/usr/local/bin/api-server-motd’
removed ‘/usr/local/bin/logcli’
removed ‘/usr/local/bin/logcli.bin’
removed ‘/usr/local/bin/redis-wait-ready’
removed ‘/usr/local/bin/runagent’
removed ‘/usr/local/bin/volumectl’
removed ‘/usr/local/sbin/add-module’
removed ‘/usr/local/sbin/add-user’
removed ‘/usr/local/sbin/apply-vpn-routes’
removed ‘/usr/local/sbin/create-cluster’
removed ‘/usr/local/sbin/disk-performance’
removed ‘/usr/local/sbin/grant-actions’
removed ‘/usr/local/sbin/join-cluster’
removed ‘/usr/local/sbin/overlay-cleanup’
removed ‘/usr/local/sbin/redis-cli’
removed ‘/usr/local/sbin/remove-module’
removed ‘/usr/local/sbin/remove-user’
removed ‘/usr/local/sbin/revoke-actions’
removed ‘/usr/local/sbin/switch-leader’
removed ‘/usr/local/sbin/tun-manager’
removed ‘/usr/local/sbin/update-core’
removed ‘/usr/local/sbin/update-module’
Some files may be left in the following directories:
/etc/
/etc/containers/
/etc/containers/registries.conf.d/
/etc/profile.d/
/etc/systemd/
/etc/systemd/system-generators/
/etc/systemd/system/
/etc/systemd/system/dnf-automatic-download.service.d/
/etc/systemd/system/dnf-automatic-install.service.d/
/etc/systemd/system/dnf-automatic-notifyonly.service.d/
/etc/systemd/system/dnf-automatic.service.d/
/etc/systemd/system/user@.service.d/
/etc/systemd/system/user@0.service.d/
/etc/systemd/system/wg-quick@wg0.service.d/
/etc/systemd/user/
/usr/
/usr/local/
/usr/local/bin/
/usr/local/sbin/
/var/
/var/lib/
Wipe Podman storage
A “/etc/containers/storage.conf” config file exists.
Remove this file if you did not modify the configuration.
Clean up /etc/hosts

I’ve now reinstalled NS 8 on the same VM. After that, the initial setup went smoothly. First, I installed and configured Samba AD. That worked fine so far. However, just like on another NS 8 instance, I’m having trouble logging in to the User Portal. Even though this is a brand-new installation.

What’s going wrong here?

I tried to reproduce the issue without success, installation and user portal are working here.

My user portal is reachable at https://node.ns8.test/users-admin/ad.ns8.test and I’m able to login as Administrator.

Are there errors in the logs when you try to login?

Is the samba domain reachable from the NS8?

ping myad.xxx.com

The samba domain is reachable from NS 8.

That is all what i can find in the logs.

2026-08-04T13:30:32+02:00 [1:samba1:samba-dc] Auth: [Kerberos KDC,ENC-TS Pre-authentication] user [(null)][Administrator@XXXXX.XXXXX-ONLINE.COM] at [Tue, 04 Aug 2026 11:30:32.850676 UTC] with [aes256-cts-hmac-sha1-96] status [NT_STATUS_PROTOCOL_UNREACHABLE] workstation [(null)] remote host [ipv4:192.168.154.1:48201] mapped to [XXX-ONLINE][Administrator]. local host [NULL] 2026-08-04T13:30:33+02:00 [1:traefik1:traefik] 192.168.154.122 - - [04/Aug/2026:11:30:28 +0000] “POST /users-admin/xxxxx.xxxxx-online.com/api/login HTTP/2.0” 499 21 “-” “-” 110 “samba1-amld-https@file” “http://127.0.0.1:20000” 5007ms 2026-08-04T13:30:33+02:00 [1:samba1:samba-dc] Auth: [Kerberos KDC,ENC-TS Pre-authentication] user [(null)][Administrator@XXXXX.XXXXX-ONLINE.COM] at [Tue, 04 Aug 2026 11:30:33.884264 UTC] with [aes256-cts-hmac-sha1-96] status [NT_STATUS_OK] workstation [(null)] remote host [ipv4:192.168.154.1:41698] became [XXXXX-ONLINE[Administrator] [S-1-5-21-4040196191-2615639880-851222450-500]. local host [NULL] 2026-08-04T13:30:37+02:00 [1::qemu-ga] info: guest-ping called 2026-08-04T13:30:41+02:00 [1:ldapproxy1:ldapproxy] 2026/08/04 11:30:41 [info] 25#25: *9 client disconnected, bytes from/to client:1343/228090, bytes from/to upstream:228090/1343 2026-08-04T13:30:41+02:00 [1:samba1:api-moduled] [GIN] 2026/08/04 - 13:30:41 | 200 | 12.7s | 192.168.154.122 | POST “/api/login” 2026-08-04T13:30:42+02:00 [1::qemu-ga] info: guest-ping called

I guess it’s the same error as in the other thread. Is there also the LAM error again?

Here are logs of a working login:

2026-08-04T14:17:13+02:00 [1:ldapproxy1:ldapproxy] 2026/08/04 12:17:13 [info] 29#29: *23 client 127.0.0.1:50299 connected to 127.0.0.1:20002
2026-08-04T14:17:13+02:00 [1:ldapproxy1:ldapproxy] 2026/08/04 12:17:13 [info] 29#29: *23 proxy 192.168.3.148:36226 connected to 192.168.3.148:636
2026-08-04T14:17:13+02:00 [1:samba2:samba-dc] Auth: [LDAP,simple bind/TLS] user [NS8]\[ldapservice@ad.ns8-test.test] at [Tue, 04 Aug 2026 12:17:13.484655 UTC] with [Plaintext] status [NT_STATUS_OK] workstation [DC234] remote host [ipv4:192.168.3.148:36226] became [NS8]\[ldapservice] [S-1-5-21-4004702653-2937838001-2797294098-1103]. local host [ipv4:192.168.3.148:636]
2026-08-04T14:17:13+02:00 [1:samba2:samba-dc] Auth: [Kerberos KDC,ENC-TS Pre-authentication] user [(null)]\[Administrator@AD.NS8-TEST.TEST] at [Tue, 04 Aug 2026 12:17:13.670874 UTC] with [aes256-cts-hmac-sha1-96] status [NT_STATUS_OK] workstation [(null)] remote host [ipv4:192.168.3.148:40596] became [NS8]\[Administrator] [S-1-5-21-4004702653-2937838001-2797294098-500]. local host [NULL]
2026-08-04T14:17:13+02:00 [1:ldapproxy1:ldapproxy] 2026/08/04 12:17:13 [info] 29#29: *23 client disconnected, bytes from/to client:1293/227964, bytes from/to upstream:227964/1293
2026-08-04T14:17:13+02:00 [1:samba2:api-moduled] [GIN] 2026/08/04 - 14:17:13 | 200 |  713.5ms |   192.168.3.133 | POST     "/api/login"
2026-08-04T14:17:14+02:00 [1:ldapproxy1:ldapproxy] 2026/08/04 12:17:14 [info] 29#29: *27 client 127.0.0.1:55587 connected to 127.0.0.1:20002
2026-08-04T14:17:14+02:00 [1:ldapproxy1:ldapproxy] 2026/08/04 12:17:14 [info] 29#29: *29 client 127.0.0.1:58359 connected to 127.0.0.1:20002
2026-08-04T14:17:14+02:00 [1:ldapproxy1:ldapproxy] 2026/08/04 12:17:14 [info] 29#29: *27 proxy 192.168.3.148:36238 connected to 192.168.3.148:636
2026-08-04T14:17:14+02:00 [1:ldapproxy1:ldapproxy] 2026/08/04 12:17:14 [info] 29#29: *31 proxy 192.168.3.148:36250 connected to 192.168.3.148:636
2026-08-04T14:17:15+02:00 [1:ldapproxy1:ldapproxy] 2026/08/04 12:17:15 [info] 29#29: *31 client disconnected, bytes from/to client:1409/227341, bytes from/to upstream:227341/1409
2026-08-04T14:17:15+02:00 [1:ldapproxy1:ldapproxy] 2026/08/04 12:17:15 [info] 29#29: *27 client disconnected, bytes from/to client:1409/227341, bytes from/to upstream:227341/1409

Let’s check the network…

ip a

…and the Samba config:

api-cli run module/samba1/get-configuration | jq

It’s a fresh installation without any app. Only samba is installed.

Output of ip a:

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: enp6s18: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether bc:24:11:a8:4f:32 brd ff:ff:ff:ff:ff:ff
inet 192.168.154.1/24 brd 192.168.154.255 scope global noprefixroute enp6s18
valid_lft forever preferred_lft forever
inet6 fe80::be24:11ff:fea8:4f32/64 scope link noprefixroute
valid_lft forever preferred_lft forever
3: wg0: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000
link/none
inet 10.5.4.1/32 scope global wg0
valid_lft forever preferred_lft forever

Output of Samba config:

“configuration_required”: false,
“credentials_required”: false,
“realm”: “xxxxx.-online.com”,
“domain”: “ixxxxx.xxxxx-online.com”,
“nbalias”: “”,
“nbdomain”: “XXXXX-ONLINE”,
“ipaddress”: “192.168.154.1”,
“ipaddress_list”: [
{
“ipaddress”: “192.168.154.1”,
“label”: “enp6s18”
}
],
“ipaddress_alterable”: true,
“hostname”: “dc1”

Network and samba config looks good. I tested a similar setup and it worked.

Maybe try the curl command from the other thread to check the latency, adapt NS8FQDN,ad.xxx.com and PASSWORD to your setup.

curl -k -s -o /dev/null -w '%{http_code} %{time_total}\n' \
  -X POST https://NS8FQDN/users-admin/ad.xxx.com/api/login \
  -H 'Content-Type: application/json' \
  -d '{"username":"Administrator","password":"PASSWORD"}'

It should return something like

200 0.714507

000 4.898547

Status 000 means a timeout after about 5 seconds.
If you try the command again, Is there always a timeout?

Do the hostnames resolve to the NS8 LAN IP address? If they resolve to public IPs, the firewall may block the request…

nslookup NS8FQDN
nslookup ad.xxx.com

If nslookup isn’t available:

dnf install bind-utils

I think it’s ok…

Server: 192.168.154.254
Address: 192.168.154.254#53

Name: tdho-ns8node1.xxxxx-online.com
Address: 192.168.154.20

[root@tdho-ns8node1 ~]# nslookup ad.xxxxx-online.com
Server: 192.168.154.254
Address: 192.168.154.254#53

Name: ad.xxxxx-online.com
Address: 192.168.154.20

After trying the above command again, the timeout is back,

The DNS resolves to a wrong IP.

The NS8 has 192.168.154.1…

…but the DNS returns 192.168.154.20.

Sorry @mrmarkuz

I ran the tests on the NS8 from the other thread—the same one where I’m having problems with the user portal. The values match. I forgot to mention that.

OK, let’s test if the samba port is opened.

nmap -p 636 ad.xxx.com

If nmap is missing:

dnf install nmap

To remove nmap after testing:

dnf remove nmap

nmap -p 636 ad.xxxxx-online.com
Starting Nmap 7.92 ( https://nmap.org ) at 2026-08-04 17:32 CEST
Nmap scan report for ad.xxxxx-online.com (192.168.154.20)
Host is up (0.00011s latency).
rDNS record for 192.168.154.20: dc01.ad.xxxxx-online.com

PORT STATE SERVICE
636/tcp open ldapssl

Nmap done: 1 IP address (1 host up) scanned in 5.18 seconds

The nmap result looks good.

The default DC hostname is dc1 but in the nmap result it’s dc01. Could there be a wrong name in DNS?

As I mentioned earlier, I’m using the NS8 from the other thread. The output is correct.

I would have tried uninstalling the LAM app. But that doesn’t make sense, since the problem occurs on the freshly installed NS8 even without the LAM app.

I don’t think that LAM is the cause but it would be interesting if the LAM error also occurs on the fresh installed server.

Does it work when you use the IP instead of the NS8FQDN or does it time out too?

curl -k -s -o /dev/null -w '%{http_code} %{time_total}\n' \
  -X POST https://192.168.154.20/users-admin/ad.xxx.com/api/login \
  -H 'Content-Type: application/json' \
  -d '{"username":"Administrator","password":"PASSWORD"}'