Theme
Troubleshooting
Work down from the symptom you actually have.
The Portal says my storage is not connected
Check, in this order:
- Is the service running?
sc-conn svc status, or the Windows Services console. - Does the dashboard say the uplink is up? Open
http://localhost:8883on the machine. - Does this Connector have a virtual file system? A Connector with nothing to serve never links, and the Portal shows it as Not seen yet. See Virtual file systems.
- Can the machine reach your site's server on TCP port 7600? It is outbound from your side, and nothing has to be opened inbound. System > Network in the Connector lists the exact hostname and port it dials, and says whether each one is connecting right now. If it says Not connecting there, the traffic is being blocked before it arrives. See Before you install.
- Is a re-enrollment needed? The dashboard says so plainly. See Enroll to your site.
Users sign in but every folder is empty or will not open
Almost always one of two things.
No grant on the Connector. The user exists, synced from the Portal, and nobody has given them access. Open them under Access, then Users, and check whether it says No access yet. See Permissions.
No mount in the Portal. The user has permission here, and their What they see list in the Portal does not place this virtual file system anywhere. See Users.
A user is missing from the Connector
Users sync from the Portal. If one is missing:
- Confirm they exist in the Portal, on the site this Connector is enrolled to.
- Check the uplink on the dashboard. A Connector that is not linked receives nothing.
- Check whether the Portal shows this Connector as needing re-enrollment.
Every session on a folder set is refused, but the link is up
Users authenticate, and then the session is dropped before a single folder opens. There are two causes with opposite fixes, and the dashboard names which one it is.
The clock on this machine is off. The dashboard says Clock is off and, when it could measure it, how far ahead or behind the machine is. The Portal's Storage page shows Your Connector's clock is off. The Connector refuses any session whose voucher looks more than five minutes old or more than five minutes in the future, so a machine whose clock has wandered past that refuses all of them.
Correct the system time and turn automatic time synchronization back on. That is the whole fix: nothing is re-enrolled or reinstalled, the notice clears at the next successful sign in, and the Connector does not need a restart. See Before you install.
The enrollment no longer matches your site. The dashboard says Re-enroll needed: the site's voucher key no longer matches this Connector's enrollment. It means your site was re-enrolled without re-enrolling this Connector. Re-enroll the Connector and service resumes. See Enroll to your site.
The dashboard says the certificate could not be renewed
The Connector presents a certificate to your site that lasts thirty days, and renews it by itself, over its connection to the Portal, from the halfway point. While a renewal is merely late nothing else changes: every link stays up and transfers keep working. The dashboard notice is the warning that this will stop.
| The notice says | What it means | What to do |
|---|---|---|
| It has not been able to renew its certificate, and when the certificate ends | The Connector cannot reach the Portal, and about a week is left | Allow this machine to reach portal.sftp.cloud on port 443. The Connector retries every hour and the notice clears by itself |
| The certificate has ended | The same, and the time has run out. Your site refuses the Connector the next time it reconnects | The same. It still renews by itself once it can reach the Portal; nothing has to be re-enrolled |
| The Portal did not accept the certificate | The Connector cannot renew by itself | Choose Re-enroll on the notice and paste a re-enrollment code from the Portal's Storage page |
| The storage was disconnected from your site | Someone disconnected this storage in the Portal | To use it again, choose Reset pairing and enroll with a new code. See Enroll to your site |
System > Network lists the exact Portal address and port. See Before you install.
An operation is denied and the user does not know why
Open Monitoring, then Activity, and filter by Denied only.
Users are never told why an operation was refused; the full reason is recorded there.
A move or rename fails between two folders
Moves never cross a virtual file system boundary, including between two on the same Connector. Clients fall back to copy and delete.
If the client does not fall back, copy and delete by hand. See Permissions.
Transfers are slow
Check where the bottleneck actually is:
- Connector to storage. Every byte crosses this link. A Connector in one cloud region reaching a bucket in another is the usual cause.
- Speed caps. Check the user's caps in the Portal, the site wide caps on Site settings, and, on a dedicated plan, the server ceilings on Site security. The strictest applicable value wins.
- Node health on the Connector dashboard, for CPU, memory and data volume pressure.
The admin console will not open
| Symptom | Cause |
|---|---|
Nothing answers on localhost:8883 | The service is not running, or the bind address was changed |
| Nothing answers from another machine | The default bind is loopback only. See Settings |
| Refused from your address | The IP allow list on Settings, Web server tab |
| A certificate warning | The self signed certificate. Expected on first contact |
If you changed the bind address and locked yourself out, fix it while the service is stopped:
sh
sudo sc-conn svc stop
sudo sc-conn config web --bindto 127.0.0.1:8883 --tls none
sudo sc-conn svc startI am locked out of the admin console
Use a recovery code in place of the six digit code.
If those are gone, another administrator on the same Connector can change your password and reset your second factor. If there is no other administrator, there is no supported way back in: these accounts are local and offline by design, and Syncplify cannot reach them.
Create a second administrator now, before you need it. See Administrators.
After a rebuild or a reinstall
The data directory is what matters.
| You kept it | You did not |
|---|---|
| Same identity, same virtual file systems, same permissions, same encryption keys, same enrollment | Enroll again, recreate everything, and any at rest encryption key is gone with it |
sc-setup uninstall keeps the data directory. --purge deletes it.
To enroll an installed Connector again after it was disconnected in the customer portal, do not uninstall: choose Reset pairing on its dashboard, or run sc-conn enroll reset --yes with the service stopped, then enroll it with a new code. The storage definitions and keys are kept. See Enroll to your site.
Where to look, in one table
| Question | Place |
|---|---|
| Is it running and linked? | The Connector dashboard |
| Why was a session refused, or why did something fail? | The Connector's log: the logs directory under the data directory, or wherever Settings, Logging points |
| Who did what to which file? | Connector Activity |
| Is the signed record intact? | Connector Log integrity |
| Who changed the account, the plan or a user? | Portal Activity |
| Is my storage reachable from the Portal's point of view? | Portal Storage |
| Was the platform down? | Portal Service level |