I have a tunnel connected to my local computer to simulate as if it were production to see that everything works correctly, in this same computer I have installed the WARP service with Zero Trust to my organization, when I am connected to WARP the tunnel status is set to “degraded”, I read about this that some time ago was a temporary error by Cloudflare and it was already solved, but it still happens to me, is it normal or I have to do something?
I, too, have been experiencing this issue on my Mac when using tunnels over ZT WARP. From my testing it appears specific datacenters are inaccessible. I am entering my own issues in as a service ticket and will update you as I know more or if additional information is required.
The customer service ticket I created was not associated with a business/enterprise contract, and since it’s primary use case is for us developers it wasn’t urgent enough for me to push for it to receive attention on the weekend. I will however make sure that some movement comes today now that all teams are back.
Quick update, I have learned this appears to be a known issue and am looking to see what else can be done regarding this report. It seems to be related with WARP’s routing modifications.
The support request has been merged into an ongoing conversation and I have entered a vote on our behalf for resolution. I will keep monitoring the conversation and will notify you of changes or solutions that come from it.
I am experiencing the same but with a cloudflared deployment in kubernetes, everything seems to be working fine, however I am getting (degraded) state as it is shown in the image below.
I have reached out to you in a private chat requesting logs. Please share them with me so I can identify if your issues is in the scope of this thread.
My apologies the wait on this has been awhile, it can take sometime to discuss large routing topics like these that have broader implications.
While considerations are currently being made about official support for “Tunnel over WARP/Gateway” becoming a feature, I would recommend the workaround of adding the Tunnel IPs to your client’s split tunnel. To get a list of our Tunnel IPs, please follow this documentation:
Let me know if there is anything else I can help with, otherwise this will close out automatically in the coming days.