WARP client to use private dns over the tunnel

The article " Private DNS" says to use QUIC protocol.
However, when we change it to QUIC the tunnel doesn’t come up anymore.Preformatted text

I’d like to add the error we are seeing in the logs of cloudflared. see below

{“level”:“error”,“event”:0,“ip”:“198.41.192.227”,“connIndex”:0,“error”:“failed to dial to edge with quic: CRYPTO_ERROR 0x178 (remote): tls: no application protocol”,“time”:“2023-11-22T22:00:07Z”,“message”:“Failed to create new quic connection”}

Are we missing some sort of config here?

1 Like

Tunnel ID if this healps
43ca06cf-8f14-4c44-bade-1a6c1e6bbb21

Similar issue here, in my case the outbound QUIC connection from cloudflared to the Cloudflare edge can’t be established because “CRYPTO_ERROR 0x178 (remote): tls: no application” (see full logs below). I’ve been going back and forth with the team managing the fortigate firewall in front of the VM running cloudflared but they assure me that they don’t see anything blocked and QUIC over UDP/7488 is allowed.

Not sure if it’s relevant but I’m also getting a warning about post-quantum even when I’ve explicitly disabled it (and I understand it is disabled by default anyway).

Any ideas on how I can get closer to the root of this?

My full logs are:

Dec 19 14:04:08 localhost systemd[1]: Starting cloudflared...
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF Starting tunnel tunnelID=9f39ac42-cc30-4577-a1e2-45d58926f698
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF Version 2023.10.0
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF GOOS: linux, GOVersion: go1.20.6, GoArch: amd64
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF Settings: map[no-autoupdate:true post-quantum:false pq:false token:*****]
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF Generated Connector ID: 0fd430f5-c9ca-46d2-ac66-3a94cf12a555
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF cloudflared will not automatically update if installed by a package manager.
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF Initial protocol quic
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF ICMP proxy will use 10.0.5.63 as source for IPv4
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF ICMP proxy will use fe80::250:56ff:feb7:4271 in zone ens192 as source for IPv6
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF Starting metrics server on 127.0.0.1:32853/metrics
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF
Dec 19 14:04:08 localhost cloudflared[79181]: ===================================================================================
Dec 19 14:04:08 localhost cloudflared[79181]: You are hitting an error while using the experimental post-quantum tunnels feature.
Dec 19 14:04:08 localhost cloudflared[79181]: Please check:
Dec 19 14:04:08 localhost cloudflared[79181]:    https://pqtunnels.cloudflareresearch.com
Dec 19 14:04:08 localhost cloudflared[79181]: for known problems.
Dec 19 14:04:08 localhost cloudflared[79181]: ===================================================================================
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z ERR Failed to create new quic connection error="failed to dial to edge with quic: CRYPTO_ERROR 0x178 (remote): tls: no application protocol" connIndex=0 event=0 ip=198.41.192.27
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF Retrying connection in up to 2s connIndex=0 event=0 ip=198.41.192.27
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z ERR Failed to create new quic connection error="failed to dial to edge with quic: CRYPTO_ERROR 0x178 (remote): tls: no application protocol" connIndex=0 event=0 ip=198.41.192.57
Dec 19 14:04:08 localhost cloudflared[79181]: 2023-12-19T13:04:08Z INF Retrying connection in up to 4s connIndex=0 event=0 ip=198.41.192.57
Dec 19 14:04:10 localhost cloudflared[79181]: 2023-12-19T13:04:10Z ERR Failed to create new quic connection error="failed to dial to edge with quic: CRYPTO_ERROR 0x178 (remote): tls: no application protocol" connIndex=0 event=0 ip=198.41.192.67
Dec 19 14:04:10 localhost cloudflared[79181]: 2023-12-19T13:04:10Z INF Retrying connection in up to 8s connIndex=0 event=0 ip=198.41.192.67
Dec 19 14:04:18 localhost cloudflared[79181]: 2023-12-19T13:04:18Z ERR Failed to create new quic connection error="failed to dial to edge with quic: CRYPTO_ERROR 0x178 (remote): tls: no application protocol" connIndex=0 event=0 ip=198.41.200.63
Dec 19 14:04:18 localhost cloudflared[79181]: 2023-12-19T13:04:18Z INF Retrying connection in up to 16s connIndex=0 event=0 ip=198.41.200.63
Dec 19 14:04:28 localhost cloudflared[79181]: 2023-12-19T13:04:28Z ERR Failed to create new quic connection error="failed to dial to edge with quic: CRYPTO_ERROR 0x178 (remote): tls: no application protocol" connIndex=0 event=0 ip=198.41.200.13
Dec 19 14:04:28 localhost cloudflared[79181]: 2023-12-19T13:04:28Z INF Retrying connection in up to 32s connIndex=0 event=0 ip=198.41.200.13
Dec 19 14:04:35 localhost cloudflared[79181]: 2023-12-19T13:04:35Z ERR Failed to create new quic connection error="failed to dial to edge with quic: CRYPTO_ERROR 0x178 (remote): tls: no application protocol" connIndex=0 event=0 ip=198.41.192.57
Dec 19 14:04:35 localhost cloudflared[79181]: 2023-12-19T13:04:35Z INF Retrying connection in up to 1m4s connIndex=0 event=0 ip=198.41.192.57
Dec 19 14:05:06 localhost cloudflared[79181]: 2023-12-19T13:05:06Z INF
Dec 19 14:05:06 localhost cloudflared[79181]: ===================================================================================
Dec 19 14:05:06 localhost cloudflared[79181]: You are hitting an error while using the experimental post-quantum tunnels feature.
Dec 19 14:05:06 localhost cloudflared[79181]: Please check:
Dec 19 14:05:06 localhost cloudflared[79181]:    https://pqtunnels.cloudflareresearch.com
Dec 19 14:05:06 localhost cloudflared[79181]: for known problems.
Dec 19 14:05:06 localhost cloudflared[79181]: ===================================================================================
Dec 19 14:05:06 localhost cloudflared[79181]: 2023-12-19T13:05:06Z ERR Failed to create new quic connection error="failed to dial to edge with quic: CRYPTO_ERROR 0x178 (remote): tls: no application protocol" connIndex=0 event=0 ip=198.41.192.107
Dec 19 14:05:06 localhost cloudflared[79181]: 2023-12-19T13:05:06Z INF Retrying connection in up to 1m4s connIndex=0 event=0 ip=198.41.192.107
Dec 19 14:05:23 localhost cloudflared[79181]: 2023-12-19T13:05:23Z ERR Failed to create new quic connection error="failed to dial to edge with quic: CRYPTO_ERROR 0x178 (remote): tls: no application protocol" connIndex=0 event=0 ip=198.41.200.33
Dec 19 14:05:23 localhost cloudflared[79181]: 2023-12-19T13:05:23Z INF Retrying connection in up to 1m4s connIndex=0 event=0 ip=198.41.200.33
Dec 19 14:05:29 localhost cloudflared[79181]: 2023-12-19T13:05:29Z ERR Failed to create new quic connection error="failed to dial to edge with quic: CRYPTO_ERROR 0x178 (remote): tls: no application protocol" connIndex=0 event=0 ip=198.41.200.23
Dec 19 14:05:29 localhost cloudflared[79181]: 2023-12-19T13:05:29Z INF Retrying connection in up to 1m4s connIndex=0 event=0 ip=198.41.200.23
Dec 19 14:05:52 localhost cloudflared[79181]: 2023-12-19T13:05:52Z INF Switching to fallback protocol http2 connIndex=0 event=0 ip=198.41.200.23
Dec 19 14:05:52 localhost cloudflared[79181]: 2023-12-19T13:05:52Z INF Registered tunnel connection connIndex=0 connection=0ff7a23e-021c-449d-986e-856554e07815 event=0 ip=198.41.200.63 location=vie05 protocol=http2
Dec 19 14:05:52 localhost systemd[1]: Started cloudflared.
Dec 19 14:05:53 localhost cloudflared[79181]: 2023-12-19T13:05:53Z INF Registered tunnel connection connIndex=1 connection=66859ae6-adfe-470f-b1dc-73f746b2925a event=0 ip=198.41.192.227 location=bud01 protocol=http2
Dec 19 14:05:54 localhost cloudflared[79181]: 2023-12-19T13:05:54Z INF Registered tunnel connection connIndex=2 connection=1bea15a2-993b-4850-adbb-49a0fc73f479 event=0 ip=198.41.200.193 location=vie05 protocol=http2
Dec 19 14:05:54 localhost cloudflared[79181]: 2023-12-19T13:05:54Z INF Updated to new configuration config="{\"warp-routing\":{\"enabled\":true}}" version=3
Dec 19 14:05:55 localhost cloudflared[79181]: 2023-12-19T13:05:55Z INF Registered tunnel connection connIndex=3 connection=9c684266-04f7-45b8-92c3-a221ee795465 event=0 ip=198.41.192.57 location=bud01 protocol=http2