unable to monitor proxmox with https via zabbix proxy.

rahul.kamble

New Member
May 25, 2024
5
0
1
>i have a pve node which i am trying to monitor via zabbix-proxy (reference - https://www.zabbix.com/integrations/proxmox)
>Without proxy i can monitor pve and all guest vms.
>with proxy I see below error on zabbix-proxy logs-



Code:
 5224:20250525:234920.692 Proxmox API failed: 172.16.0.10 Error: Error: cannot get URL: Couldn't connect to server.
  5222:20250525:235420.918 Proxmox API failed: 172.16.0.10 Error: Error: cannot get URL: Couldn't connect to server.
  5224:20250525:235920.160 Proxmox API failed: 172.16.0.10 Error: Error: cannot get URL: Couldn't connect to server.

[root@zabbix-prxy ~]# curl -v -k https://<ip>:8006/api2/json
*   Trying <IP>:8006...
* Connected to <ip> (<ip>) port 8006 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
*  CAfile: /etc/pki/tls/certs/ca-bundle.crt
* TLSv1.0 (OUT), TLS header, Certificate Status (22):
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.2 (IN), TLS header, Certificate Status (22):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS header, Finished (20):
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.2 (OUT), TLS header, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.2 (OUT), TLS header, Unknown (23):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384
* ALPN, server did not agree to a protocol
* Server certificate:
*  subject: OU=PVE Cluster Node; O=Proxmox Virtual Environment; CN=pve-10.local
*  start date: Mar 18 11:55:39 2025 GMT
*  expire date: Mar 18 11:55:39 2027 GMT
*  issuer: CN=Proxmox Virtual Environment; OU=fdd2c3a7-6f47-4da3-ad12-7549d1c4663b; O=PVE Cluster Manager CA
*  SSL certificate verify result: unable to get local issuer certificate (20), continuing anyway.
* TLSv1.2 (OUT), TLS header, Unknown (23):
> GET /api2/json HTTP/1.1
> Host: <ip>:8006
> User-Agent: curl/7.76.1
> Accept: */*
>
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* old SSL session ID is stale, removing
* TLSv1.2 (IN), TLS header, Unknown (23):
* Mark bundle as not supporting multiuse
< HTTP/1.1 401 No ticket
< Cache-Control: max-age=0
< Connection: close
< Date: Mon, 26 May 2025 04:39:25 GMT
< Pragma: no-cache
< Server: pve-api-daemon/3.0
< Expires: Mon, 26 May 2025 04:39:25 GMT
<
* Closing connection 0
* TLSv1.2 (OUT), TLS header, Unknown (23):
* TLSv1.3 (OUT), TLS alert, close notify (256):
[/CODE]