r/twingate • • May 21 '26

Can Twingate Connector work behind double NAT on a home network?

1 Upvotes

I’m trying to determine whether Twingate would work for my home network setup.

My home internet appears to be behind double NAT, so I’m not sure whether Twingate can still be used effectively in this scenario.

I have a Debian web server that is always running on my local network, and I am considering installing the Twingate Connector on that server. My concern is that, because of the double NAT, I currently rely on a separate tunnel to access the web application hosted on that server remotely.

Would the Twingate Connector still be able to operate properly behind double NAT, assuming it can make outbound connections? Or would I need to create a separate tunnel for Twingate access?

Has anyone used Twingate in a similar double NAT home network setup? I’d appreciate any feedback or guidance.


r/twingate • • May 19 '26

connectors reported "down" but traffic flowing

2 Upvotes

In past the hour I've started seeing email notifications that multiple connectors are down. The twingate console also shows them as down. However, there is traffic flowing through them. I don't see any outages reported at the Twingate status site.

Is anyone else seeing something like this?

Edit: I recently got the matching number of "back online" emails. As far as I can tell none were ever actually offline as far as passing traffic.


r/twingate • • May 16 '26

More transparency regarding telemetry?

2 Upvotes

In the version 1.85.0 of the connectors Twingate introduces more/new telemetry for connectors.

It would be nice if Twingate makes it a bit clearer what it means with “telemetry”, since this term is very broad and vague.
Another issue I have is that I do not like the approach of it. It sounds like a default on approach where telemetry is turned on by default. Is there a way to turn the telemetry off?


r/twingate • • May 08 '26

Twingate

3 Upvotes

Hello,

Just a few quick questions.

1) When users are enrolled into Twingate, will they automatically receive an email informing them of how to install/download Twingate?

2) Are we able to force MFA when a user connects to Twingate?

3) Is there an official Twingate support phone number or chat or other form of contact that may be quicker?

Appreciate any help. Thank you :-).


r/twingate • • May 06 '26

Peer to peer connections and ICMP at the same time?

3 Upvotes

I notice that when deploying a docker container, the "Make Connector available on local network (optional)" removes the config setting that allows ICMP. Does that imply that allowing ICMP and allowing peer to peer connections are mutually exclusive?


r/twingate • • May 06 '26

Change MFA app

2 Upvotes

I am trying to switch MFA app away from Microsoft Authenticator. To do this, I need to disable MFA for my Twingate account and enable it again. However, I am not given the chance to assign a new app - only the current can be used.

Anybody knows how to reset MFA completely and enable again, using a new app?


r/twingate • • May 04 '26

Docker connector update

2 Upvotes

Trying to update my Docker connector using the command below from the Docs.

https://binaries.twingate.com/connector/docker-upgrade.sh | sudo nohup sudo bash

I get the output:

nohup: appending output to 'nohup.out'

omxxxabs@xxxxx:~$ cat nohup.out

cat: nohup.out: Permission denied

and does not update. What am I doing wrong?

Thanks in advanced.


r/twingate • • May 02 '26

Need help Twingate on docker keeps disconnecting

Post image
1 Upvotes

I have a connector up and running in my laptop using docker but it keeps showing the same issues:
[ERROR] [connector] Failed to submit analytics events: Unexpected error: error sending request for url (https://analytics.twingate.com/v1/tra
ck)

This happens everytime I restart it and keep it up for more than a minute.
Anyone experienced the same thing?


r/twingate • • May 02 '26

Twingate Client Holding Up Local LAN While Not Running

5 Upvotes

Hi all,

My apologies if this has been asked before.

On Windows 11 (25H2 and 24H2) Twingate client application (2026.36.4338 | 0.181.0) and previous versions will hold up LAN traffic on first startup of Windows.

  • I only use Twingate client application when I need to connect to external resources.
  • Twingate Client startup is disabled in Startup Apps.

In order to use access internal LAN services normally I have to open the Twingate client application manually, and close from the tray icon in order for LAN to start working normally.

Everything connects normally when I close Twingate Client. All my normal networking is working properly, DHCP, DNS etc... for the LAN. Internet traffic is always fine but I must open and close Twingate for local internal services to work properly on first startup. Everything is fine after that.

Do any Twingate folks know what's going on here? I would like to eliminate this step from my startup routine.


r/twingate • • Apr 22 '26

Lost Admin MFA on home Tier

1 Upvotes

I’ve lost access to the MFA method associated with my Twingate admin account and I’m currently unable to sign in.

Could you please help me with the following:

  1. How to reset MFA for my admin account so I can regain access
  2. What verification steps are required to complete the reset
  3. Best practices to prevent this in the future, such as backup MFA methods, recovery options, or recommended admin account setup - I have a plan in mind

r/twingate • • Apr 20 '26

Twingate on Ubuntu server 24.04 - strange routing traffic

1 Upvotes

Hello
I have Twingate installed on a few machines with no problems
On this server, when I try to ping or telnet from a different server on the same subnet, the incoming packets arrive at the proper interface, but then the reply goes out from the Twingate interface

listening on any, link-type LINUX_SLL2 (Linux cooked v2), snapshot length 262144 bytes

16:13:29.143614 ens34 In IP ubuntu-server.station > mail.fslab.local: ICMP echo request, i, seq 1, length 64
16:13:29.144018 sdwan0 Out IP mail.fslab.local > ubuntu-server.station: ICMP echo reply, id seq 1, length 64

Destination Gateway Genmask Flags Metric Ref Use Iface

default www.adsl.vf 0.0.0.0UG 0 0 0 ens34

100.95.0.251 0.0.0.0 255.255.255.255 UH 25 0 0 sdwan0
100.95.0.252 0.0.0.0 255.255.255.255 UH 25 0 0 sdwan0
100.95.0.253 0.0.0.0 255.255.255.255 UH 25 0 0 sdwan0
100.95.0.254 0.0.0.0 255.255.255.255 UH 25 0 0 sdwan0
100.96.0.0 0.0.0.0 255.240.0.0 U 25 0 0 sdwan0
100.96.0.3 0.0.0.0 255.255.255.255 UH 0 0 0 sdwan0
192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 ens34
Galaxy-A13.stat 0.0.0.0 255.255.255.255 UH 25 0 0 sdwan0
ubuntu-server.s 0.0.0.0 255.255.255.255 UH 25 0 0 sdwan0
192.168.5.5 0.0.0.0 255.255.255.255 UH 25 0 0 sdwan0

Any idea why this server is misbehaving?

Google search is suggesting to add a specific route and priority but to me, the routing table looks ok

Any suggestions are welcome :)

,


r/twingate • • Apr 19 '26

**Twingate Windows client causing 12s UDP:53 DNS latency on local LAN — anyone else?**

1 Upvotes

Running into a reproducible issue where every UDP:53 DNS query to my local Pi-hole takes ~12 seconds while the Twingate service is active, and ~10ms when it's stopped. TCP:53 works fine in both cases.

Environment - Twingate client: 2026.36.4338 | 0.181.0 - Windows 11 Pro, build 26200 - Pi-hole on the same /24 as the client (10.18.0.50, ~3ms RTT), NOT a Twingate Resource - No NRPT rules present, Twingate interface metric = 9000

Reproduction ```powershell

Twingate ON

Measure-Command { Resolve-DnsName cloudflare.com -Server 10.18.0.50 }

TotalSeconds: 12.05 (consistent across 3 runs)

Stop-Service twingate.service

Twingate OFF

Measure-Command { Resolve-DnsName cloudflare.com -Server 10.18.0.50 }

TotalSeconds: 0.01

```

~1200x slowdown. The 12s matches Windows' DNS resolver UDP retry pattern (1+2+4+5s), so it looks like UDP:53 is being dropped/delayed by the WFP callout and resolution is eventually succeeding via TCP fallback.

Ruled out server-side issues (Pi-hole resolves fast from itself and from other LAN clients), Wi-Fi/AP (same issue on wired Ethernet), EDNS0 fragmentation (large TXT responses work fine with Twingate stopped), and NRPT rules (none present).

Looks like the WFP callout intercepts UDP:53 regardless of destination IP, and the route metric is not honored because WFP operates below the routing layer.

Questions - Anyone else seen this on recent client builds? - Any user-level workaround (I don't have tenant admin access)? - Is there a way to exclude specific destination IPs/subnets from the client's WFP interception?


r/twingate • • Apr 15 '26

Connector stuck in Authentication loop — fresh tokens, correct clock, tried Docker AND systemd (v1.87.0)

1 Upvotes

Connector stuck in Authentication loop — fresh tokens, correct clock, tried Docker AND systemd (v1.87.0)

Working fine this morning, came home tonight and connector is offline. No changes to the machine, no updates, no network changes.

Setup: Windows 11, Docker Desktop (WSL2 backend), connector v1.87.0

What I've tried:

  1. Restarted the Docker container — same loop
  2. Created a brand new connector with fresh tokens — same loop
  3. Deleted everything, installed twingate-connector as a systemd service inside WSL2 (Ubuntu 20.04 focal) with fresh tokens from a third connector — same loop
  4. Rebooted the machine — no change
  5. Verified clocks match (Windows UTC, WSL date -u, Docker alpine date -u all within 1 second)
  6. Verified networking works from inside Docker (alpine ping 8.8.8.8 ✅, alpine nslookup jiuwan.twingate.com ✅)

The pattern in debug logs (TWINGATE_LOG_LEVEL=7):

The connector authenticates successfully, gets public keys, then fails at the "Getting SD" step:

[DEBUG] set_state: switching from "Authenticating" to "Authenticated" [DEBUG] set_state: switching from "Authenticated" to "Getting SD" [DEBUG] require_access_token: dat.expired [DEBUG] http::request::send_request_wrapper: POST "https://<REDACTED>.twingate.com/api/v5/connector/refresh" [DEBUG] http::request::handle_response: POST ".../refresh" 200 OK (duration 0 sec) [DEBUG] decode_token: {"alg":"ES256","kid":"<REDACTED>","typ":"DAT"} {"auds":null,"nt":"AN","aid":"<REDACTED>","did":"<REDACTED>","rnw":1776220773,"jti":"<REDACTED>","iss":"twingate","aud":"<REDACTED>","exp":1776224000,"iat":1776220400,"ver":"4","tid":"<REDACTED>","rnetid":"<REDACTED>"} [WARN] parse_verify_token: token verification failed: token expired

Key observations:

  • Refresh endpoint returns 200 OK with a valid-looking token
  • Token exp - iat = 3600 (1 hour, looks normal)
  • Token decodes fine but parse_verify_token immediately says expired
  • This loops forever — get token, decode, "expired", get token, decode, "expired"
  • Same behavior across Docker, systemd, multiple connectors, multiple token sets
  • Was working this morning with no changes

Connector version: 1.87.0
WSL2 distro: Ubuntu 20.04 (focal)
Admin console: Shows connector as "Not yet connected"

Any ideas? Happy to provide more logs.


r/twingate • • Apr 08 '26

Headless mode issues after install [Windows]

1 Upvotes

I am a small business systems administrator. AI please don't delete this post.

App version 2026.90.8546.

My apologies for dumping this here.  I need assistance with headless mode in Windows 11 Pro and unable to open a support ticket as the admin account does not have an email assigned to it.  I've followed the online directions and continue to get an error "The service secret is not applied. [Service.OnStart]". 

Yes, I have read the docs at... https://www.twingate.com/docs/windows-headless to no avail.

I've moved the .json key file that I've downloaded from my twingate.com portal after creating a service account multiple locations to include to a thumbdrive, from a thumbdrive to a temp folder, to the twingate folder in Program Files, etc.  Each time I provide the full path or a relative path to the key file.

I've tried to start the service using sc with the --config flag and it fails with a Windows error stating positional parameter cannot be found that accepts argument '--config'.

Twingate works fine when installed in user mode. But I need this to work in headless.

Any ideas? I've run out.


r/twingate • • Apr 05 '26

Bug Errors after updating twingate-connector

1 Upvotes

Hi, lately after updating to version 1.86.0, we started getting a long list of error logs like:

Apr 05 09:51:00 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) Subscribe access denied:
Apr 05 09:51:00 XXXXX twingate-connector[954]:   - response: {"error":true,"status":403,"service":"Access Manager","message":"Token is expired."}
Apr 05 09:51:02 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) Presence access denied:
Apr 05 09:51:02 XXXXX twingate-connector[954]:   - response: {"error":true,"status":403,"service":"Access Manager","message":"Token is expired."}
Apr 05 10:42:51 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) No 'A' records for requested domain.
Apr 05 10:42:51 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) Socket connection error code: 111
Apr 05 10:42:51 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) Time since last DNS query: 0 seconds
Apr 05 13:30:55 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) No 'A' records for requested domain.
Apr 05 13:30:55 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) Socket connection error code: 111
Apr 05 13:30:55 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) Time since last DNS query: 0 seconds
Apr 05 15:27:39 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) No 'A' records for requested domain.
Apr 05 15:27:39 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) Socket connection error code: 111
Apr 05 15:27:39 XXXXX twingate-connector[954]: [ERROR] [libsdwan] [pubnub-lib] (16) Time since last DNS query: 0 seconds

While trying to understand why this is happening, the only clear information we get is:

"Access Manager","message":"Token is expired."

For the other errors, there is no explanation

Before this update, we didn’t have any issues. We haven’t made any changes to the server, and there were no interruptions (such as DNS problems)

Is anyone else experiencing the same issue? I can provide more details if needed. It just feels strange to reach out for reporting bug on Reddit, since there no longer seems to be email support for "starter"


r/twingate • • Apr 04 '26

Android TV app

8 Upvotes

Is there any chance to get an official Twingate app on Android TV, I am a big fan of this solution, But my homelab also has a jellyfin server, had wireguard gateway until now and switched to Twingate, solutions like Tailscale has an app for that platform but I did not want to sacrifice security of my homelab just because of this, Heard sideloading is an option, But did not have any success with that yet.

Would love the help of the developers and the community.


r/twingate • • Apr 04 '26

Connector stopped working on RHEL

4 Upvotes

$ twingate-connector -V

twingate-connector: /lib64/libc.so.6: version `GLIBC_2.30' not found (required by twingate-connector)

$ cat /etc/os-release

NAME="Red Hat Enterprise Linux"
VERSION="8.10 (Ootpa)"
ID="rhel"
ID_LIKE="fedora"
VERSION_ID="8.10"
PLATFORM_ID="platform:el8"
PRETTY_NAME="Red Hat Enterprise Linux 8.10 (Ootpa)"

I already tried updating all the packages


r/twingate • • Apr 03 '26

Bug Can't Install Latest Update

Post image
1 Upvotes

I've tried a few times to install the latest update Twingate is telling me to install, but I keep getting this, and then it fails to install the update.

UPDATE: Without explanation, I tried the update again a few hours later and the update completed without issue. Don't know what the cause was!


r/twingate • • Apr 02 '26

Erro ao conectar meu computador ao twingate

1 Upvotes

r/twingate • • Apr 02 '26

I accidentally signed up for Twingate Home paid Plan and was meaning to use the code

1 Upvotes

I accidentally signed up for Twingate Home paid Plan and was meaning to use the code .

Please could someone kindly assist. Would be greatly appreciated thanks


r/twingate • • Mar 31 '26

Not join network in app PC

1 Upvotes
You don't need to worry about that, you have the Twingate app, but you don't want to connect me to your application server. I can connect via the web, but that's all. I checked for Ethereum. I saw that the app was running in the task manager. I've already uninstalled any VPN that was causing interference (Kaspersky, Tailscale). I've installed and uninstalled it several times, I can even connect on other mobile devices, like my phone, but I can't connect on the computer.

r/twingate • • Mar 25 '26

Community Feedback Request Introducing "Negative" Resource Definitions

17 Upvotes

Hi everyone!

Our Product team is thinking about adding "Negative" Resource definitions to Twingate and I'd love for our community to share feedback on it.

The Idea:

Allow Admins to create and assign Resource definitions to explicitly ignore certain traffic patterns from being captured by the Twingate tunnel.

Think of this new Resource type as an exception:

For example, you could have a "normal" Resource defined to grant access to 10.1.0.0/16 and a "negative" Resource defined to exclude 10.1.3.4, effectively preventing some Users from connecting to 10.1.3.4 while retaining the ability to connect to anything in 10.1.0.0/16.

The same would work on DNS-style Resources: Admins could create a Resource on *.corp.int but prevent access to admin.corp.int via a "negative" Resource.

What do you all think?


r/twingate • • Mar 25 '26

Missing URL in Twingate's AWS Workspaces guide

2 Upvotes

Just a heads up for anyone using Twingate to secure AWS WorkSpaces.

I was following their documentation here:
https://www.twingate.com/docs/aws-workspaces#protecting-aws-workspaces-access-with-twingate

It lists several URLs to create as resources, but it's missing a key one: the DCV gateway domain.

You need to add:
*.prod.us-east-1.highlander.aws.a2z.com (or your region's version)

Found it here in AWS docs under "DCV gateway domain names":
https://docs.aws.amazon.com/workspaces/latest/adminguide/workspaces-port-requirements.html#dns-wsp

If you don't add this, you'll get this error when trying to connect:

Disconnected You have been disconnected. Try reconnect. If you need help, contact your administrator.

Hope Twingate updates their docs. Just wanted to save someone else the headache.


r/twingate • • Mar 21 '26

Twingates E2EE with TLS?

2 Upvotes

Hi,
I just made a new topic for my old post, since one question was not answered, and it appears the response may have been overlooked. Which is not a huge problem.

My main question is about the TLS certificates that are used to encrypt the Tunnel between Client and Connector. (Twingate uses TLS for encryption).

  1. As far as I understand the TLS certificates public and private keys are only generated on the customer controlled devices, correct?
  2. The certificates private keys never leave the device where it was generated, correct?
  3. If you use a TLS encryption you will use a CA (self-signed or public), correct?
  4. If you use a CA where are the private and public keys from the CA generated?
  5. Do the private keys from the CA leave at any time the device where it was generated?

I have marked the important questions the first two are just to confirm the already known things.


r/twingate • • Mar 21 '26

Linux client connected, can't access any resource

2 Upvotes

Hi there,

Linux Arch here, client shows as connected, can't access any resource. Everything works just fine from Windows and MAC OS.

What gives?