When a test can't reach an application over mabl Link, the fastest way to find out why is to test the tunnel directly. The mabl Desktop App and the mabl CLI can both reach through a Link tunnel from your computer and check whether its agents can reach a host, open a port, answer an HTTP request, and move data at the speed you expect. This article explains how to run those checks and how to read the results.
Before you start
To test a Link connection, you must have the correct access in the tunnel's Link tunnel access settings.
- For workspace tunnels, a workspace owner goes to Settings > Networking, opens Link tunnel access, and adds the role under Team access > Roles allowed to access Link tunnels.
- For company tunnels, an account admin makes the same change on the Networking page of the account dashboard.
See Controlling access to Link tunnels for more details.
The role setting applies whenever you're signed in as yourself, in the Desktop App or with mabl auth login in the CLI. If you activate an API key in the CLI instead, you can test the workspace's tunnels without a role setting.
The tunnel must also have at least one connected Link Agent running version 3.0 or later.
Run checks from the mabl Desktop App
- From the mabl app menu bar, go to Edit > Link tunnels
- In the Diagnostics tab, choose a tunnel from the Tunnel list, which includes the tunnels in every workspace and company you belong to. The Overview shows the tunnel's connected agents, health, and updates, the agents that serve it, and the environments that route through it.
- Under Check, choose a check, and enter its target under Parameters. See Checks below.
- Choose a Scope:
- Any agent: the tunnel picks an agent for each connection, the same way your tests route. Start here.
- Specific agent: test one agent directly, to look into behavior that only one agent shows.
- Every agent: run the check once per agent and compare the results, to find differences between agents.
- Click Run check. The outcome appears on the Results tab.
The checks run from your computer through the tunnel, so they test the same path your cloud tests take to reach your network.
Checks
| Check | The question it answers | Target |
|---|---|---|
| Reachability | Can my agents reach a host inside the network? | A host and port inside your network, such as app.internal:443
|
| TCP connect | Can the tunnel open a connection to this port? | A host and port, such as db.internal:5432
|
| HTTP request | What does this internal endpoint actually answer? | A URL. Optionally Follow redirects or Allow insecure TLS. |
| Ping / RTT | How far is the round trip, and is anything dropping? | The number of pings to send. The default is 10. |
| Speed test | How much throughput does the tunnel path have? | Download, upload, and a duration in seconds. The default is 60. |
Reading the results
Each result shows which agent served the check, and details such as name resolution, connect time, and the response. A result is one of:
- Pass: the check succeeded.
- Fail: the check failed. The details show where, for example the name didn't resolve or the connection was refused.
- Degraded: the check succeeded, but slower or with more loss than expected.
- Cancelled: you stopped the check before it finished.
- Unknown: the agent can't run this check. An agent that hasn't been updated yet may not offer the check. Updating the agent enables it.
When you run a check on Every agent, compare the rows. If one agent fails where the others pass, the problem is on that agent's host or network, not in the application.
If you see You do not have access to this tunnel, your role isn't allowed. The message says where a workspace owner or account admin can add it. See Controlling access to Link tunnels.
Run checks from the mabl CLI
The mabl link-agents test commands run the same kinds of checks from a terminal, which is useful on a machine without the Desktop App or in a script. Every command takes --tunnel {name} and exits with a non-zero status when the check fails.
| Command | What it checks |
|---|---|
mabl link-agents test tcp {host:port} |
Opens a TCP connection to the target through the tunnel and reports how long it took. |
mabl link-agents test url {url} |
Makes an HTTP request through the tunnel and shows the response, like a small version of curl. |
mabl link-agents test destination {host:port} |
Asks every agent on the tunnel to resolve and connect to the target, and compares their results. |
mabl link-agents test ping |
Measures the round-trip time between your computer and the tunnel's agent. |
mabl link-agents test speed |
Measures round-trip time and download and upload throughput through the tunnel. |
For example:
mabl link-agents test tcp db.internal:5432 --tunnel qa-env-01
mabl link-agents test url https://app.internal/health --tunnel qa-env-01 -L
mabl link-agents test destination app.internal:443 --tunnel qa-env-01
Choose the tunnel and agent
| Option | Description |
|---|---|
--tunnel {name} |
The tunnel to test. Required. |
--workspace-id, -w
|
The workspace whose tunnel to test. Defaults to your configured workspace, and also finds your company's tunnels. |
--company-id |
Test a company tunnel. |
--personal |
Test your own personal tunnel. --tunnel names the computer. Requires mabl auth login. |
--agent {id} |
For tcp and url: test one agent directly instead of letting the tunnel pick. |
--all-agents |
For tcp and url: run the check once per connected agent. |
--output json |
Print the result as JSON, for scripts. |
Options for each check
-
tcp:--connect-timeoutin milliseconds. The default is 10,000. -
url: curl-style options:-Xfor the method,-Hfor a header (repeatable),-dfor a request body,-u user:passwordfor basic authentication,-kto skip certificate verification,-Lto follow redirects,-ito include response headers,-fto fail on a status of 400 or higher, and--max-timein milliseconds. -
destination:--connect-timeoutper agent, in milliseconds. The default is 5,000. -
ping:--countof pings, default 5, and--timeoutper ping in milliseconds. -
speed:--ping,--download, or--uploadto run only one test (all three run by default), and--durationof each throughput test in seconds, default 60.
Find a DNS mismatch between agents
Each Link Agent resolves host names with its own host's DNS. If the agents on one tunnel run in different networks, they can resolve the same name to different addresses, so a test passes or fails depending on which agent it reaches. mabl link-agents test destination shows the address each agent resolved, and warns when they don't agree.