Troubleshooting

Connection troubleshooting

Recover missing resources, claims, heartbeat, protocol readiness, assignment, policy, and closure signals safely.

Page type: TroubleshootingConnection troubleshootingStatus: CurrentCurrent product behaviorLast reviewed: 2026-07-26

Find the symptom that matches the failed connection. Use the resource identity, workspace, and last visible state from the panel. Do not put passwords, tokens, or private connection values into a support record.

Resource is missing

Check
Agent/gateway online state and workspace.
Success signal
The connection path is ready and the resource appears as pending or managed.

Claim is pending

Check
Pending Claims and workspace.
Success signal
Lock & Claim completes on the correct record.

Heartbeat is stale

Check
Last heartbeat, Agent service, and outbound reachability.
Success signal
A new heartbeat and current ready state appear.

Protocol is not ready

Check
RDP, SSH, VNC, or Kubernetes fields and the target service.
Success signal
Portal readiness is current while target details remain protected.

Assignment is missing

Check
Person, resource, duration, and session policy.
Success signal
A valid assignment is visible and a new access decision can be created.

Policy blocks launch

Check
Duration, workspace, and session restrictions.
Success signal
An authorized decision updates the state or records the expected block.

Active session conflicts

Check
Active session and closure state.
Success signal
Existing work closes before a new session opens.

Closure is missing

Check
Gateway/Agent last event and session state.
Success signal
The closure event appears; delayed state is reviewed before another attempt.

Gateway is offline

Check
Gateway or private-network node state.
Success signal
The gateway returns to ready and resource reachability updates.

Agentless target is unreachable

Check
Gateway/private-network path, target service, firewall or allowlist, and deployment owner.
Success signal
The gateway and target are reachable; then resource readiness and the session decision can be evaluated again.

Safe diagnostics

On the Windows Agent host, verify the installed version, service state, last heartbeat, and outbound reachability with local administration tools.

  1. Open PowerShell as an administrator.
  2. Run Get-Service -Name CerberusAgent and read the state of CERBERUS Windows Agent.
  3. Compare the local result with the same resource’s last heartbeat, version, and ready state in the panel.
  4. If the service is running while heartbeat stays stale, check HTTPS egress and the organization’s proxy or firewall policy.

Add the service state, Agent version, last heartbeat time, resource identity, session identity, and visible failure state to the support record. Keep credentials, tokens, private keys, raw connection values, and real user data out of the record.

If the issue remains, follow Connect a machine, Agentless access, and Revocation and evidence.