使用Flask与Ngrok时发送认证请求失败,求排查解决
问题:Ngrok TLS连接错误导致无法转发Flask Webhook服务
我编写了一段测试Webhook监听器的Flask代码,运行正常,但执行ngrok http 4242时会话一直处于「reconnecting (failed to send authentication request: session closed)」状态。运行ngrok diagnose后检测到TLS相关错误(NGROK_ERR_8001、NGROK_ERR_8003),具体信息如下:
Flask测试代码
from flask import Flask, request, Response app = Flask(__name__) @app.route('/', methods=['POST','GET']) def return_response(): print(request.json); return Response(status=200) @app.route('/webhook', methods=['POST']) def response(): print(request.json); return Response(status=200) if __name__ == "__main__": app.run(debug=True, port=4242, host='10.1.10.112')
Ngrok错误输出
ngrok (Ctrl+C to quit) Session Status reconnecting (failed to send authentication request: session closed) Version 3.3.0 Latency - Web Interface http://127.0.0.1:4040 Connections ttl opn rt1 rt5 p50 p90 0 0 0.00 0.00 0.00 0.00
Ngrok诊断输出
Testing ngrok connectivity...
Internet Connectivity Name Resolution [ OK ] TCP [ OK ] TLS [ WARN ]
Errors and warnings encountered during diagnostics:
- Diagnostics * Connectivity
- Err: Failed to establish internet connectivity: could not establish any TLS connections (NGROK_ERR_8001)
- google.com (142.250.207.78:443)
- Err: Failed to establish TLS connection to 142.250.207.78 with error: context deadline exceeded. Possible Man-in-the Middle. (NGROK_ERR_8003)
- google.com (142.250.66.78:443)
- Err: Failed to establish TLS connection to 142.250.66.78 with error: dial tcp 142.250.66.78:443: i/o timeout. Possible Man-in-the Middle. (NGROK_ERR_8003)
- google.com (142.250.66.46:443)
- Err: Failed to establish TLS connection to 142.250.66.46 with error: dial tcp 142.250.66.46:443: i/o timeout. Possible Man-in-the Middle. (NGROK_ERR_8003)
Error establishing ngrok connection: Failed to establish internet connectivity: could not establish any TLS connections (NGROK_ERR_8001)
Report written to /tmp/ngrok-diagnose3756442921/diagnose.json
排查原因与解决办法
原因分析
这些错误本质是TLS连接无法正常建立,常见触发因素:
- 网络环境存在代理、防火墙或VPN拦截了TLS流量
- 本地网络DNS解析正常,但TCP握手超时,可能是运营商限制或路由问题
- 系统存在恶意软件或中间人攻击(MITM)篡改TLS连接
解决步骤
- 检查网络环境:关闭VPN、代理工具,暂时禁用防火墙(仅测试用,测试后恢复),重新运行
ngrok http 4242 - 切换网络:尝试连接手机热点,排除本地局域网或运营商的限制
- 更新ngrok版本:当前使用的是3.3.0,替换为最新稳定版,旧版本可能存在兼容性问题
- 检查系统证书:确认本地根证书库正常,若存在自定义证书(如公司MITM证书),需将其添加到ngrok的信任列表中
- 切换ngrok模式:尝试
ngrok tcp 4242绕开TLS相关拦截,或指定ngrok使用其他端口通信 - 验证本地TLS连接:手动执行
curl -v https://google.com测试TLS连接,确认是否是系统层面的问题而非ngrok单独的问题
内容的提问来源于stack exchange,提问作者Quyễn Nguyễn
相关产品推荐
相关产品推荐

