# Error getting load from agent xx.xxx.x.xx: Request rejected by server: '401' 'Unauthorized'

**URL:** https://community.thinlinc.com/t/error-getting-load-from-agent-xx-xxx-x-xx-request-rejected-by-server-401-unauthorized/1508
**Category:** Community Support
**Created:** [11 April 2025 23:16 UTC](https://community.thinlinc.com/t/error-getting-load-from-agent-xx-xxx-x-xx-request-rejected-by-server-401-unauthorized/1508 "2025-04-11T23:16:39Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![kwilder](https://dub1.discourse-cdn.com/flex005/user_avatar/community.thinlinc.com/kwilder/32/662_2.png) [@kwilder](https://community.thinlinc.com/u/kwilder)
#### Post date: [11 April 2025 23:16 UTC](https://community.thinlinc.com/t/error-getting-load-from-agent-xx-xxx-x-xx-request-rejected-by-server-401-unauthorized/1508/1 "2025-04-11T23:16:39Z")

</div>

I am evaluating ThinLinc for commercial use. I was able to get connected to an agent desktop when server and agent are on same VM. When I configure server with subcluster agent on separate VM the server cannot get load from agent.

```auto
sudo tail --lines 2 /var/log/vsmserver.log
2025-04-11 23:04:53 WARNING vsmserver.loadinfo: Error getting load from agent xx.xxx.x.xx: Request rejected by server: '401' 'Unauthorized'
2025-04-11 23:04:53 WARNING vsmserver.loadinfo: Marking agent xx.xxx.x.xx as down

```

I have tried agent public IP and private IP. I know there is not a network problem because I am able ssh from the server to the agent if I use a private key.  
`ssh -i ~/.ssh/id_rsa ubuntu@xx.xxx.x.xx`

What is the mechanism for server to connect to agent to get the the “load”? Is it over ssh or some other port directly to the agent? And what authentication does it use (private key, password, something else)?  
I think there is something that I don’t understand

---

<div class="post-metadata">

### Author: ![aaron](https://dub1.discourse-cdn.com/flex005/user_avatar/community.thinlinc.com/aaron/32/13_2.png) [@aaron](https://community.thinlinc.com/u/aaron)
#### Post date: [13 April 2025 21:09 UTC](https://community.thinlinc.com/t/error-getting-load-from-agent-xx-xxx-x-xx-request-rejected-by-server-401-unauthorized/1508/2 "2025-04-13T21:09:32Z")

</div>

Hi @kwilder,

You can find a list of ports used by the agent server here:

> **[On a machine running VSM Agent — ThinLinc Administrator's Guide](https://www.cendio.com/resources/docs/tag/tcp-ports_agent.html)**
>
> Overview of essential TCP ports used by ThinLinc agents, including SSH, Web Access, and VNC services.

In short, the master connects to the agent via port `904`. There is no authentication as such, but you need to make sure of two things:

- the parameter `/vsmagent/master_hostname` is set correctly on the agent. This should be the IP address or hostname of the master server.
- the parameter `/vsmserver/subclusters/<cluster_name>/agents` contains the correct IP address or hostname of the agent

You should only use private network addresses for this as the traffic between master and agent servers is not encrypted. Hope that helps.

---

<div class="post-metadata">

### Author: ![kwilder](https://dub1.discourse-cdn.com/flex005/user_avatar/community.thinlinc.com/kwilder/32/662_2.png) [@kwilder](https://community.thinlinc.com/u/kwilder)
#### Post date: [14 April 2025 00:00 UTC](https://community.thinlinc.com/t/error-getting-load-from-agent-xx-xxx-x-xx-request-rejected-by-server-401-unauthorized/1508/3 "2025-04-14T00:00:44Z")

</div>

Thanks for the fast response. My agent `/vsmagent/master_hostname` setting was pointed to `localhost`. Fixed it with these commands using private IP of master VM.

```auto
sudo /opt/thinlinc/bin/tl-config /vsmagent/master_hostname=xx.xxx.x.xx
sudo systemctl restart vsmagent

```
