Network UPS Tools (NUT): A Complete Setup Guide

Network UPS Tools (NUT) reads your UPS over USB, serial or SNMP and shuts down one or many machines when the battery runs low. You need five small config files on the host with the cable, and one on each client.

On this page
  1. How NUT is put together
  2. Step 1: nut.conf sets the role
  3. Step 2: ups.conf defines the UPS
  4. Step 3: upsd.conf and upsd.users control access
  5. Step 4: upsmon.conf decides when to shut down
  6. Reading ups.status
  7. Step 5: add network clients
  8. The shutdown sequence, step by step
  9. Commands and settings: upscmd and upsrw
  10. Troubleshooting
  11. Where to go next
  12. Frequently asked questions

How NUT is put together

NUT is a set of small programs rather than one daemon. Knowing which piece does what makes every error message easier to read.

NUT components
ComponentRuns onJobConfig file
Driver (usbhid-ups, snmp-ups, blazer_usb, and many others)Host with the cableSpeaks the UPS's protocol and translates it into standard NUT variablesups.conf
upsdHost with the cableServes driver data to local and network clients on TCP 3493upsd.conf, upsd.users
upsmonEvery host that should shut downWatches status, runs notifications, triggers the OS shutdownupsmon.conf
upssched (optional)Any upsmon hostTimers, such as "shut down after 5 minutes on battery"upssched.conf
Tools: upsc, upscmd, upsrw, nut-scannerAnywhereRead variables, send commands, change settings, discover devicesnone

The examples below use the Debian and Ubuntu layout (/etc/nut/). Some distributions use /etc/ups/; the file contents are the same. Install the packages first (on Debian and Ubuntu, the nut package pulls in server and client parts).

Step 1: nut.conf sets the role

# /etc/nut/nut.conf
# none        = NUT disabled
# standalone  = one machine, UPS on this host, no network clients
# netserver   = UPS on this host, other machines connect to it
# netclient   = this host only runs upsmon against a remote server
MODE=netserver

Use standalone if this is the only machine on the UPS. In practice netserver costs nothing extra and makes adding a second host later a one-file change.

Step 2: ups.conf defines the UPS

Run nut-scanner -U first. It lists USB UPS devices and prints a ready-made section with the right driver, vendor ID and product ID.

# /etc/nut/ups.conf
maxretry = 3

[myups]
    driver = usbhid-ups
    port = auto
    desc = "Rack UPS, office closet"
    # Optional: raise low-battery earlier than the UPS's own signal
    # ignorelb
    # override.battery.charge.low = 30
    # override.battery.runtime.low = 300

The name in brackets (myups) is how every other tool refers to the UPS. port = auto is correct for USB drivers; serial drivers need a device such as /dev/ttyS0. If you have two USB UPS units on one host, add vendorid, productid or serial lines so each section matches the right one.

Start the driver and check for errors:

sudo upsdrvctl start
# or, on distributions with NUT 2.8 systemd units:
sudo systemctl restart nut-driver@myups.service

Unit names vary. Recent NUT releases generate one nut-driver@NAME unit per section, grouped by nut-driver.target; older packages use a single nut-driver.service. Run systemctl list-units 'nut*' to see what your system has.

Step 3: upsd.conf and upsd.users control access

# /etc/nut/upsd.conf
LISTEN 127.0.0.1 3493
LISTEN 192.168.1.10 3493     # this server's LAN address

You will see many guides use LISTEN 0.0.0.0 3493. That works, but it listens on every interface, including VPN, guest or public-facing ones. Listing specific addresses is safer. Either way, allow 3493 only from your LAN in the host firewall.

# /etc/nut/upsd.users
[upsmon_local]
    password = ChangeThisLocal
    upsmon primary

[monuser]
    password = ChangeThisRemote
    upsmon secondary

[admin]
    password = ChangeThisAdmin
    actions = SET
    instcmds = ALL

upsmon primary grants the right to declare a forced shutdown. Give it only to the upsmon on the server itself. Clients get upsmon secondary. The admin user is for upscmd and upsrw; leave it out if you will never send commands. On NUT older than 2.8, write upsmon master and upsmon slave instead. The files hold passwords, so make sure they are readable only by root and the NUT group (packages usually set this).

Step 4: upsmon.conf decides when to shut down

# /etc/nut/upsmon.conf (on the server)
MONITOR myups@localhost 1 upsmon_local ChangeThisLocal primary
MINSUPPLIES 1
SHUTDOWNCMD "/sbin/shutdown -h +0"
POWERDOWNFLAG /etc/killpower

POLLFREQ 5
POLLFREQALERT 5
HOSTSYNC 15
DEADTIME 15
FINALDELAY 5

NOTIFYCMD /usr/local/bin/ups-notify.sh
NOTIFYFLAG ONBATT   SYSLOG+WALL+EXEC
NOTIFYFLAG ONLINE   SYSLOG+WALL+EXEC
NOTIFYFLAG LOWBATT  SYSLOG+WALL+EXEC
NOTIFYFLAG FSD      SYSLOG+WALL+EXEC
NOTIFYFLAG COMMBAD  SYSLOG+WALL+EXEC
NOTIFYFLAG REPLBATT SYSLOG+WALL+EXEC
  • MONITOR: UPS name at host, the number of power supplies this host draws from that UPS (1 for a normal server), user, password, role.
  • MINSUPPLIES: how many supplies must stay healthy for the host to keep running. Servers with two power supplies on two UPS units can use this so losing one UPS does not shut them down.
  • SHUTDOWNCMD: what upsmon runs. Use the full path. On hypervisors this is often a script that stops guests first.
  • POWERDOWNFLAG: a file the primary creates just before shutdown, telling the late shutdown stage to send killpower. Some packages set a different default path; keep whatever your distribution's shutdown hook expects.
  • NOTIFYCMD and NOTIFYFLAG: EXEC runs your script with the message as an argument and NOTIFYTYPE and UPSNAME in the environment. That script is where email, push alerts or webhooks go.
  • HOSTSYNC: how long the primary waits for secondaries to disconnect during FSD. DEADTIME: how long a UPS can go without fresh data before upsmon treats it as dead.

Now start everything and check:

sudo systemctl restart nut-server nut-monitor
upsc -l                # lists UPS names upsd is serving
upsc myups@localhost   # dumps all variables

Typical output includes lines such as battery.charge: 100, battery.runtime: ... (seconds), input.voltage: ..., ups.load: ... (percent) and, most important, ups.status: OL CHRG. Which variables appear depends on what the UPS reports.

Reading ups.status

Common NUT status flags
FlagMeaning
OLOn line (utility power)
OBOn battery
LBLow battery. OB LB together is the default shutdown trigger
CHRG / DISCHRGBattery charging or discharging
RBReplace battery
BOOST / TRIMAVR is raising or lowering voltage (see AVR)
OVEROverload
CALRuntime calibration in progress
FSDForced shutdown declared by the primary

Step 5: add network clients

On each additional machine, install the client package and set two files:

# /etc/nut/nut.conf
MODE=netclient

# /etc/nut/upsmon.conf
MONITOR myups@192.168.1.10 1 monuser ChangeThisRemote secondary
MINSUPPLIES 1
SHUTDOWNCMD "/sbin/shutdown -h +0"

Restart nut-monitor on the client and run upsc myups@192.168.1.10 to confirm it can reach the server. Clients that cannot reach the server log COMMBAD and, after DEADTIME, will shut down if the UPS was last seen on battery.

The shutdown sequence, step by step

Understanding FSD avoids most "why did it shut down early" and "why didn't it come back" questions.

  1. Power fails. The UPS reports OB. Every upsmon logs ONBATT and runs its notifications. Nothing shuts down yet.
  2. Battery reaches critical. The status becomes OB LB. The primary upsmon sets the FSD flag on upsd.
  3. Secondaries shut down. They see FSD, run their SHUTDOWNCMD, and disconnect from upsd as they go down.
  4. The primary waits. It waits until all secondaries have disconnected or HOSTSYNC expires, whichever comes first.
  5. The primary shuts down. It creates the POWERDOWNFLAG file, waits FINALDELAY, and runs its own SHUTDOWNCMD.
  6. Killpower. Near the end of the OS shutdown, a hook checks for the flag (with upsmon -K) and runs the driver's shutdown routine (upsdrvctl shutdown or the packaged equivalent). The UPS is told to turn its output off after a delay, often around 20 seconds by default for usbhid-ups (ups.delay.shutdown).
  7. Power returns. The UPS restores output, and machines with "restore on AC power loss" set in BIOS boot automatically.

Why killpower matters more than people think

Without killpower, a short outage that ends after the servers have halted but before the battery dies leaves the UPS output on. The servers sit halted, and because their power never dropped, "power on after AC loss" never fires. They stay off until someone presses a button. Killpower turns a brief outage into a full power cycle, which is what makes unattended recovery work. Check that your distribution's shutdown hook is installed, and confirm with a real test.

Commands and settings: upscmd and upsrw

upscmd -l myups                                   # list supported instant commands
upscmd -u admin myups test.battery.start.quick    # start a quick self-test
upscmd -u admin myups beeper.mute                 # silence the current alarm
upsrw myups                                       # list writable variables
upsrw -s ups.delay.shutdown=60 -u admin myups     # change the killpower delay

Both tools prompt for the password if you omit -p, which keeps it out of shell history. Commands and writable variables vary widely by UPS model. See self-test and runtime calibration for when to run tests.

Troubleshooting

Common NUT errors and fixes
SymptomLikely causeFix
Driver: "No matching HID UPS found" or permission deniedudev rules not applied, so the NUT user cannot open the deviceReplug the USB cable after installing NUT, or run udevadm control --reload-rules and udevadm trigger; confirm with nut-scanner -U
upsc: "Driver not connected"Driver not running or wrong nameCheck systemctl status for the driver unit and that the section name matches
upsc: "Data stale"Driver lost contact with the UPS: flaky cable, USB hub, power saving on the USB port, or another program grabbing the deviceUse a direct port and short cable, stop vendor tools and apcupsd, consider pollinterval tuning
Client: "Connection refused"upsd listening only on 127.0.0.1, or firewallAdd a LISTEN line for the LAN address and open 3493 for the LAN
Client: "Access denied" or "Unknown UPS"Wrong user, password or UPS nameMatch upsd.users and the bracketed name in ups.conf exactly
Nothing starts at bootMODE=none left in nut.confSet the correct MODE and enable the units

If the operating system does not see the UPS at all (nothing in lsusb), the problem is below NUT. Work through UPS not detected by computer.

Test before you trust it

Use upsmon -c fsd on the primary to simulate the full forced-shutdown sequence, including killpower. It really shuts everything down and really cuts UPS output, so do it at a planned time with everything saved. Then repeat once by actually cutting input power.

Where to go next

For platform-specific setups, see Proxmox UPS shutdown, Synology, TrueNAS and Home Assistant monitoring. For an APC-only alternative with a simpler single file, see apcupsd. For picking a shutdown threshold, see how much runtime you need, and for a NAS-centered setup, UPS for a NAS.

Frequently asked questions

What port does NUT use?

TCP 3493 is the registered port for upsd. Clients connect to it to read status and receive FSD notices. Open it on the server's host firewall for your LAN only, and never forward it from the internet. The driver and upsd on the same host communicate through local sockets, not this port.

Should I use primary or master in upsmon.conf?

Use primary and secondary on NUT 2.8 and newer. If your distribution still ships 2.7.x or older, it only understands master and slave. Recent versions accept both spellings, so mixed old and new hosts on one network work as long as each config uses words its own version understands.

Can a Windows PC be a NUT client?

Yes, through third-party NUT client programs for Windows that connect to upsd on port 3493 and shut the PC down on FSD or low battery. They are not part of the core NUT project, so check that the one you choose is maintained and supports your Windows version.

How do I make NUT shut down earlier than the UPS's own low battery signal?

Either set override.battery.charge.low or override.battery.runtime.low with the ignorelb flag in ups.conf so the driver raises LB at your threshold, or use upssched to trigger a shutdown after a fixed time on battery. Driver support for these options varies, so check the driver's man page.

Does NUT work with a UPS connected to a Synology or TrueNAS box?

Yes. Both run NUT internally and can act as a network UPS server. Other machines then run upsmon as secondaries pointed at the NAS's IP, using the UPS name and credentials the NAS defines. Synology uses fixed names that clients must match.

What is the difference between nut-scanner and upsc?

nut-scanner searches USB, SNMP, XML and network for UPS devices and prints a suggested ups.conf section. It is for discovery before setup. upsc queries a running upsd for a configured UPS and shows its live variables. It is for checking that a working setup is reading data.

Sources and further reading

  1. Network UPS Tools project site
  2. NUT User Manual
  3. NUT man pages: ups.conf(5), upsd.conf(5), upsd.users(5), upsmon.conf(5), upsmon(8), usbhid-ups(8)
  4. NUT Hardware Compatibility List