On this page
- How NUT is put together
- Step 1: nut.conf sets the role
- Step 2: ups.conf defines the UPS
- Step 3: upsd.conf and upsd.users control access
- Step 4: upsmon.conf decides when to shut down
- Reading ups.status
- Step 5: add network clients
- The shutdown sequence, step by step
- Commands and settings: upscmd and upsrw
- Troubleshooting
- Where to go next
- Frequently asked questions
How NUT is put together
NUT is a set of small programs rather than one daemon. Knowing which piece does what makes every error message easier to read.
| Component | Runs on | Job | Config file |
|---|---|---|---|
Driver (usbhid-ups, snmp-ups, blazer_usb, and many others) | Host with the cable | Speaks the UPS's protocol and translates it into standard NUT variables | ups.conf |
upsd | Host with the cable | Serves driver data to local and network clients on TCP 3493 | upsd.conf, upsd.users |
upsmon | Every host that should shut down | Watches status, runs notifications, triggers the OS shutdown | upsmon.conf |
upssched (optional) | Any upsmon host | Timers, such as "shut down after 5 minutes on battery" | upssched.conf |
Tools: upsc, upscmd, upsrw, nut-scanner | Anywhere | Read variables, send commands, change settings, discover devices | none |
The examples below use the Debian and Ubuntu layout (/etc/nut/). Some distributions use /etc/ups/; the file contents are the same. Install the packages first (on Debian and Ubuntu, the nut package pulls in server and client parts).
Step 1: nut.conf sets the role
# /etc/nut/nut.conf
# none = NUT disabled
# standalone = one machine, UPS on this host, no network clients
# netserver = UPS on this host, other machines connect to it
# netclient = this host only runs upsmon against a remote server
MODE=netserver
Use standalone if this is the only machine on the UPS. In practice netserver costs nothing extra and makes adding a second host later a one-file change.
Step 2: ups.conf defines the UPS
Run nut-scanner -U first. It lists USB UPS devices and prints a ready-made section with the right driver, vendor ID and product ID.
# /etc/nut/ups.conf
maxretry = 3
[myups]
driver = usbhid-ups
port = auto
desc = "Rack UPS, office closet"
# Optional: raise low-battery earlier than the UPS's own signal
# ignorelb
# override.battery.charge.low = 30
# override.battery.runtime.low = 300
The name in brackets (myups) is how every other tool refers to the UPS. port = auto is correct for USB drivers; serial drivers need a device such as /dev/ttyS0. If you have two USB UPS units on one host, add vendorid, productid or serial lines so each section matches the right one.
Start the driver and check for errors:
sudo upsdrvctl start
# or, on distributions with NUT 2.8 systemd units:
sudo systemctl restart nut-driver@myups.service
Unit names vary. Recent NUT releases generate one nut-driver@NAME unit per section, grouped by nut-driver.target; older packages use a single nut-driver.service. Run systemctl list-units 'nut*' to see what your system has.
Step 3: upsd.conf and upsd.users control access
# /etc/nut/upsd.conf
LISTEN 127.0.0.1 3493
LISTEN 192.168.1.10 3493 # this server's LAN address
You will see many guides use LISTEN 0.0.0.0 3493. That works, but it listens on every interface, including VPN, guest or public-facing ones. Listing specific addresses is safer. Either way, allow 3493 only from your LAN in the host firewall.
# /etc/nut/upsd.users
[upsmon_local]
password = ChangeThisLocal
upsmon primary
[monuser]
password = ChangeThisRemote
upsmon secondary
[admin]
password = ChangeThisAdmin
actions = SET
instcmds = ALL
upsmon primary grants the right to declare a forced shutdown. Give it only to the upsmon on the server itself. Clients get upsmon secondary. The admin user is for upscmd and upsrw; leave it out if you will never send commands. On NUT older than 2.8, write upsmon master and upsmon slave instead. The files hold passwords, so make sure they are readable only by root and the NUT group (packages usually set this).
Step 4: upsmon.conf decides when to shut down
# /etc/nut/upsmon.conf (on the server)
MONITOR myups@localhost 1 upsmon_local ChangeThisLocal primary
MINSUPPLIES 1
SHUTDOWNCMD "/sbin/shutdown -h +0"
POWERDOWNFLAG /etc/killpower
POLLFREQ 5
POLLFREQALERT 5
HOSTSYNC 15
DEADTIME 15
FINALDELAY 5
NOTIFYCMD /usr/local/bin/ups-notify.sh
NOTIFYFLAG ONBATT SYSLOG+WALL+EXEC
NOTIFYFLAG ONLINE SYSLOG+WALL+EXEC
NOTIFYFLAG LOWBATT SYSLOG+WALL+EXEC
NOTIFYFLAG FSD SYSLOG+WALL+EXEC
NOTIFYFLAG COMMBAD SYSLOG+WALL+EXEC
NOTIFYFLAG REPLBATT SYSLOG+WALL+EXEC
- MONITOR: UPS name at host, the number of power supplies this host draws from that UPS (1 for a normal server), user, password, role.
- MINSUPPLIES: how many supplies must stay healthy for the host to keep running. Servers with two power supplies on two UPS units can use this so losing one UPS does not shut them down.
- SHUTDOWNCMD: what upsmon runs. Use the full path. On hypervisors this is often a script that stops guests first.
- POWERDOWNFLAG: a file the primary creates just before shutdown, telling the late shutdown stage to send killpower. Some packages set a different default path; keep whatever your distribution's shutdown hook expects.
- NOTIFYCMD and NOTIFYFLAG:
EXECruns your script with the message as an argument andNOTIFYTYPEandUPSNAMEin the environment. That script is where email, push alerts or webhooks go. - HOSTSYNC: how long the primary waits for secondaries to disconnect during FSD. DEADTIME: how long a UPS can go without fresh data before upsmon treats it as dead.
Now start everything and check:
sudo systemctl restart nut-server nut-monitor
upsc -l # lists UPS names upsd is serving
upsc myups@localhost # dumps all variables
Typical output includes lines such as battery.charge: 100, battery.runtime: ... (seconds), input.voltage: ..., ups.load: ... (percent) and, most important, ups.status: OL CHRG. Which variables appear depends on what the UPS reports.
Reading ups.status
| Flag | Meaning |
|---|---|
OL | On line (utility power) |
OB | On battery |
LB | Low battery. OB LB together is the default shutdown trigger |
CHRG / DISCHRG | Battery charging or discharging |
RB | Replace battery |
BOOST / TRIM | AVR is raising or lowering voltage (see AVR) |
OVER | Overload |
CAL | Runtime calibration in progress |
FSD | Forced shutdown declared by the primary |
Step 5: add network clients
On each additional machine, install the client package and set two files:
# /etc/nut/nut.conf
MODE=netclient
# /etc/nut/upsmon.conf
MONITOR myups@192.168.1.10 1 monuser ChangeThisRemote secondary
MINSUPPLIES 1
SHUTDOWNCMD "/sbin/shutdown -h +0"
Restart nut-monitor on the client and run upsc myups@192.168.1.10 to confirm it can reach the server. Clients that cannot reach the server log COMMBAD and, after DEADTIME, will shut down if the UPS was last seen on battery.
The shutdown sequence, step by step
Understanding FSD avoids most "why did it shut down early" and "why didn't it come back" questions.
- Power fails. The UPS reports
OB. Every upsmon logs ONBATT and runs its notifications. Nothing shuts down yet. - Battery reaches critical. The status becomes
OB LB. The primary upsmon sets the FSD flag on upsd. - Secondaries shut down. They see FSD, run their SHUTDOWNCMD, and disconnect from upsd as they go down.
- The primary waits. It waits until all secondaries have disconnected or
HOSTSYNCexpires, whichever comes first. - The primary shuts down. It creates the POWERDOWNFLAG file, waits
FINALDELAY, and runs its own SHUTDOWNCMD. - Killpower. Near the end of the OS shutdown, a hook checks for the flag (with
upsmon -K) and runs the driver's shutdown routine (upsdrvctl shutdownor the packaged equivalent). The UPS is told to turn its output off after a delay, often around 20 seconds by default forusbhid-ups(ups.delay.shutdown). - Power returns. The UPS restores output, and machines with "restore on AC power loss" set in BIOS boot automatically.
Why killpower matters more than people think
Without killpower, a short outage that ends after the servers have halted but before the battery dies leaves the UPS output on. The servers sit halted, and because their power never dropped, "power on after AC loss" never fires. They stay off until someone presses a button. Killpower turns a brief outage into a full power cycle, which is what makes unattended recovery work. Check that your distribution's shutdown hook is installed, and confirm with a real test.
Commands and settings: upscmd and upsrw
upscmd -l myups # list supported instant commands
upscmd -u admin myups test.battery.start.quick # start a quick self-test
upscmd -u admin myups beeper.mute # silence the current alarm
upsrw myups # list writable variables
upsrw -s ups.delay.shutdown=60 -u admin myups # change the killpower delay
Both tools prompt for the password if you omit -p, which keeps it out of shell history. Commands and writable variables vary widely by UPS model. See self-test and runtime calibration for when to run tests.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Driver: "No matching HID UPS found" or permission denied | udev rules not applied, so the NUT user cannot open the device | Replug the USB cable after installing NUT, or run udevadm control --reload-rules and udevadm trigger; confirm with nut-scanner -U |
upsc: "Driver not connected" | Driver not running or wrong name | Check systemctl status for the driver unit and that the section name matches |
upsc: "Data stale" | Driver lost contact with the UPS: flaky cable, USB hub, power saving on the USB port, or another program grabbing the device | Use a direct port and short cable, stop vendor tools and apcupsd, consider pollinterval tuning |
| Client: "Connection refused" | upsd listening only on 127.0.0.1, or firewall | Add a LISTEN line for the LAN address and open 3493 for the LAN |
| Client: "Access denied" or "Unknown UPS" | Wrong user, password or UPS name | Match upsd.users and the bracketed name in ups.conf exactly |
| Nothing starts at boot | MODE=none left in nut.conf | Set the correct MODE and enable the units |
If the operating system does not see the UPS at all (nothing in lsusb), the problem is below NUT. Work through UPS not detected by computer.
Test before you trust it
Use upsmon -c fsd on the primary to simulate the full forced-shutdown sequence, including killpower. It really shuts everything down and really cuts UPS output, so do it at a planned time with everything saved. Then repeat once by actually cutting input power.
Where to go next
For platform-specific setups, see Proxmox UPS shutdown, Synology, TrueNAS and Home Assistant monitoring. For an APC-only alternative with a simpler single file, see apcupsd. For picking a shutdown threshold, see how much runtime you need, and for a NAS-centered setup, UPS for a NAS.
Frequently asked questions
What port does NUT use?
TCP 3493 is the registered port for upsd. Clients connect to it to read status and receive FSD notices. Open it on the server's host firewall for your LAN only, and never forward it from the internet. The driver and upsd on the same host communicate through local sockets, not this port.
Should I use primary or master in upsmon.conf?
Use primary and secondary on NUT 2.8 and newer. If your distribution still ships 2.7.x or older, it only understands master and slave. Recent versions accept both spellings, so mixed old and new hosts on one network work as long as each config uses words its own version understands.
Can a Windows PC be a NUT client?
Yes, through third-party NUT client programs for Windows that connect to upsd on port 3493 and shut the PC down on FSD or low battery. They are not part of the core NUT project, so check that the one you choose is maintained and supports your Windows version.
How do I make NUT shut down earlier than the UPS's own low battery signal?
Either set override.battery.charge.low or override.battery.runtime.low with the ignorelb flag in ups.conf so the driver raises LB at your threshold, or use upssched to trigger a shutdown after a fixed time on battery. Driver support for these options varies, so check the driver's man page.
Does NUT work with a UPS connected to a Synology or TrueNAS box?
Yes. Both run NUT internally and can act as a network UPS server. Other machines then run upsmon as secondaries pointed at the NAS's IP, using the UPS name and credentials the NAS defines. Synology uses fixed names that clients must match.
What is the difference between nut-scanner and upsc?
nut-scanner searches USB, SNMP, XML and network for UPS devices and prints a suggested ups.conf section. It is for discovery before setup. upsc queries a running upsd for a configured UPS and shows its live variables. It is for checking that a working setup is reading data.
Sources and further reading
- Network UPS Tools project site
- NUT User Manual
- NUT man pages: ups.conf(5), upsd.conf(5), upsd.users(5), upsmon.conf(5), upsmon(8), usbhid-ups(8)
- NUT Hardware Compatibility List