Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A 502 Bad Gateway means a server acting as a gateway or proxy received an invalid or unusable response from another server upstream. In the usual request path—Browser → CDN/load balancer/reverse proxy → web server or application—the intermediary could not complete the request. The problem is usually at the website, hosting, CDN, or origin, although a VPN, proxy, DNS resolver, firewall, or local network can produce a failure visible only to you.

Wait for the interval shown, reload once, and then test the site in a private window, another browser, another device, and another network. If it fails everywhere, only the site owner or provider can fix the underlying service. If it works elsewhere, investigate your browser, VPN, DNS, router, or network.

What “Please try again in 30 seconds” means

“Try again in 30 seconds” is advice written by that particular error page or provider. It is not a universal HTTP requirement. A service may recover after a process restart, failover, deployment, or temporary overload, and the message also discourages rapid repeated requests during an incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make one deliberate retry after the suggested interval. Repeatedly refreshing every few seconds does not repair a failed origin and can increase load during an outage.

#1 Best Overall
NOYAFA NF-8508 Network Cable Tester with Optical Power Meter
  • Multifunctional NOYAFA NF-8508 Network Cable Tester: There are nine features to meet your needs. Continuity Testing, Cable Scan, Port Flash, Length Measurement, POE Power Supply Test, QC testing, Optical Power Meter, VFL and NVC function.It is perfectly suited for various engineering cabling projects, network troubleshooting, network equipment maintenance and testing scenarios. Its precise cable scanning and fault localization capabilities help you effortlessly pinpoint the root cause of issues.
  • 7 WAVELENGTHS OPTICAL POWER METER: NF-8508 network cable tester can measure 7 standard wavelengths, 850/1300/1310/1490/1550/1625/1650, power detecting range(dBm): -70 ~ +10. Its power detection range spans from -70 dBm to +10 dBm, supporting FC/SC/ST connectors. It enables precise fiber optic power measurement, helping users efficiently assess fiber signal strength and ensure healthy fiber link operation. It effortlessly detects attenuation issues within fibers, thereby safeguarding fiber network stability.
  • High Efficiency Visual Fault Locator: Easy identification of fiber breakpoints, poor connections, bending or cracking. Excellent for finding the right fiber to splice or quickly finding a break. Emmiting Energy: standard wavelenth: 650nm. Fast flashing, slow flashing, high precison.The built-in self-calibration ensures stable long-term performance, and Class IIIa laser (output<5mW) ensures safe daily operation.
  • PORT FLASHING:The indicator light on the connection port in the NF-8508 device flashes to help accurately locate the cable. Displays port information, including operating speed, duplex mode, and negotiation settings. Port lights flash on the same screen to show the port's operating speed, making it easy to pinpoint lines and ports.
  • PoE Testing and Cable Length Test: PoE testing can check cable mapping polarity and voltage of PoE network switches, withstand 60VDC. Automatically detects and switches between 10M/100M/1000M modes, Includes cable tracking, short circuit test, interruption of circuit test and etc The RJ45 cable tester can quickly measure the length of the cable with a range of 200m. Not only network cables, but also phone lines and BNC cables.

What a 502 Bad Gateway error is

Think of the gateway as a receptionist calling another department. The receptionist connected successfully, but received a broken, incomplete, or otherwise unusable reply. It reports that failure to your browser as 502. The origin may still be running; it could be on the wrong port, refusing connections, failing TLS, crashing while responding, or returning malformed HTTP.

See the HTTP definition at MDN’s 502 reference.

Status Typical meaning
502 A gateway received an invalid or unusable upstream response.
504 The gateway did not receive an upstream response within its allowed time; see MDN’s 504 reference.
500 The application or server encountered an internal error.
503 The service is temporarily unavailable, often from maintenance, overload, or limited capacity.

Fixes for visitors

  1. Wait and reload once. Honor the page’s 30-second instruction (or wait 30–60 seconds), then use the browser reload control.
  2. Check the address. Confirm the domain, path, subdomain, and www spelling. An old bookmark or copied URL can point to a retired route.
  3. Use a private window. Try Chrome or Edge Incognito, Firefox Private Browsing, or Safari Private Window. If it works there, an extension, cookie, cached site data, browser proxy, or privacy filter is a likely factor.
  4. Try another browser and device. Test a phone, tablet, or second computer. Failure on every device points toward the site; failure in one browser points toward local state.
  5. Temporarily disable a VPN or proxy. A VPN can use a different DNS resolver or exit location, perform TLS inspection, or be blocked by the site. Disable it only for this test; do not leave security protection off permanently.
  6. Change networks. Switch from Wi-Fi to mobile data, or use a trusted hotspot. If mobile data works but Wi-Fi does not, investigate the router, ISP DNS, filtering, or local firewall.
  7. Restart the router. This can clear stale connection or DNS state when several sites or every home device are affected. It cannot repair a failed website origin.
  8. Flush DNS only when the issue is local. Use this as a targeted test, not a universal 502 cure:

    Windows Command Prompt

    ipconfig /flushdns

    Expected output: Successfully flushed the DNS Resolver Cache.

    macOS Terminal

    sudo dscacheutil -flushcache
    sudo killall -HUP mDNSResponder

    Linux with systemd-resolved

    sudo resolvectl flush-caches

    Linux commands vary by resolver. Changing to a public DNS service can be a comparison test, but it is not guaranteed to fix a bad origin and can introduce inconsistent routing.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  9. Contact the site. If the error persists across devices and networks, the owner or hosting provider must investigate.

Is it your network or the website?

What you observe Most likely direction
Fails on every device and network Website, origin, CDN, hosting, or DNS problem
Works for other people but not you Browser, VPN, proxy, DNS, firewall, ISP, or local network
Only one browser fails Extension, cookie, cache, proxy, or TLS state
Only one URL or feature fails Broken application route, API, backend, or deployment
Several websites fail Router, ISP, DNS, VPN, or security software
Only a corporate network fails Company proxy, firewall, secure web gateway, or filtering policy

Compare a second device, a second network, an independent uptime checker, and the provider’s official status page. Third-party checkers can be stale or unable to reach regionally restricted sites, so one “down” result is not conclusive.

Important warning for payments and forms

A 502 after submitting a payment, booking, upload, account change, or form does not prove that the action failed. The application may have completed the operation before the gateway failed while returning the response. Check confirmation email, order history, or account activity; avoid submitting the same payment repeatedly; and ask the merchant or service provider if the result is unclear.

When the site owner must intervene

Owners should first identify which layer generated the response: Nginx, Apache, a CDN, cloud load balancer, service mesh, tunnel, corporate proxy, or the application. A provider-branded page and request or Ray ID can help distinguish an edge-generated error from one passed through from the origin.

1. Confirm that the upstream is running

Check the application process, PHP-FPM, container, Kubernetes pod, or service manager. Test from the proxy host:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -v http://127.0.0.1:8080/

For Docker, test from the proxy container’s network rather than only from the host:

Rank #2
Sale
Klein Tools VDV501-851 Scout Pro 3 Tester Starter Set Cable Tester
  • VERSATILE CABLE TESTING: Cable tester tests voice (RJ11/12), data (RJ45), and video (coax F-connector) terminated cables, providing clear results for comprehensive testing on unenergized Ethernet cables (not designed to test PoE)
  • EXTENDED CABLE LENGTH MEASUREMENT: Measure cable length up to 2000 feet (610 m), allowing for precise cable length determination
  • COMPREHENSIVE FAULT DETECTION: Test for Open, Short, Miswire, or Split-Pair faults, ensuring thorough fault detection and identification
  • BACKLIT LCD DISPLAY: Backlit LCD screen displays cable length, wiremap, cable ID, and test results, ensuring easy readability in various lighting conditions
  • EFFICIENT CABLE TRACING: Trace cables, wire pairs, and individual conductor wires using the multiple style tone generator (requires analog probe Cat. No. VDV500-123, sold separately), simplifying cable tracing tasks
docker exec -it <proxy-container> curl -v http://<service-name>:8080/

A connection refusal commonly means nothing is listening, the port is wrong, or a firewall is rejecting traffic. A successful direct response shifts attention to proxy settings, headers, TLS, or response parsing.

2. Verify hostname, port, and container networking

Typical mistakes include pointing at port 80 while the application listens on 8080, using a host-published port from inside a container, using localhost (which means the proxy container itself), stale private IPs, or containers on different networks.

getent hosts <upstream-host>
nc -vz <upstream-host> <port>
curl -v http://<upstream-host>:<port>/

Use equivalent DNS and TCP tools where getent or nc is unavailable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Check DNS and IPv4/IPv6

dig <upstream-host>
dig @1.1.1.1 <upstream-host>
dig @8.8.8.8 <upstream-host>
curl -4 -v https://example.com/
curl -6 -v https://example.com/

Compare returned addresses and whether they are private or public as intended. If IPv4 works and IPv6 fails, inspect the AAAA record, IPv6 route, firewall, and listener.

4. Check firewalls and security groups

Verify that the proxy can reach the upstream port and that the upstream permits the proxy’s source address. Review cloud security groups, host firewalls, CDN allowlists, intrusion-prevention rules, and network routes. A CDN IP range blocked at the origin can create a persistent 502.

5. Test TLS and protocol alignment

Possible causes include an expired or mismatched certificate, incorrect SNI, an HTTPS proxy-to-HTTP origin mismatch, an untrusted self-signed certificate, incompatible TLS versions, or TLS inspection.

curl -vk https://<upstream-host>/

-k bypasses certificate verification for controlled diagnosis only. It is not a safe permanent fix. Cloudflare lists certificate, TLS inspection, and origin reachability as common Tunnel troubleshooting areas (Cloudflare Tunnel documentation).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Look for malformed responses

Broken headers, invalid characters, incorrect Content-Length, premature connection closure, protocol mismatch, corrupt gzip, or unsupported transfer encoding can all make an otherwise reachable upstream unusable. Cloudflare documents malformed and compression-related 502 cases in its 502/504 guidance.

Rank #3
NOYAFA NF-8506 Network Cable Tester with IP Scan, CAT5 CAT6 Ethernet Tester
  • New Upgraded Multi-function Network Cable Tester: NF-8506 TDR network tester has IP scanning, POE test, anti-interference RJ11 RJ45 CAT5 CAT6 cable test, continuity test, Ping network rate test, port flashing, sensitivity adjustment, cable Function of length test and LED flashlight.
  • 200m cable length test: The NF-8506 Network cable tester is a portable cable length tester. The cable tester can accurately measure the cable length in the range of 8.2ft/ 2.5m-656ft /200m, find the cable fault distance and facilitate real-time field measurementt
  • PING Tester+IP Scanner: This handheld Ping cable toner can be used to diagnose and maintain local area networks (Lans) running TCP/IP protocols. Powerful PING capabilities can verify connections, check the integrity of transmitted and received data, indicate network traffic load by measuring round-trip times and provide IP addresses
  • Network Rate Test + Cable Continuity Test: Ethernet tester can quickly assess network rate issues. Conducts PING tests from multiple locations to gauge server and website response speeds. Allows users to ensure the integrity and connectivity of network cables by identifying any breaks, openings, or short circuits along the cable length.
  • POE Tester: Identifies PoE devices efficiently. Detects crossover methods (unknown/end-span/mid-span/8-core power supply) and polarity. Comprehensive PoE detection, including non-standard, IEEE 802.3AF, and IEEE 802.3AT.

7. Check crashes, deployments, and capacity

Correlate the first 502 with deployments, dependency updates, certificate renewals, DNS changes, container rebuilds, and load-balancer edits. Investigate CPU and memory saturation, out-of-memory kills, file-descriptor and connection-pool limits, disk capacity, ephemeral ports, database limits, and too many concurrent upstream connections. Preserve logs before restarting: a restart can hide the cause.

Owner diagnostic workflow

Capture the public response:

curl -sS -D - -o /dev/null https://example.com/
curl -v https://example.com/
curl -sS -o /dev/null 
  -w 'DNS: %{time_namelookup}nConnect: %{time_connect}nTLS: %{time_appconnect}nTTFB: %{time_starttransfer}nTotal: %{time_total}nHTTP: %{http_code}n' 
  https://example.com/

Then test the origin while preserving the intended host and TLS name:

curl -v -H 'Host: example.com' http://127.0.0.1:8080/
curl -vk --resolve origin.example.com:443:203.0.113.10 
  https://origin.example.com/

Replace the documentation IP with the real origin address. Inspect reverse-proxy, application, process-manager, container, load-balancer, CDN, firewall, and DNS logs at the same timestamp.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Log message Likely direction
connection refused No listener, wrong port, or active rejection
no route to host Routing or firewall problem
upstream timed out Slow or unreachable upstream; may become 504
upstream prematurely closed connection Crash or early application close
SSL handshake failed TLS, certificate, SNI, or protocol issue
host not found in upstream DNS or configuration failure
invalid header Malformed upstream response
upstream sent too big header Header or proxy-buffer limitation

Do not increase proxy timeouts blindly. A longer timeout may help a genuinely slow application, but it can also accumulate connections and worsen overload.

Nginx checks

A basic proxy block might look like this, but it is not a universal drop-in configuration:

location / {
    proxy_pass http://127.0.0.1:8080;
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
}

WebSockets, path rewriting, HTTPS upstreams, authentication headers, request sizes, and container networking may require different settings. Validate before reloading:

sudo nginx -t
sudo systemctl reload nginx

Common log locations are /var/log/nginx/error.log and /var/log/nginx/access.log, although distributions can differ. Nginx’s proxy module reference explains directive behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Docker-specific 502 causes

  • localhost points to the proxy container, not the application.
  • The service name or Docker network is wrong.
  • The app listens only on 127.0.0.1 inside its container.
  • A host port was used where the container port is required.
  • Health checks mark a container ready before the app is ready.
  • IPv4 and IPv6 bindings do not match the proxy’s connection.
  • A restart changed an address while stale configuration remains.
docker ps
docker logs <container-name>
docker inspect <container-name>
docker network inspect <network-name>

Cloudflare and AWS edge cases

Cloudflare says most 502/504 errors originate at the origin, but first determine who generated the response. A Cloudflare-branded page may be passing through an origin 502/504 or showing an edge-to-origin failure; an unbranded response can indicate a response generated by another layer. Do not purge the cache as a reflex: purging cannot revive a crashed or unreachable origin. See Cloudflare’s 5xx guidance.

Rank #4
Sale
Klein Tools VDV500-920 Wire Tracer Tone Generator and Probe Kit Continuity Tester for Ethernet, Internet, Telephone, Speaker, Coax, Video, and Data Cables, RJ45, RJ11, RJ12
  • DIGITAL MODE: Easily trace and locate cables on an active network to identify their paths and destinations effectively
  • ANALOG MODE: Isolate individual wire pairs, facilitating the tracing of voice, data, video, and audio cables
  • CONTINUITY AND POLARITY TESTING: Results for continuity and polarity tests are displayed on LEDs that are clearly labeled and easy to read
  • TRACE UNSTRIPPED WIRES: Rugged Angled Bed of Nails (ABN) clips securely attach to wires
  • WIRE MAPPING CAPABILITIES: Utilize wire mapping capabilities to verify Pin-to-Pin connections and shield detection

For AWS Application Load Balancers, investigate target connection failures, targets closing connections unexpectedly, and invalid target responses using the ALB troubleshooting guide. For CloudFront, check origin DNS and connectivity, origin protocol policy, TLS hostname and certificate, firewall rules, and cache behavior. CloudFront can retry or cache some errors according to configuration, so an origin fix may not appear immediately; consult CloudFront status-code documentation and its response-error guide.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to send support

Report the exact URL, failure time and time zone, screenshot or complete message, browser and operating system, whether another device or network failed, whether the error is intermittent, and any Ray ID, request ID, provider name, or status code. This lets the owner correlate your report with edge and origin logs.

Monitoring and prevention for site owners

Monitoring detects and documents 502s; it does not repair a broken application. A basic external HTTP monitor can alert you when a route fails from multiple locations. More advanced platforms add DNS, SSL, API, browser-transaction, logs, traces, on-call, and incident workflows. Choose based on the failure you need to diagnose rather than buying a CDN or monitoring product as a substitute for fixing the origin.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Basic outage alerts: a free or entry-level monitor such as UptimeRobot. Its plans and limits change; see the official pricing page.
  • Logs, traces, on-call, and browser transactions: Better Stack’s current offerings are listed at betterstack.com/pricing and its monitoring page.
  • CDN, DNS, WAF, DDoS protection, and reverse proxy: Cloudflare’s plans are listed at cloudflare.com/plans. Adding an edge layer can improve resilience but also adds another possible failure path.

Product prices, plan limits, provider behavior, and UI labels change. The cited commercial signals were observed on August 18, 2026; verify current terms before purchasing.

Frequently Asked Questions

Is a 502 error my fault?

Usually it is a server-side proxy or origin problem, but a VPN, local proxy, DNS resolver, firewall, or network can make the failure affect only you. Test another browser, device, and network before deciding.

Will restarting my router fix a 502?

It can help when several sites or devices on one network have stale DNS or connection state. It cannot repair a crashed or misconfigured website origin.

Will clearing cache fix a 502?

It may isolate a browser extension, cookie, or proxy problem, especially in a private window. A genuine server-generated 502 normally requires action at the proxy, origin, or infrastructure layer.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why does the site work on mobile data but not Wi-Fi?

Your Wi-Fi path may have a DNS, router, ISP, firewall, VPN, or filtering problem. Compare DNS answers and test without the VPN before changing settings permanently.

Best Value
Klein Tools VDV526-200 LAN Scout Jr Cable Tester Ethernet Cable Tester Kit
  • VERSATILE CABLE TESTING: Cable tester for data (RJ45) terminated cables and patch cords, ensuring comprehensive testing capabilities
  • LARGE BACKLIT LCD: Backlit LCD display enables easy reading of pin-to-pin wiremap results, even in low-lit areas
  • COMPREHENSIVE FAULT DETECTION: Test for Open, Short, Miswire, Split-Pair faults, Cross-over, and Shield, providing thorough fault detection
  • INTUITIVE USER INTERFACE: User-friendly interface with three buttons and simple, easy-to-identify test responses, ensuring a smooth testing experience
  • MULTIPLE TONE GENERATOR STYLES: Tone on a single wire, wire pair, or all 8 conductor wires using the multiple style tone generator (solid/warble); requires probe Cat. No. VDV500-123 (sold separately)

Can a VPN cause a 502?

Yes. A VPN can change DNS and routing, use a blocked exit address, or interfere with TLS. Disable it briefly to compare, then restore it.

Should I change DNS?

Only as a targeted comparison when the issue is isolated to one device or network. Flushing or comparing resolvers can reveal stale or incorrect DNS, but it will not fix an unreachable origin.

What is the difference between 502 and 504?

A 502 means the gateway received an invalid or unusable upstream response. A 504 generally means it did not receive a response within the allowed time. The underlying network or application problem can overlap.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do I fix a 502 in Nginx?

Confirm the upstream process is listening, verify the host and port, test it with curl, check DNS, firewall, TLS, and Nginx error logs, then validate with sudo nginx -t before reloading. Do not assume Nginx itself is the root cause.

Why does Docker Nginx return 502?

Common causes are using localhost inside the proxy container, wrong service or container port, separate Docker networks, an app bound only to loopback, or a container that is not ready.

How long should I wait before contacting the site owner?

Retry once after the page’s suggested interval, then test another browser or network. If it continues across devices and networks—or involves a payment or important transaction—contact the owner promptly with the URL, time, screenshot, and request ID.

The Bottom Line

A 502 is usually a broken conversation between a gateway and an upstream service. Visitors should wait briefly, test another browser and network, and stop repeatedly refreshing; owners should test the origin directly, verify DNS, ports, firewall and TLS, inspect logs, and correlate the failure with deployments or resource limits. A 30-second wait is provider advice, not an HTTP guarantee.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.