Understand who opens the connection
For a passive check, the server or proxy requests a value from the agent. For an active check, the agent obtains its check list and sends collected values to the configured server or proxy. Active does not mean every inbound port can be ignored, and passive does not mean the data is automatically encrypted.
Typical default ports are agent TCP 10050 for passive checks and server/proxy TCP 10051 for active communication. Confirm actual configuration instead of using defaults as evidence.
Match four pieces
- The host record has the correct technical Host name, distinct from its visible label.
- The host is monitored by the intended server or proxy.
- The template's items use the intended active or passive type.
- The agent's settings point to the corresponding endpoint and use an accepted identity and encryption policy.
For active checks, Hostname must match the expected technical name. ServerActive defines the active destination. Server controls which peers can perform passive checks; these settings answer different questions.
Use a small verification item
Start with an agent availability or other simple supported value using the selected template. Inspect Latest data for a fresh value and check the agent log for active-check configuration errors. A running service alone does not prove host matching or item collection succeeded.
Protect the transport
Use supported TLS configuration for your design. A pre-shared key needs a matching identity, secret value and policy on both sides. Store it privately; do not publish example production PSKs. A Cloudflare HTTPS dashboard does not automatically transport the agent's native protocol.
Diagnose the direction
For passive failures, check listener, allowed peer, route and port from the poller to the agent. For active failures, check route to ServerActive, host identity, proxy assignment and the available active item list. Do not change both directions randomly while troubleshooting.
Common mistakes
Linking a passive template to an endpoint designed only for active connectivity produces missing data. The active agent can work even if a passive availability indicator does not show the expected state. A visible name matching the Windows hostname does not necessarily mean the technical Host name matches.
Free scope
Zabbix software is free; an existing server still needs resources, maintenance and storage. This lesson does not require paid monitoring services and does not propose moving its backend into static Cloudflare hosting.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.