Duaer

Troubleshooting

Fix WeCom error 60020 (IP not allowed) in Duaer

When Duaer sends a WeCom app message and gets 60020, the server IP is not in the self-built app trusted IP list. Add the IP shown in the error.

What the error looks like in Duaer

errcode 60020 with an errmsg like not allow to access from your ip … from ip: 1.2.3.4. WeCom accepts API calls for a self-built app only from trusted IPs. The address after from ip is the public IP Duaer called from.

Add the trusted IP in the WeCom admin console

  1. Copy the address after from ip in the error.
  2. Open the WeCom admin console, go to app management, and select the self-built app your Duaer credential uses.
  3. Under the developer API settings, find the trusted IP list, select configure, paste the IP, and confirm.
  4. If the console asks you to set a trusted domain or message server URL first, do that, then add the IP.
  5. Back in Duaer, select Execute step on the WeCom node to confirm.

A self-hosted Duaer server with a changing public IP hits 60020 again after the IP changes. Give the server a fixed egress IP.

Skip it for group-only alerts

To post only to a fixed group, use a WeCom group-bot Webhook credential, which needs no trusted IP. Refer to Send a WeCom message in Duaer.

Questions

Which IP does Duaer use for WeCom?

The address after from ip in the 60020 error is the public IP Duaer called from. Add that one to the trusted IP list.

Does a WeCom group bot in Duaer need a trusted IP?

No. Trusted IPs apply to self-built app APIs only; a group-bot Webhook from Duaer is not affected.

In this section