247-IT Guide
NUT on Windows: monitoring a UPS via Network UPS Tools
Network UPS Tools (NUT) is the vendor-neutral standard for reading UPS units over the network. The NUT server usually runs on a NAS, a firewall or a Linux machine; Windows is normally just a client. How the pieces fit together, how to test the connection from Windows and what to watch out for security-wise.
How NUT works
NUT has three parts. A driver talks to the UPS via USB, serial or SNMP. The
server upsd publishes the readings on the network, by default
on TCP port 3493. Clients read those values and decide
whether to shut down. This way NUT supports several thousand UPS models, including ones
without a network card of their own.
The machine the UPS is connected to via USB is the primary (formerly "master"). It shuts down last and can tell everyone else via FSD (forced shutdown) that it is time. All other clients are secondaries (formerly "slaves").
| Variable / status | Meaning |
|---|---|
battery.charge | battery charge in percent |
battery.runtime | estimated runtime in seconds |
ups.load | load in percent |
input.voltage | input voltage in volts |
ups.status = OL | on mains power (online) |
ups.status = OB | on battery |
ups.status = LB | low battery, usually together with OB: "OB LB" |
ups.status = FSD | forced shutdown, set by the primary |
Where the NUT server usually runs
The server runs where the UPS is connected via USB. In smaller environments that is often a device that runs around the clock anyway:
NAS (Synology, QNAP)
Both ship a NUT server. On Synology the option is called "Enable network UPS server",
plus the IP addresses of the clients have to be allowed. Synology uses the UPS name
ups and fixed credentials that are well documented in the community.
Firewall (pfSense, OPNsense)
Via the NUT package or plugin: the firewall is usually the device that should keep running longest during an outage, which makes it a good primary.
Linux, Proxmox, Raspberry Pi
Package nut or nut-server. Configuration lives in
ups.conf (driver), upsd.conf (network) and
upsd.users (users).
A minimal Linux server that listens on the network and knows a read-only user:
# /etc/nut/upsd.conf
LISTEN 0.0.0.0 3493
# /etc/nut/upsd.users
[monitor]
password = ALongPassword
upsmon secondary
Rather than 0.0.0.0, enter only the address on the management network, see
section 04. A NUT server on Windows itself is rare; Windows is almost always a client.
NUT clients for Windows
| Client | What it does | Fits when … |
|---|---|---|
| WinNUT-Clientopen source, free | Reads a NUT server and shuts down its own Windows machine. | single Windows PCs or servers without dependencies. |
| UPS Hyper-V Shutdown Monitorcommercial, 30-day trial | Reads one or more NUT servers and shuts down Hyper-V hosts and their VMs in a fixed order, without agents on the hosts. | Hyper-V environments with several hosts, VMs and dependencies. |
Whether a Windows machine can reach the NUT server can be checked with PowerShell and no
extra software. The commands list every variable of the UPS ups:
Test-NetConnection nas.company.local -Port 3493
$c = New-Object Net.Sockets.TcpClient('nas.company.local', 3493)
$w = New-Object IO.StreamWriter($c.GetStream()); $w.AutoFlush = $true
$r = New-Object IO.StreamReader($c.GetStream())
$w.WriteLine('LIST VAR ups')
do { $l = $r.ReadLine(); $l } until ($l -match '^(END LIST|ERR)')
$c.Close()
ERR UNKNOWN-UPS means the UPS name is wrong. ERR ACCESS-DENIED or a
timeout usually means the client's IP address is not allowed on the server or a firewall
blocks port 3493.
Securing NUT on the network
The NUT protocol is a simple text protocol. Without separately configured TLS, readings, user name and password travel unencrypted. Anyone with write access can send commands to the UPS, such as starting a self-test or switching it off. Therefore:
- Listen on the management network only — in
upsd.conf, enter the management network address instead of0.0.0.0and restrict port 3493 to the clients with a firewall. - Separate users — one read-only user (
upsmon secondary), and a separate one withinstcmdsonly where commands such as a self-test are really needed. - Your own passwords — don't reuse default credentials from guides where the device lets you set your own.
- Allow clients instead of opening up — on NAS and firewall, permit only the clients' IP addresses.
NUT in the UPS Hyper-V Shutdown Monitor
In the UPS Hyper-V Shutdown Monitor you choose NUT as the protocol and enter server, port (3493), UPS name and, if required, user and password. A test button shows immediately whether the connection works.
- Readings — battery charge, runtime, status, input voltage and load from the NUT variables, as the basis for the thresholds.
- FSD takes priority — if the NUT server reports "FSD", the shutdown starts immediately, regardless of the other thresholds.
- Ordered Hyper-V shutdown — VMs and hosts in the configured order, as described in Shutting down Hyper-V VMs during a power outage.
- Several NUT servers and UPS units — each UPS protects only the hosts assigned to it.
- UPS self-test via NUT — on demand or scheduled via
test.battery.start; the NUT user needs theinstcmdsright.
The software connects via the unencrypted NUT protocol, so the NUT server belongs in a trusted network (section 04).
Checking a NUT setup
- UPS name known — the name from
ups.confor from the NAS (upson Synology). - Server listens on the network — not only on
127.0.0.1;Test-NetConnectionsucceeds from every client. - Clients allowed — IP addresses entered on the server or NAS.
- Plausible values — compare runtime and charge with the UPS display.
- Primary goes last — the machine with the USB cable must keep running until every client has shut down.
- Test once — during a maintenance window or in the test mode of the shutdown software.
Frequently asked questions
What is NUT (Network UPS Tools)?
NUT is free, vendor-neutral software that reads UPS units through drivers via USB, serial or SNMP and publishes the readings through a network service on TCP port 3493. Clients on the network read these values and shut down in an orderly way during a power outage.
Do I need my own NUT server on Windows?
Usually not. The NUT server runs where the UPS is connected, often on a NAS, a firewall or a Linux machine. Windows machines are clients that query this server over the network.
Which port does NUT use?
TCP port 3493 by default. It must be reachable from client to server, but should stay limited to the management network, because the protocol is unencrypted unless TLS is configured separately.
What does the status "OB LB" mean?
"OB" stands for on battery, "LB" for low battery. Together it means: mains power has failed and the battery is nearing its end. By now at the latest, the orderly shutdown must be running.
More guides
Replacing UPS batteries
Ageing, warning signs and swapping without a protection gap.
Restarting after a power outage
Starting servers, storage and VMs automatically when power returns.
Eaton IPM alternative for Hyper-V
Node licensing, editions and Hyper-V integration compared.
Hyper-V on Server Core
Protect hosts without a desktop via WinRM or a web interface.
SNMPv3 on a UPS network card
authPriv with SHA and AES instead of a plain-text community.
Shutting down Hyper-V VMs in a power outage
Stop action, shutdown order and time budget for an orderly shutdown.
Hyper-V failover cluster power outage
Coordinating quorum, CSV and live migration.
Active Directory & power outages
The USN rollback myth and the real risks for domain controllers.
SQL Server & Exchange on Hyper-V
Protecting databases during a power outage.
Calculating UPS runtime
Why the datasheet runtime rarely holds.
PowerChute alternative for Hyper-V
UPS shutdown without vendor lock-in.
Monitoring UPS units from multiple vendors
One tool instead of several silos.
Set up an ordered shutdown yourself
30 days free, every feature included. With test mode and dry run, so the first real power outage is not the first test.