Skip to content
UPSmonitor 247-IT

247-IT Guide

NUT on Windows: monitoring a UPS via Network UPS Tools

Network UPS Tools (NUT) is the vendor-neutral standard for reading UPS units over the network. The NUT server usually runs on a NAS, a firewall or a Linux machine; Windows is normally just a client. How the pieces fit together, how to test the connection from Windows and what to watch out for security-wise.

01 Basics Driver, server, clients — and what goes over the wire.

How NUT works

NUT has three parts. A driver talks to the UPS via USB, serial or SNMP. The server upsd publishes the readings on the network, by default on TCP port 3493. Clients read those values and decide whether to shut down. This way NUT supports several thousand UPS models, including ones without a network card of their own.

The machine the UPS is connected to via USB is the primary (formerly "master"). It shuts down last and can tell everyone else via FSD (forced shutdown) that it is time. All other clients are secondaries (formerly "slaves").

The most important NUT variables and status values
Variable / status Meaning
battery.chargebattery charge in percent
battery.runtimeestimated runtime in seconds
ups.loadload in percent
input.voltageinput voltage in volts
ups.status = OLon mains power (online)
ups.status = OBon battery
ups.status = LBlow battery, usually together with OB: "OB LB"
ups.status = FSDforced shutdown, set by the primary
02 The NUT server Wherever the UPS is connected, the server runs.

Where the NUT server usually runs

The server runs where the UPS is connected via USB. In smaller environments that is often a device that runs around the clock anyway:

NAS (Synology, QNAP)

Both ship a NUT server. On Synology the option is called "Enable network UPS server", plus the IP addresses of the clients have to be allowed. Synology uses the UPS name ups and fixed credentials that are well documented in the community.

Firewall (pfSense, OPNsense)

Via the NUT package or plugin: the firewall is usually the device that should keep running longest during an outage, which makes it a good primary.

Linux, Proxmox, Raspberry Pi

Package nut or nut-server. Configuration lives in ups.conf (driver), upsd.conf (network) and upsd.users (users).

A minimal Linux server that listens on the network and knows a read-only user:

# /etc/nut/upsd.conf
LISTEN 0.0.0.0 3493

# /etc/nut/upsd.users
[monitor]
    password = ALongPassword
    upsmon secondary

Rather than 0.0.0.0, enter only the address on the management network, see section 04. A NUT server on Windows itself is rare; Windows is almost always a client.

03 Windows as client Which client suits which job.

NUT clients for Windows

Windows clients compared
Client What it does Fits when …
WinNUT-Clientopen source, free Reads a NUT server and shuts down its own Windows machine. single Windows PCs or servers without dependencies.
UPS Hyper-V Shutdown Monitorcommercial, 30-day trial Reads one or more NUT servers and shuts down Hyper-V hosts and their VMs in a fixed order, without agents on the hosts. Hyper-V environments with several hosts, VMs and dependencies.

Whether a Windows machine can reach the NUT server can be checked with PowerShell and no extra software. The commands list every variable of the UPS ups:

Test-NetConnection nas.company.local -Port 3493

$c = New-Object Net.Sockets.TcpClient('nas.company.local', 3493)
$w = New-Object IO.StreamWriter($c.GetStream()); $w.AutoFlush = $true
$r = New-Object IO.StreamReader($c.GetStream())
$w.WriteLine('LIST VAR ups')
do { $l = $r.ReadLine(); $l } until ($l -match '^(END LIST|ERR)')
$c.Close()

ERR UNKNOWN-UPS means the UPS name is wrong. ERR ACCESS-DENIED or a timeout usually means the client's IP address is not allowed on the server or a firewall blocks port 3493.

04 Security NUT talks plain text by default.

Securing NUT on the network

The NUT protocol is a simple text protocol. Without separately configured TLS, readings, user name and password travel unencrypted. Anyone with write access can send commands to the UPS, such as starting a self-test or switching it off. Therefore:

  1. Listen on the management network only — in upsd.conf, enter the management network address instead of 0.0.0.0 and restrict port 3493 to the clients with a firewall.
  2. Separate users — one read-only user (upsmon secondary), and a separate one with instcmds only where commands such as a self-test are really needed.
  3. Your own passwords — don't reuse default credentials from guides where the device lets you set your own.
  4. Allow clients instead of opening up — on NAS and firewall, permit only the clients' IP addresses.
05 Implementation NUT as the source for the Hyper-V shutdown.

NUT in the UPS Hyper-V Shutdown Monitor

In the UPS Hyper-V Shutdown Monitor you choose NUT as the protocol and enter server, port (3493), UPS name and, if required, user and password. A test button shows immediately whether the connection works.

  1. Readings — battery charge, runtime, status, input voltage and load from the NUT variables, as the basis for the thresholds.
  2. FSD takes priority — if the NUT server reports "FSD", the shutdown starts immediately, regardless of the other thresholds.
  3. Ordered Hyper-V shutdown — VMs and hosts in the configured order, as described in Shutting down Hyper-V VMs during a power outage.
  4. Several NUT servers and UPS units — each UPS protects only the hosts assigned to it.
  5. UPS self-test via NUT — on demand or scheduled via test.battery.start; the NUT user needs the instcmds right.

The software connects via the unencrypted NUT protocol, so the NUT server belongs in a trusted network (section 04).

06 Checklist Tool-independent.

Checking a NUT setup

  1. UPS name known — the name from ups.conf or from the NAS (ups on Synology).
  2. Server listens on the network — not only on 127.0.0.1; Test-NetConnection succeeds from every client.
  3. Clients allowed — IP addresses entered on the server or NAS.
  4. Plausible values — compare runtime and charge with the UPS display.
  5. Primary goes last — the machine with the USB cable must keep running until every client has shut down.
  6. Test once — during a maintenance window or in the test mode of the shutdown software.
07 Questions Short answers to common questions.

Frequently asked questions

What is NUT (Network UPS Tools)?

NUT is free, vendor-neutral software that reads UPS units through drivers via USB, serial or SNMP and publishes the readings through a network service on TCP port 3493. Clients on the network read these values and shut down in an orderly way during a power outage.

Do I need my own NUT server on Windows?

Usually not. The NUT server runs where the UPS is connected, often on a NAS, a firewall or a Linux machine. Windows machines are clients that query this server over the network.

Which port does NUT use?

TCP port 3493 by default. It must be reachable from client to server, but should stay limited to the management network, because the protocol is unencrypted unless TLS is configured separately.

What does the status "OB LB" mean?

"OB" stands for on battery, "LB" for low battery. Together it means: mains power has failed and the battery is nearing its end. By now at the latest, the orderly shutdown must be running.

Set up an ordered shutdown yourself

30 days free, every feature included. With test mode and dry run, so the first real power outage is not the first test.