# Locations and status

A VPN server can be healthy from one country and blocked from another. TunnelHQ tests from the locations you choose, records a result for each, and combines them into one status.

## Any location vs. specific locations

By default, a monitor tests from **Any**: TunnelHQ picks a worker and runs the check. That's enough to answer "is this server up?"

Add specific locations when location matters. Add a country from the picker, which lists the locations TunnelHQ can test from right now (the same list as `GET /api/v1/regions`). Each location you add gets its own independent check on every cycle, so you can see that a server is reachable from one place and blocked from another, which a single-location check would miss.

:::caution[Specific locations need Pro or Business]
Free and Starter monitors test from **Any**. Specific locations are available on Pro, with up to 5 locations per monitor, and on Business, with up to 12.
:::

## Aggregate status

When a monitor tests from more than one location, TunnelHQ keeps the latest result for each location and combines them into one **aggregate status**.

| Status | When |
| --- | --- |
| Healthy | At least one location is up and none are down. |
| Partial | At least one location is up and at least one is down. The server is up, but not everywhere. |
| Down | At least one location is down and none are up. |
| Degraded | No location is up or down, and at least one got a definite refusal: the server answered and rejected the monitor's credentials or certificate. |
| Unknown | Every location's latest result was inconclusive, for example because of a fault on TunnelHQ's checker. |
| Paused | The monitor is paused. |

**Degraded** is a confirmed configuration problem rather than an unknown, which is why it's shown separately from a check that's still pending. It isn't an alerting state on its own, but it isn't a dead end either: when the monitor recovers from it, the recovery is announced as usual.

A location with no available checker shows **Unavailable** and is left out of the aggregate entirely, so it can't raise an alert, hide a failure, or make a monitor partial. Locations under maintenance are left out too.

A single check with no verdict (still retrying, inconclusive, or a checker fault) shows **Unknown**, except a refused credential or certificate, which shows **Degraded**. A monitor that has never been checked shows **Pending**.

The aggregate status drives the status pill, the dashboard counts, and incident creation, so a monitor with several locations reflects what all your users see, not a single vantage point. [What a failed check says](/docs/concepts/monitors/#what-a-failed-check-says) explains which failures count as down.

## Partial-failure alerts

Each monitor has a **Notify on partial outage** switch, off by default. Turn it on to be alerted when some locations fail while others pass. Leave it off to hear only about full outages: a change to **Partial** then sends no alert, and neither does a brief **Healthy → Partial → Healthy** or **Down → Partial → Down** bounce. Removing every specific location turns the switch off.

## Pausing a single location

You can pause one location without removing it: click the power icon on its chip. The chip stays in the list, dimmed, the scheduler skips it, and it stops counting toward the aggregate. Click the power icon again to resume it. This is useful when a probe location has problems of its own and you don't want the noise.

:::note[Location codes]
In the API and in heartbeat history, locations are identified by lowercase ISO 3166-1 alpha-2 codes (`pk`, `de`, `sg`, and so on), plus the special value `any`. The API calls this field `region`.
:::
