How to Fix "Connection Refused"

The host is up, the port is closed. Three things to check.

Connection refused means nothing is listening on the port, or a firewall is rejecting it. Diagnose the service, port, and binding.

What "connection refused" means

"Connection refused" (ECONNREFUSED) is a TCP-level error: the host responded to the connection attempt, but explicitly rejected it — nothing is listening on the target port, or the kernel refused the connection. This is different from a timeout (the host didn't respond at all) and from "no route to host" (a network-layer failure).

Because the host actively rejected the connection, you know the host is reachable at the network layer. The problem is on the host: the service isn't running, it's listening on the wrong port, it's bound to localhost only, or a firewall is sending RST instead of dropping the packet. The fix is almost always one of those four.

Check 1-2: is the service running, on the right port?

First, confirm the service is running on the host. SSH in and check with `systemctl status <service>`, `docker ps`, or `ss -tlnp` (Linux) / `netstat -an` (Windows) to see what's actually listening. If the process isn't there, start it. If it crashed, read the logs to find out why before restarting, or you'll be back here in an hour.

Second, verify the port. A service listening on 3000 while you're connecting to 8080 gives "connection refused." Check the service config and the listening output from `ss`/`netstat`. Also confirm you're hitting the right host — a typo in the hostname or a wrong IP in DNS will send your connection to a machine that has nothing on that port.

Check 3-4: binding and firewall

Third, check what address the service is bound to. A common mistake is a service configured to listen on `127.0.0.1` or `localhost` only, which means it accepts local connections but refuses remote ones. The fix is to bind to `0.0.0.0` (all interfaces) or the specific external IP. Check the service config — Node apps set this in the listen call, web servers in their config, databases in their bind-address setting.

Fourth, check the firewall. A firewall configured to REJECT (rather than DROP) packets on a closed port sends a TCP RST, which the client sees as "connection refused" — indistinguishable from no service running. Check `iptables -L` / `ufw status` on Linux, Windows Firewall rules, and cloud security groups. A port-monitoring check (like SurePing's TCP monitor) will tell you the moment a service stops accepting connections, so you catch this before users do.

Related