Updated: 28 September 2026 · Applies to: AlmaLinux and Rocky Linux 9 and 10, RHEL 9 and 10 (firewalld with nftables), Ubuntu 24.04 and 26.04 and Debian 13 (UFW or nftables), servers with CSF

When another server or your own computer gets Connection refused, the target server answered, but nothing accepted the connection on that port. Most of the time the service is not running, or it listens only on 127.0.0.1. Firewalls are the second cause. The old CentOS 7 advice to switch between the firewalld and iptables services no longer applies: current systems use firewalld (AlmaLinux, Rocky Linux, RHEL) or UFW (Ubuntu), both on top of nftables.

The error message itself is a clue:

  • Connection refused: nothing listens on that address and port, or a firewall actively rejects the connection.
  • Connection timed out: packets are dropped on the way, usually by a firewall (on the server, at the provider, or on the client's network).
  • No route to host: a firewall rejects the traffic with an ICMP message, or the IP address is wrong or unreachable.

1. Is the service running?

systemctl status nginx

Use your own service name. If it failed, journalctl -u nginx -n 50 shows why.

2. Is it listening on the right address?

ss -ltnp 'sport = :8080'
  • No line: the service is not listening on that port. Check its configuration.
  • 127.0.0.1:8080 or [::1]:8080: it only accepts local connections. Change the listen address in the service's configuration to 0.0.0.0 (or the server's IP), for example bind-address for MariaDB or bind for Redis, then restart it. Only do this for services that should be reachable, and protect them with the firewall.
  • 0.0.0.0:8080 or *:8080: it listens on all addresses. Go to step 3.

3. Test on the server itself

curl -v http://127.0.0.1:8080/     # web services
nc -zv 127.0.0.1 8080              # any TCP port

If this works but remote connections do not, the problem is between the client and the service: the firewall.

4. Check the firewall

firewalld (AlmaLinux, Rocky Linux, RHEL):

firewall-cmd --state
firewall-cmd --list-all
firewall-cmd --permanent --add-port=8080/tcp && firewall-cmd --reload

UFW (Ubuntu, Debian):

ufw status verbose
ufw allow 8080/tcp

CSF (often on cPanel servers): add the port to TCP_IN in /etc/csf/csf.conf and run csf -r. If only one client fails, check whether its IP address was blocked: csf -g 198.51.100.7, and remove the block with csf -dr 198.51.100.7.

To see every rule, whichever tool created it: nft list ruleset.

5. SELinux (AlmaLinux, Rocky Linux, RHEL)

If a service will not start on a non-standard port, SELinux may block it. Check ausearch -m avc -ts recent, then allow the port for that kind of service, for example for a web server:

semanage port -a -t http_port_t -p tcp 8081

6. Test from outside

nc -zv 203.0.113.10 8080

Run this from another machine. If it times out while the server-side checks all pass, look for a firewall outside the server, for example at your own office or in a cloud security group.

If this happens on a Ucartz server and you cannot find the cause, open a support ticket with the output of steps 2 and 6.

Official documentation: firewalld documentation and ss manual page.

Ucartz services for this topic

Was this answer helpful? 0 Users Found This Useful (0 Votes)