Updated: 28 September 2026 · Applies to: AlmaLinux and Rocky Linux 9 and 10, RHEL 9 and 10 (firewalld with nftables), Ubuntu 24.04 and 26.04 and Debian 13 (UFW or nftables), servers with CSF
When another server or your own computer gets Connection refused, the target server answered, but nothing accepted the connection on that port. Most of the time the service is not running, or it listens only on 127.0.0.1. Firewalls are the second cause. The old CentOS 7 advice to switch between the firewalld and iptables services no longer applies: current systems use firewalld (AlmaLinux, Rocky Linux, RHEL) or UFW (Ubuntu), both on top of nftables.
The error message itself is a clue:
- Connection refused: nothing listens on that address and port, or a firewall actively rejects the connection.
- Connection timed out: packets are dropped on the way, usually by a firewall (on the server, at the provider, or on the client's network).
- No route to host: a firewall rejects the traffic with an ICMP message, or the IP address is wrong or unreachable.
1. Is the service running?
systemctl status nginx
Use your own service name. If it failed, journalctl -u nginx -n 50 shows why.
2. Is it listening on the right address?
ss -ltnp 'sport = :8080'
- No line: the service is not listening on that port. Check its configuration.
127.0.0.1:8080or[::1]:8080: it only accepts local connections. Change the listen address in the service's configuration to0.0.0.0(or the server's IP), for examplebind-addressfor MariaDB orbindfor Redis, then restart it. Only do this for services that should be reachable, and protect them with the firewall.0.0.0.0:8080or*:8080: it listens on all addresses. Go to step 3.
3. Test on the server itself
curl -v http://127.0.0.1:8080/ # web services nc -zv 127.0.0.1 8080 # any TCP port
If this works but remote connections do not, the problem is between the client and the service: the firewall.
4. Check the firewall
firewalld (AlmaLinux, Rocky Linux, RHEL):
firewall-cmd --state firewall-cmd --list-all firewall-cmd --permanent --add-port=8080/tcp && firewall-cmd --reload
UFW (Ubuntu, Debian):
ufw status verbose ufw allow 8080/tcp
CSF (often on cPanel servers): add the port to TCP_IN in /etc/csf/csf.conf and run csf -r. If only one client fails, check whether its IP address was blocked: csf -g 198.51.100.7, and remove the block with csf -dr 198.51.100.7.
To see every rule, whichever tool created it: nft list ruleset.
5. SELinux (AlmaLinux, Rocky Linux, RHEL)
If a service will not start on a non-standard port, SELinux may block it. Check ausearch -m avc -ts recent, then allow the port for that kind of service, for example for a web server:
semanage port -a -t http_port_t -p tcp 8081
6. Test from outside
nc -zv 203.0.113.10 8080
Run this from another machine. If it times out while the server-side checks all pass, look for a firewall outside the server, for example at your own office or in a cloud security group.
If this happens on a Ucartz server and you cannot find the cause, open a support ticket with the output of steps 2 and 6.
Official documentation: firewalld documentation and ss manual page.
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
