LogLens AI / Errors / connection refused

Connection refused: what it means and how to fix it

TL;DR. Connection refused (ECONNREFUSED) means your client reached the host but nothing was listening on that port — the service is down, bound to a different address/port, or a firewall actively rejected the packet.

What causes connection refused

The target service is not running or crashed; it is listening on 127.0.0.1 instead of 0.0.0.0 so it only accepts local connections; the client is using the wrong port; or a firewall/security group is sending a TCP reset. Unlike a timeout, "refused" means a machine answered and said no.

How to diagnose it

Check the service is up and listening: ss -ltnp | grep <port> (or netstat -ltnp). Test reachability: curl -v http://host:port or nc -vz host port. If it listens on 127.0.0.1 only, remote clients get refused.

How to fix connection refused

  1. Confirm the service is running. Start or restart it and verify it stays up — a crash loop produces intermittent refusals.
  2. Check the bind address and port. Make it listen on 0.0.0.0 (all interfaces) if remote clients connect, and confirm client and server agree on the port.
  3. Open the firewall / security group. Allow the port in ufw/iptables, the cloud security group, or the Kubernetes NetworkPolicy/Service.

Example log line

dial tcp 10.0.0.12:5432: connect: connection refused

How LogLens detects connection refused

LogLens flags repeated connection-refused bursts and the restart pattern behind them. LogLens AI is a free, self-hosted AI log analyzer that surfaces lines like this automatically, groups them into one incident, and explains them in plain language.

Install LogLensSee the tour

Related errors

FAQ

What is the difference between connection refused and connection timed out?

Refused means a host answered and rejected the connection (nothing listening / firewall reset). Timed out means no answer at all — usually a wrong host, a dropped packet, or a firewall silently discarding traffic.

Why does connection refused happen only remotely?

The service is almost certainly bound to 127.0.0.1 (localhost only). Bind it to 0.0.0.0 so it accepts connections from other hosts.