The application runs, answers on the server itself, and does not open from outside. In almost every case it is one of three things: the application only listens on 127.0.0.1, the firewall does not let the port through, or the request never arrives because of DNS or a proxy. Working out which is done from the inside out, and it is quick. This article is for a VPS with root access.
From the inside out, in order
| 1 |
Is the application listening, and where? sudo ss -tlnpFind the port. The address on the left says it all: 127.0.0.1:3000 only accepts requests from the server itself; 0.0.0.0:3000 (or *:3000) accepts from anywhere. If the port does not even appear, the application is not running.
|
|
| 2 |
Does it answer on the server itself? curl -I http://127.0.0.1:3000. If it does not answer here, the problem is the application, not the network.
|
|
| 3 |
Look at the firewall: sudo ufw status verboseIf it says “inactive”, ufw is not what is blocking. If it is active and the port is not listed, that is the block.
|
|
| 4 |
Test from outside, from another computer or a phone: curl -I http://VPS-IP:3000. Or, with nc: nc -zv VPS-IP 3000.
|
|
| 5 |
If you go by name, check the DNS and that the A record points at this VPS: checking the DNS.
|
|
What the message says
| From outside, you see |
It means |
What to do |
| “Connection refused” |
The request reached the server and nobody answered on that port (or it was rejected). |
The application is not running, or listens only on 127.0.0.1. See step 1. |
| It waits, then “timed out” |
The request was dropped on the way. Usually the firewall. |
Open the port (see below) and repeat the test. |
| Works by IP, not by name |
DNS does not point at this server, or has not propagated. |
Check the A record: how long DNS takes. |
| Works on HTTP, not on HTTPS |
Port 443 is closed, or the certificate is missing. |
Open 443 and see HTTPS for a container. |
Opening a port, by system
| System |
Open port 8080 |
Check |
| Ubuntu and Debian (ufw) |
sudo ufw allow 8080/tcp |
sudo ufw status verbose |
| AlmaLinux and Rocky (firewalld) |
sudo firewall-cmd --permanent --add-port=8080/tcp and then sudo firewall-cmd --reload |
sudo firewall-cmd --list-all |
If you are switching on ufw for the first time, do it in this order, or you close SSH’s own port and lock yourself out of your server: sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enableOpenSSH assumes port 22. If your SSH uses another, open that one.
|
Docker steps around ufw. A port published by a container (-p 8080:80) is open to the world even if ufw did not allow it, because Docker writes its own rules. To keep it on the server only, publish on 127.0.0.1 (-p 127.0.0.1:8080:80) and put a proxy with HTTPS in front: nginx as a reverse proxy.
|
|
Open only what you need. Database ports (MySQL, PostgreSQL) should not be open to the world. To reach them from outside, use a tunnel: SSH tunnel. The six basic precautions are in keeping a VPS secure.
|
After opening the port on the server, there may still be another barrier outside it, if your environment has an additional firewall configured. If the test from outside still says “timed out” with the port open and the application listening on 0.0.0.0, tell us: we check the network side. Installing and configuring the firewall inside the server is yours: how far our support goes.
|
|
Did the inside-out test and the port still does not answer? Send us the VPS IP, the port, and the result of ss -tlnp and of the test from outside.
Open a support ticket
|
RECOMMENDED PRODUCT VPS server with root access Resources of your own, the OS you choose, reinstall whenever you like. from $7.61/mo (3-year plan, with coupon) See plans |