How to Fix ERR_CONNECTION_REFUSED in Google Chrome: Client & Server-Side Fixes

Fix the ERR_CONNECTION_REFUSED on Chrome
🗓️ Last Updated: October 2026
⏱️ 7 Min Read
🛡️ Peer-Reviewed & Production-Tested
✓ Expert Verified Quick Answer: Fixing ERR_CONNECTION_REFUSED

The ERR_CONNECTION_REFUSED error in Google Chrome indicates that the target web host actively rejected the TCP connection attempt on the specified port (typically port 80 or 443). On the client side, fix it by clearing Chrome browser cache, flushing OS DNS records, and disabling proxy extensions. On the server side, fix it by verifying that the web server (Nginx/Apache) is running, confirming listening ports with netstat, and adjusting firewall rules (UFW/iptables) to allow inbound HTTP/HTTPS traffic.

What Does ERR_CONNECTION_REFUSED Mean?

When you attempt to load a webpage in Google Chrome, your browser sends a TCP SYN packet to initiate a three-way network handshake. If the target machine receives the request but has no application listening on that port, or if a firewall intercepts the request, it responds with a TCP RST (reset) packet.

Chrome interprets this RST packet as ERR_CONNECTION_REFUSED. Unlike connection timeout errors (where the server fails to reply at all), a refused connection confirms the destination host is reachable, but actively declining connection attempts.

Whether you are an end user or managing an application on a high-performance cloud VPS, resolving this issue requires checking both client-side and server-side configurations.

Client-Side Solutions: Troubleshooting Local Device Settings

Before modifying server files, test client-side network factors that commonly produce false connection refusals.

1. Clear Chrome Browsing Data and Cache

Stale DNS entries and cached HTTP redirects can instruct Chrome to attempt connections on deprecated ports. Press Ctrl + Shift + Delete (or Cmd + Shift + Delete on macOS), select Cached images and files and Cookies, and click Clear data.

2. Flush Operating System DNS Cache

Corrupted local resolver caches route connection attempts to outdated IP addresses. Flush your local DNS cache by running the following command in an administrative PowerShell terminal:

ipconfig /flushdns

On macOS, open Terminal and execute sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder.

3. Disable Proxy Settings and VPN Extensions

Misconfigured local proxies or dead VPN tunnels frequently intercept outbound browser packets. Navigate to Chrome Settings > System > Open your computer’s proxy settings, and verify that “Automatically detect settings” is enabled while manual proxy servers are switched off.

Server-Side Solutions: Web Host and Firewall Diagnostics

If multiple visitors report ERR_CONNECTION_REFUSED simultaneously, the root cause resides on your web server.

Step 1: Check Web Server Daemon Status

The most common cause of refused connections is a stopped or crashed web server daemon. Connect to your host via SSH and verify service status:

# For Nginx servers
sudo systemctl status nginx

# For Apache servers
sudo systemctl status apache2

If the service is inactive or reported as failed, start it immediately using sudo systemctl restart nginx or sudo systemctl restart apache2.

Step 2: Verify Open Listening Ports (80 and 443)

Confirm that your web server is actively bound to public IPv4 and IPv6 network sockets on standard web ports. Execute:

sudo ss -tulpn | grep -E ':(80|443)'

You should see listening sockets associated with your web daemon process. If port 443 is missing, inspect your SSL configuration; an invalid or expired certificate can prevent the HTTPS listener from binding. Securing your domains with a validated SSL certificate ensures TLS listeners bind cleanly without crashing.

Step 3: Audit Firewall Rules (UFW / iptables)

Host firewalls actively reject connection attempts when inbound web traffic rules are missing. On Ubuntu/Debian servers utilizing UFW, inspect firewall status:

sudo ufw status verbose

If ports 80 and 443 are not explicitly allowed, execute the following commands to permit inbound web traffic:

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw reload

This ensures edge filtering devices allow incoming TCP handshakes through to your web daemon.

Step 4: Check Web Server Configuration Syntax

A typographical error in a virtual host file can cause web services to fail silently or fail to bind to secondary IP addresses. Always test configuration syntax before reloading:

# Nginx syntax verification
sudo nginx -t

# Apache syntax verification
sudo apachectl configtest

If errors are reported, open the corresponding configuration file, correct the syntax, and reload the service.

Furthermore, verify that your server is not exceeding system-wide open file limits. When high traffic surges hit default Linux configurations, exhaustion of available file descriptors prevents the kernel from accepting new TCP sockets, manifesting as connection refusals. If persistent firewall conflicts or complex multi-homed IP routing issues continue to reject connections, consulting a professional server administrator provides rapid root-cause diagnosis and remediation.

Regularly auditing network listener states with diagnostic utilities like netstat or ss ensures that all required daemon ports remain bound correctly after automated system package upgrades.

Server-Side Diagnostic Protocols: Investigating Port Listeners and Daemon Crashes

While Google Chrome displays the ERR_CONNECTION_REFUSED error on the user’s browser, the root cause frequently resides on the destination web server. This error indicates that a TCP connection request reached the server’s IP address, but the server explicitly rejected the connection by returning a TCP RST (reset) packet.

The most common server-side cause is that the web server daemon (such as Apache, Nginx, or Caddy) has crashed or failed to bind to public network interfaces. If Nginx is listening solely on 127.0.0.1:80 rather than 0.0.0.0:80, external visitors attempting to connect over the internet are immediately refused.

Administrators should connect via SSH and inspect active network sockets using ss -tulpn | grep -E ':(80|443)'. This command immediately reveals which processes are holding HTTP/HTTPS ports and confirms whether sockets are bound globally.

Verifying Firewall Rules and Port Filtering

Firewall misconfigurations can also prompt connection resets if incoming packets are rejected rather than silently dropped. Auditing both internal server firewalls and external cloud security groups ensures ports 80 and 443 remain unobstructed.

  • UFW Firewall Verification: Run sudo ufw status verbose and execute sudo ufw allow 'Nginx Full' to unblock web ports.
  • Iptables Filter Auditing: Inspect raw kernel tables with sudo iptables -L INPUT -v -n to check for aggressive reject rules.
  • Cloud Security Groups: Verify that cloud provider security groups (such as AWS, DigitalOcean, or Hetzner) permit inbound TCP traffic on ports 80 and 443.
  • SELinux and AppArmor Policies: Check audit logs for security profile denials preventing web daemons from binding to network ports.

Client-Side Troubleshooting: DNS Flushing, Proxy Bypasses, and Antivirus Conflicts

When the server is proven to be operational, client-side network caching and local security software are the primary culprits behind ERR_CONNECTION_REFUSED. Stale DNS records stored inside Windows or Chrome can point browsers to decommissioned server IP addresses.

Clearing Chrome’s internal socket pools and host resolver cache forces the browser to establish fresh TCP handshakes. Additionally, third-party antivirus suites frequently inject local proxy listeners that fail and sever web connectivity.

  • Chrome Internal DNS Flush: Navigate to chrome://net-internals/#dns and click “Clear host cache” to eliminate stale local mappings.
  • Chrome Socket Pool Reset: Go to chrome://net-internals/#sockets and click “Flush socket pools” to terminate hanging TCP sockets.
  • Windows TCP/IP Stack Reset: Open administrative Command Prompt and run netsh int ip reset && ipconfig /flushdns.
  • Disable Misconfigured Proxy Servers: Open Windows Settings > Network & Internet > Proxy and verify “Automatically detect settings” is enabled.

Verifying SSL/TLS Certificate Bindings and HTTPS Port Listeners

A frequent hidden cause of connection refused errors during HTTPS browsing is a missing or misconfigured SSL certificate binding. If your web server configuration directs traffic to port 443 but lacks valid cryptographic certificates, the daemon aborts TLS handshakes and closes the connection abruptly.

Testing certificate integrity using openssl s_client -connect yourdomain.com:443 -servername yourdomain.com verifies certificate validity directly from the terminal. Confirming that Let’s Encrypt certificates renew automatically via certbot cron jobs prevents certificate expiration from disrupting customer access.

Conclusion: Restoring Reliable Browser and Server Connectivity

The ERR_CONNECTION_REFUSED error is a clear indication that a network connection was rejected at the TCP transport layer. By systematically investigating both server-side daemon listeners and client-side network resolvers, administrators can pinpoint the precise point of failure.

Ensuring web daemons bind globally, keeping firewall ports open, and flushing client socket pools restores seamless connectivity, guaranteeing uninterrupted access for users and reliable operations for web platforms.

Frequently Asked Questions

What is the difference between ERR_CONNECTION_REFUSED and ERR_CONNECTION_TIMED_OUT?

ERR_CONNECTION_REFUSED occurs when the server actively sends a TCP RST packet rejecting connection. ERR_CONNECTION_TIMED_OUT occurs when no response packet is received at all, usually due to dropped packets or network outages.

Can antivirus software trigger ERR_CONNECTION_REFUSED in Chrome?

Yes. Desktop antivirus suites with web shields or firewall modules can block outbound port 80/443 traffic if they misclassify a website as malicious, presenting a connection refused error.

Why does my site work on HTTP but refuse connections on HTTPS?

This occurs when port 443 is blocked in the server firewall, or when the web server is not configured with an SSL/TLS virtual host block to listen on port 443.

How do I check if my website port is reachable externally?

You can use external port checking tools or run curl -Iv https://yourdomain.com from a remote terminal to observe the raw TCP connection handshake.

Will switching to Google DNS fix ERR_CONNECTION_REFUSED?

If your ISP’s DNS resolver is returning an incorrect or outdated IP address, switching to public DNS providers like Google (8.8.8.8) or Cloudflare (1.1.1.1) will resolve DNS propagation errors.

FINAL VERDICT & CONCLUSION Strategic Recommendation

Conclusion: Mastering Best Practices for How to Fix ERR_CONNECTION_REFUSED in Google Chrome: Client & Server-Side Fixes

Following structured server administration guidelines and methodically troubleshooting technical issues ensures your web infrastructure remains stable, performant, and secure under production workloads.

Eliminate technical bottlenecks and host your websites on high-availability cloud infrastructure. Discover Onlive Server fully managed VPS and dedicated server hosting for optimized server performance.

Naveen Rajput
✓ Verified Technical Author 16+ Years Experience in Enterprise Server Infrastructure & Bare-Metal Systems

Naveen Rajput (CEO & Infrastructure Architect)

Naveen Rajput is the CEO and Director of Onlive Server Private Limited. With over 16 years of hands-on expertise across global datacenters, high-throughput hypervisors, and disaster-recovery architectures, he provides production-tested server engineering insights to enterprise CTOs and system administrators worldwide.