"No Route to Host" — Networking's Different Beast from Connection Refused

The host is reachable at the IP layer but nothing accepts or passes your connection: a REJECT firewall rule (as opposed to DROP's timeout), a bad route, or a down host in a routed setup.

What you'll see

Root causes

Firewall REJECT rules (local or intermediate)

Unlike DROP (timeout), REJECT actively refuses: iptables -j REJECT with reject-with icmp-port-unreachable surfaces as 'no route to host' to the client. Check both ends' rules.

Routing/ARP problems or off-host

Stale ARP, wrong gateway, Docker bridge misconfig after restart, or a cloud subnet route missing. ip route get <ip> shows the path your kernel would take.

Target service down (not listening, host suspended)

For k8s/Docker Networks: a container/pod not running while the IP persists in iptables → no-route for that specific VIP:port.

Fix it

  1. Distinguish REJECT from routing: can you reach the host at all?
    ping -c 2 <ip> ; ip route get <ip> ; ip neigh | grep <ip>
  2. Check firewall REJECT rules on both ends
    sudo iptables -L -n -v | grep -iE 'reject|<port>' ; sudo nft list ruleset | grep -i reject | head
  3. Fix the rule (allow instead of reject, or correct the port)
    # iptables -I INPUT -p tcp --dport <port> -j ACCEPT ; verify order: REJECT before ACCEPT still refuses
  4. Container/K8s VIP case: verify the service is actually up
    docker ps | grep <ct> ; kubectl get endpoints <svc>

Field note

Mental model: REFUSED = host says 'port closed'; NO ROUTE = something says 'can't get there' (reject rule or routing); TIMEOUT = silence (DROP). Each points at a different layer. Firewalld zones refusing a port also emit reject-with icmp — same client symptom, managed-layer fix (firewall-cmd --add-port).

Common questions

What's the difference from 'Connection refused'?

Refused reaches the host and gets an active TCP RST (nothing listening). No-route means the connection was refused en route — a firewall REJECT or routing failure before the app layer. Different fixes.

Why does only one port say no route?

Per-port REJECT rules: the host accepts your connections generally but that port's rule actively rejects. That selectivity is a firewall signature — routing problems break all ports equally.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.