The host is reachable at the IP layer but nothing accepts or passes your connection: a REJECT firewall rule (as opposed to DROP's timeout), a bad route, or a down host in a routed setup.
Unlike DROP (timeout), REJECT actively refuses: iptables -j REJECT with reject-with icmp-port-unreachable surfaces as 'no route to host' to the client. Check both ends' rules.
Stale ARP, wrong gateway, Docker bridge misconfig after restart, or a cloud subnet route missing. ip route get <ip> shows the path your kernel would take.
For k8s/Docker Networks: a container/pod not running while the IP persists in iptables → no-route for that specific VIP:port.
ping -c 2 <ip> ; ip route get <ip> ; ip neigh | grep <ip>
sudo iptables -L -n -v | grep -iE 'reject|<port>' ; sudo nft list ruleset | grep -i reject | head
# iptables -I INPUT -p tcp --dport <port> -j ACCEPT ; verify order: REJECT before ACCEPT still refuses
docker ps | grep <ct> ; kubectl get endpoints <svc>
Mental model: REFUSED = host says 'port closed'; NO ROUTE = something says 'can't get there' (reject rule or routing); TIMEOUT = silence (DROP). Each points at a different layer. Firewalld zones refusing a port also emit reject-with icmp — same client symptom, managed-layer fix (firewall-cmd --add-port).
Refused reaches the host and gets an active TCP RST (nothing listening). No-route means the connection was refused en route — a firewall REJECT or routing failure before the app layer. Different fixes.
Per-port REJECT rules: the host accepts your connections generally but that port's rule actively rejects. That selectivity is a firewall signature — routing problems break all ports equally.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.