TCP, ports, and sockets
What it means for a service to listen, and how refusals and timeouts tell you different things.
A socket is an address, a port, and a program
A server program asks the kernel for a socket, binds it to a local address and port, and listens. Clients connect to that address and port. The kernel completes the TCP handshake and the program accepts the connection. Beej's guide shows the same sequence from inside the program: socket(), bind(), listen(), accept().
The bind address is the decision operators most often get wrong:
| Bind | Who can connect |
|---|---|
127.0.0.1:8080 |
Only processes on this host, using the loopback address |
10.0.4.12:8080 |
Clients that reach the host at that one address |
0.0.0.0:8080 |
Clients using any IPv4 address of the host |
[::]:8080 |
Any IPv6 address (and often IPv4 too, depending on settings) |
Development defaults usually bind to loopback for safety. Deployed unchanged, the service then passes every local health check and is unreachable from its proxy. That is the incident in the localhost-is-not-public lab.
Reading the listener table
ss -ltnp lists TCP listeners with their bind address, port, and owning process. Read it before you blame the network:
State Local Address:Port Process
LISTEN 127.0.0.1:8080 users:(("waybill",pid=4121,fd=7))
The first column of interest is the local address. 127.0.0.1 here already explains a remote "connection refused".
The handshake and its cost
TCP opens a connection with three segments: the client sends SYN, the server replies SYN-ACK, and the client sends ACK. That costs one round trip before the request can travel. High Performance Browser Networking builds a whole argument on this. With 80 ms of round-trip time, every new connection adds at least 80 ms before the first byte of the request, and TLS adds more. Connection reuse (keep-alive, pooling) is therefore a performance feature, and a proxy that opens a fresh upstream connection per request pays this cost every time.
Failures have shapes
The way a connection fails tells you where to look:
- Connection refused: the target host answered with a reset. The route works. Nothing listens on that address and port, or a firewall actively rejects.
- Timed out: silence. Packets were dropped by a firewall, a wrong route, or a host that is down. Look at the path, not the process.
- Connection reset mid-request: something closed the connection abruptly, such as a crashing process, a proxy timeout, or a middlebox.
- No route to host: the local routing decision or an ICMP reply says the destination is unreachable.
Treat the error text as data. "Refused in 2 ms" and "timed out after 75 s" exclude different halves of the system.
Verify from the user's side
A check run on the server against 127.0.0.1 is the narrowest possible test. After any change, repeat the request the way a customer makes it: the public name, through the proxy, from another host. The labs score you on that final state, not on the loopback check.
Key terms
- Socket
- An endpoint for communication, identified for TCP by address and port. A connection is a pair of them.
- Bind address
- The local address a listening socket accepts connections on.
127.0.0.1means local only.0.0.0.0means every IPv4 address on the host. - Connection refused
- The destination host answered with a reset because nothing listens on that address and port. The network path works.
- Timeout
- No answer at all. Something dropped the packets, such as a firewall, a wrong route, or a dead host.
Read further
- Beej's Guide to Network Programming, Sections "What is a socket?" and "System Calls or Bust" (`bind()`, `listen()`, `accept()`, `connect()`) (Free to read online)
What a socket is from a program's side, and whatbind()to a specific address means compared withINADDR_ANY. Read the example servers to see the call sequence. - High Performance Browser Networking, Ch. 2, "Building Blocks of TCP" (Free to read online)
The three-way handshake and its cost in round trips, and why new connections are slow at first (slow start). This is the latency view an operator needs. - TCP/IP Illustrated, Volume 1, 2nd edition, Ch. 13, "TCP Connection Management" (Purchase)
Connection establishment and teardown, the TCP state diagram, and how a host answers a connection to a port with no listener (a reset).