# Connection refused on Ubuntu

**URL:** <https://discuss.elastic.co/t/connection-refused-on-ubuntu/36418>\
**Category:** Elasticsearch\
**Created:** [December 4, 2015, 7:31pm UTC](https://discuss.elastic.co/t/connection-refused-on-ubuntu/36418 "2015-12-04T19:31:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![taq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taq/32/6428_2.png) [@taq](https://discuss.elastic.co/u/taq)\
**Post date:** [December 4, 2015, 7:31pm UTC](https://discuss.elastic.co/t/connection-refused-on-ubuntu/36418/1 "2015-12-04T19:31:55Z")

</div>

Guys,

I had an old install and it was not working. I got a "Connection refused" when trying

`$ curl -X GET http://localhost:9200`

So, I purged my install and installed it again (now with 2.x). After that, I must got the same message, no matter if I stop and start the service. So, after using `service elasticsearch start` and then

```auto
sudo -u elasticsearch /usr/share/elasticsearch/bin/elasticsearch -d -p /var/run/elasticsearch.pid --default.config=/etc/elasticsearch/elasticsearch.yml --default.path.home=/usr/share/elasticsearch --default.path.logs=/var/log/elasticsearch --default.path.data=/var/lib/elasticsearch --default.path.work=/tmp/elasticsearch --default.path.conf=/etc/elasticsearch

```

it worked, what I'm missing here? Seems that the Ubuntu services can't start it.

I also configured `elasticsearch.yml` with `network.host: localhost` and `http.port: 9200`.

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 4, 2015, 10:17pm UTC](https://discuss.elastic.co/t/connection-refused-on-ubuntu/36418/2 "2015-12-04T22:17:13Z")

</div>

> [@taq](#):
>
> network.host: localhost

There were some changes in 2.X, see [Networking | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-network.html)

But that should work. Can you start ES directly?

---

<div class="post-metadata">

**Author:** ![taq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taq/32/6428_2.png) [@taq](https://discuss.elastic.co/u/taq)\
**Post date:** [December 5, 2015, 1:43pm UTC](https://discuss.elastic.co/t/connection-refused-on-ubuntu/36418/3 "2015-12-05T13:43:55Z")

</div>

Hey, thanks for answering.

I noticed some of the changes, that's why I tried to change `elasticsearch.yml`, but didn't noticed that now `localhost` should be `_local_`, thanks!

So, first I tried to start it with the current configuration and tried to accesss with `curl` ... and it worked!:

```auto
$ sudo service elasticsearch start
$ sudo service elasticsearch status
● elasticsearch.service - Elasticsearch
   Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; disabled; vendor preset: enabled)
   Active: active (running) 
$ curl -X GET http://localhost:9200
{
  "name" : "Atalon",
  "cluster_name" : "elasticsearch",
  "version" : {
    "number" : "2.1.0",
    "build_hash" : "72cd1f1a3eee09505e036106146dc1949dc5dc87",
    "build_timestamp" : "2015-11-18T22:40:03Z",
    "build_snapshot" : false,
    "lucene_version" : "5.3.1"
  },
  "tagline" : "You Know, for Search"
}

```

Yesterday no matter what I did it won't start without the longer command line. But now I'm a different network (wireless now, cable yesterday), can have something related to it?

But, after changing `localhost` to `_local_`, I got the connection refused again. ☹  
Checking with `netstat`, I got some interesting results:

```auto
tcp6 0 0 ::1:9200 :::* OUÇA -               
tcp6 0 0 127.0.0.1:9200 :::* OUÇA -               
tcp6 0 0 ::1:9300 :::* OUÇA -    

```

So, I tried to use IPV6 and ...

```auto
$ curl -X GET http://[::1]:9200
{
  "name" : "Coldblood",
  "cluster_name" : "elasticsearch",
  "version" : {
    "number" : "2.1.0",
    "build_hash" : "72cd1f1a3eee09505e036106146dc1949dc5dc87",
    "build_timestamp" : "2015-11-18T22:40:03Z",
    "build_snapshot" : false,
    "lucene_version" : "5.3.1"
  },
  "tagline" : "You Know, for Search"
}

```

And after this, IPV4 worked again! Checking with `netstat` again, I got an interesing result on remote address (btw, "ouça" is "listen"):

```auto
tcp 0 0 127.0.0.1:58958 127.0.0.1:9200 TIME_WAIT -               
tcp6 0 0 ::1:9200 :::* OUÇA -               
tcp6 0 0 127.0.0.1:9200 :::* OUÇA -               
tcp6 0 0 ::1:9300 :::* OUÇA -               
tcp6 0 0 127.0.0.1:9300 :::* OUÇA -  

```

I tried `curl -X GET http://localhost:58958` too but got connection refused, but `localhost` and `127.0.0.1` works. Then I changed `network.host` to `_local:ipv4_` and checked again. On `netstat`, just IPV6:

```auto
tcp6 0 0 127.0.0.1:9200 :::* OUÇA -               
tcp6 0 0 127.0.0.1:9300 :::* OUÇA -    

```

But after the first `curl` request, seems that the remote address is bound, and it worked again!

```auto
tcp 0 0 127.0.0.1:59230 127.0.0.1:9200 TIME_WAIT -               
tcp6 0 0 127.0.0.1:9200 :::* OUÇA -               
tcp6 0 0 127.0.0.1:9300 :::* OUÇA -     

```

Not really sure what is happening. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:33pm UTC](https://discuss.elastic.co/t/connection-refused-on-ubuntu/36418/4 "2017-07-05T23:33:23Z")

</div>


