# Fleet-server: dial tcp x.x.x.x:8220: connect: connection refused

**URL:** <https://discuss.elastic.co/t/fleet-server-dial-tcp-x-x-x-x-connect-connection-refused/309768>\
**Category:** Kibana\
**Tags:** fleet\
**Created:** [July 15, 2022, 8:16pm UTC](https://discuss.elastic.co/t/fleet-server-dial-tcp-x-x-x-x-connect-connection-refused/309768 "2022-07-15T20:16:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![thiavs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiavs/32/108170_2.png) [@thiavs](https://discuss.elastic.co/u/thiavs)\
**Post date:** [July 15, 2022, 8:16pm UTC](https://discuss.elastic.co/t/fleet-server-dial-tcp-x-x-x-x-connect-connection-refused/309768/1 "2022-07-15T20:16:40Z")

</div>

Guys, how are you? Good afternoon!! I'm having a little problem here setting for TLS stack, Elastic-Agent, Fleet and Elasticsearch, I can't close the connection with the fleet, I also see that the port is not listed in kibana.

 ![6618760a-a06d-46ce-8888-a619bc662300](https://us1.discourse-cdn.com/elastic/original/3X/9/7/973c86709cc98567e86a818a4b4fb860ae41bce1.jpeg)

The way below works, but I want to pass it with the tls parameters:

sudo ./elastic-agent install \   
--fleet-server-es=[https://192.168.30.20:9200](https://192.168.30.20:9200) \   
--fleet-server-service-token=AAEAAWVsYXN0aWMvZmxlZXQtc2VydmVyL3Rva2VuLTE2NTc3MzY4NDE4Mjc6SzJYa193WXVSMXUyemZmTkFQb3hrdw \   
--fleet-server-policy=48b18e60-02b7-11ed-83b8-3308383f28fd

If anyone helps, I'll be grateful!

---

<div class="post-metadata">

**Author:** ![MichelLaterman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michellaterman/32/110221_2.png) [@MichelLaterman](https://discuss.elastic.co/u/MichelLaterman)\
**Post date:** [July 18, 2022, 6:22pm UTC](https://discuss.elastic.co/t/fleet-server-dial-tcp-x-x-x-x-connect-connection-refused/309768/2 "2022-07-18T18:22:07Z")

</div>

Hi,

Is `192.168.30.40` the local address for `fleet.*.com.br`? Is there a firewall denying local connections? Do the logs from the fleet-server instance show any attempted connection?

---

<div class="post-metadata">

**Author:** ![thiavs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiavs/32/108170_2.png) [@thiavs](https://discuss.elastic.co/u/thiavs)\
**Post date:** [July 18, 2022, 7:30pm UTC](https://discuss.elastic.co/t/fleet-server-dial-tcp-x-x-x-x-connect-connection-refused/309768/3 "2022-07-18T19:30:16Z")

</div>

Hi

I configured the fleet.x.com.br domain within my /etc/hosts, the IP 192.168.30.40 is the fleet.x.com.br domain.

There is no connection coming from IP 192.168.30.40, there is no firewall between the machines, but port 8220 is not listed.

---

<div class="post-metadata">

**Author:** ![MichelLaterman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michellaterman/32/110221_2.png) [@MichelLaterman](https://discuss.elastic.co/u/MichelLaterman)\
**Post date:** [July 19, 2022, 1:15am UTC](https://discuss.elastic.co/t/fleet-server-dial-tcp-x-x-x-x-connect-connection-refused/309768/4 "2022-07-19T01:15:00Z")

</div>

OK, let's back up a little.

The commands you are running indicate that you are attempting to install the `fleet-server` running under the agent on a new host.  
You've stated that it can successfully install when you do not pass any parameters associated with TLS, but you get a connection failed error when you do.

The machine you are attempting to install `fleet-server` on is unable to connect to `192.168.30.40` (`fleet.X.com.br`). I'm assuming this is an already running a separate `fleet-server` instance, is that correct?  
`8220` is the default port for `fleet-server`.

Does the fleet-server cert/key you want to pass match the URL you are passing (`fleet.X.com.br`)?

What do you see in kibana? What hosts are listed under settings?

---

<div class="post-metadata">

**Author:** ![thiavs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiavs/32/108170_2.png) [@thiavs](https://discuss.elastic.co/u/thiavs)\
**Post date:** [July 19, 2022, 11:33am UTC](https://discuss.elastic.co/t/fleet-server-dial-tcp-x-x-x-x-connect-connection-refused/309768/5 "2022-07-19T11:33:45Z")

</div>

I will answer you according to the questions to facilitate understanding.

The commands you are running indicate that you are trying to install the fleet server running on the agent on a new host.

Answer: Agent installation is on another server

You've stated that it can install successfully when you don't pass any parameters associated with TLS, but you get a connection failure error when you do.

Answer: Exactly

The machine on which you are trying to install the fleet-server cannot connect to 192.168.30.40 (fleet.X.com.br). I'm assuming this one is already running a separate fleet server instance, is that correct?  
8220 is the default port for the fleet server.

Answer: I configured the fleet in the kibana panel (Plugin, port 8220, Ip: 0.0.0.0 I linked to the policy group. (That's all)

Does the fleet server certificate/key you want to pass match the URL you are passing (fleet.X.com.br)?

Answer: I took advantage of the elastic CA - http\_ca.crt and created the fleet.x.com.br certificates

What do you see in kibana? What hosts are listed in the settings?

Answer: Kibana creates the policy, I linked the fleet server plugin in the policy, enabled on port 8220 and listens 0.0.0.0, output to elastic and host on the fleet server [https://192.168.30.40](https://192.168.30.40)

---

<div class="post-metadata">

**Author:** ![MichelLaterman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michellaterman/32/110221_2.png) [@MichelLaterman](https://discuss.elastic.co/u/MichelLaterman)\
**Post date:** [July 19, 2022, 3:49pm UTC](https://discuss.elastic.co/t/fleet-server-dial-tcp-x-x-x-x-connect-connection-refused/309768/6 "2022-07-19T15:49:33Z")

</div>

> [@thiavs](#):
>
> Answer: Agent installation is on another server

That agent is running an instance of `fleet-server`?

On the instance you are running the install command, are you attempting to run another `fleet-server` or not?

> [@thiavs](#):
>
> Answer: I configured the fleet in the kibana panel (Plugin, port 8220, Ip: 0.0.0.0 I linked to the policy group. (That's all)

I think that this is an issue, the `fleet server hosts` setting in Kibana is passed to agents that enroll so they can find the `fleet-server`. In this case I would expect the setting to be `fleet.X.com.br` and all instances running the agent should be able to resolve the DNS entry.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2022, 4:20pm UTC](https://discuss.elastic.co/t/fleet-server-dial-tcp-x-x-x-x-connect-connection-refused/309768/8 "2022-08-16T16:20:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
