connect: No route to host (EHOSTUNREACH)
The destination host isn’t reachable — it’s down, on another subnet without routing, or a firewall rejects with “host unreachable”.
Seen on:
Linux
Meaning
Unlike “network unreachable”, the network exists but the host doesn’t answer ARP, or a firewall (firewalld default REJECT) sends ICMP host-prohibited. Very common with firewalld blocking a port on RHEL/CentOS.
Common causes
- firewalld/iptables REJECT rule on the target (icmp-host-prohibited)
- Target machine down or wrong IP
- Different VLAN/subnet without a route
- Cloud security group/NACL
⚡ Quick fix
- Open the port on the target: firewall-cmd --add-port
- Verify the IP and that the host is up
- Check routing between subnets
Detailed fix by platform
RHEL
- bash
sudo firewall-cmd --permanent --add-port=8080/tcp sudo firewall-cmd --reload
Linux
- bash
nc -vz 10.0.0.5 8080 ip route get 10.0.0.5
How to diagnose
- Host — Up and correct IP?
- Firewall — firewall-cmd --list-all on the target
- Route — ip route get
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Linux
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026