VNC connection refused: checks for TigerVNC on Ubuntu

Start by checking the server’s listening address and port. Record the listening address and port, and the destination entered in the viewer.

What does connection refused mean?

On Linux, a refused connection can mean that no process is listening at the remote address. A timeout means the connection attempt exceeded its timeout. The Linux man-pages project’s connect(2), man-pages 6.19 (8 Feb 2026) describes these as ECONNREFUSED and ETIMEDOUT.

Listening TCP sockets

Read the local address and port. In sudo ss -tlnp, -t selects TCP, -l selects listeners, -n shows numeric addresses and ports, and -p requests process information. Inspect the full list; do not infer that the server is stopped from an empty grep 590 result.

If your configured session uses display :1 with its default port, look for a listener on 5901. If that session is stopped, start it from its configured user account on the remote machine, then check the sockets again:

$ vncserver :1
$ sudo ss -tlnp

The Ubuntu wrapper’s startup message begins New Xtigervnc server and gives the display and port. For display :1 at its default port, confirm a LISTEN entry on 5901 and record its address before continuing. If startup fails, read the log path reported by the wrapper, ~/.vnc/<host>:<display#>.log. If the expected listener is still absent, stop here and resolve startup before changing the firewall.

Evidence: Ubuntu noble TigerVNC source package, build 1.13.1+dfsg-2build2, debian/helpers/usr/share/man/man1/tigervncserver.1 and debian/helpers/usr/share/perl5/TigerVNC/Wrapper.pm; Linux man-pages project, ss(8).

Network binding

If the listener is 127.0.0.1:5901, the address is local to the server. Source: Ubuntu noble tigervncserver(1), build 1.13.1+dfsg-2build2, debian/helpers/usr/share/man/man1/tigervncserver.1, -localhost.

For an existing SSH forward from viewer-machine port 5901 to server-side localhost:5901, use localhost::5901 in TigerVNC vncviewer 1.13.1 on the viewer machine. Here, localhost is the viewer machine’s end of that existing forward. The forwarding syntax is documented in OpenBSD ssh(1), -L; the explicit-port viewer syntax is in TigerVNC v1.13.1, common/rfb/Hostname.h.

This section checks an existing connection path. For tunnel setup, see the VNC over SSH walkthrough. If you have no working tunnel, stop this branch before trying the viewer target.

Destination and port

For TigerVNC 1.13.1+dfsg-2build2 on Ubuntu 24.04 LTS, the default port is 5900 plus the display number: :1 uses 5901 and :2 uses 5902. Check the actual listener if a different port was configured. Source: Ubuntu noble tigervncserver(1), build 1.13.1+dfsg-2build2, debian/helpers/usr/share/man/man1/tigervncserver.1.

The following address forms apply to TigerVNC vncviewer 1.13.1. Replace host with the intended destination:

You type TigerVNC vncviewer connects to
host:1 Port 5901 (display notation)
host:5901 Port 5901 (port notation)
host::5901 Port 5901 (explicit port, double colon)

In TigerVNC vncviewer, use the double-colon form to specify the port explicitly. Match the target to the connection path: the remote listener for a direct connection, or the viewer machine’s local endpoint for an existing SSH forward. The localhost section identifies that endpoint.

Firewall rule changes

A listener check does not settle the firewall question. The nftables manual documents a reject statement that can return a TCP reset or an ICMP error. See the Netfilter project’s nftables manual, REJECT STATEMENT (document date: 07/02/2026).

If the listener and viewer target agree but the connection is still refused, ask the server or network administrator to inspect rejection rules for that destination address and port. Provide the listening address, destination port, and exact error.

Restrict VNC to your network

Keep VNC on your trusted LAN, VPN or authenticated tunnel. For a host already using UFW, this example allows TCP 5901 (display :1 at its default port) from your LAN subnet. Replace 192.168.1.0/24 with your actual subnet, and confirm the server’s configured port before using it.

  1. Add the LAN allow rule: sudo ufw allow from 192.168.1.0/24 to any port 5901 proto tcp
  2. After the allow rule, add the deny rule for TCP 5900–5910 from anywhere: sudo ufw deny proto tcp from any to any port 5900:5910
  3. Inspect the rules: sudo ufw status numbered

Have the administrator review existing rules and verify access from both an intended client and outside the allowed subnet. Never forward TCP 5900 from an internet router to the Pi. For a Pi listening on 5900, use the range alternative below only if both ports should be allowed; this display :1 example does not enable access to 5900.

Test this on your own host before relying on it.

If you need both ports

Replace the single-port allow step above with sudo ufw allow from 192.168.1.0/24 to any port 5900:5901 proto tcp. Replace the subnet with your actual LAN subnet. Then follow the deny and inspection steps above. Use this alternative only when you intend to allow both TCP 5900 and 5901.

Test this on your own host before relying on it.

For hosts using firewalld

This is a subnet allow example for TCP 5901. Replace the subnet with your LAN subnet:

sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="5901" protocol="tcp" accept'

Then run sudo firewall-cmd --reload.

Ask the administrator to review the active zone and existing rules and verify that other sources cannot reach VNC. This allow rule alone does not establish exclusive access.

Test this on your own host before relying on it.

Checks and limits

  1. On the server, run sudo ss -tlnp and record the listener’s address and port. If the configured session is stopped, use the existing-session startup check and verify the result before proceeding.
  2. Compare the actual port with the target entered in TigerVNC vncviewer 1.13.1. For a direct connection to port 5901, use host::5901, replacing host with the remote machine.
  3. For the existing SSH forward described in the localhost section, use localhost::5901 on the viewer machine instead. Do not substitute the remote hostname into that target.
  4. Retry the same connection path and record whether the refusal remains. If it does, take the listener address, port, and exact error to the administrator or the community thread below. Stop here rather than opening a port to clear the error.

Still stuck? Compare your result with the connection-refused community thread. If you post, include your operating system, server and viewer versions, and the check that failed. Keep passwords and private account details out of public posts; use the relevant provider’s official support route for private account matters.

Related guide: VNC black screen.

VNC.com editorial

community

Discuss this in the community

Connection refused from Windows viewer to Ubuntu 24.04

Keep passwords and private account details out of public replies.

Join the community

Sources accurate as of 30 September 2026.

Open-source VNC suits personal projects and home labs. When your business depends on remote access, RealVNC Connect adds end-to-end encryption, centralised management and commercial support from the team that created VNC.