ERR_CONNECTION_RESET: what cuts the connection and how to fix it

Something hung up mid-connection. The causes on the visitor's side and the server's: crashes, firewalls, keep-alive mismatches and TLS problems.

· 3 min read · By the Spot Downtime team

ERR_CONNECTION_RESET (“The connection was reset”) means the connection was open, and then something abruptly cut it by sending a TCP reset. Unlike a refused or timed-out connection, the server was reachable. Something along the way, or the server itself, decided to hang up.

For visitors

If only you see it, something on your side is interfering:

  • VPN, proxy or antivirus. Security software that inspects HTTPS traffic resets connections it doesn't like. Disable it briefly to test.
  • A network that filters sites: workplace, school or some country-level filtering resets connections to blocked domains.
  • Router trouble. Restarting the router fixes more of these than it should.
Is it down for everyone?Check from outside your network whether the site loads for everyone else.

For site owners

The app crashed mid-request

A worker that segfaults, gets killed for using too much memory, or restarts during a deploy drops its open connections. Look for crashes and restarts at the same times.

A firewall, WAF or IPS cuts it

Intrusion prevention systems reset connections that match a rule, often on request size or content. Check firewall logs for blocked connections matching the failing requests.

Timeouts that don't match

A load balancer keeps idle connections open for 60 seconds, but the server behind it closes them after 5. The balancer reuses a connection the server already closed and gets a reset. Make the backend's keep-alive timeout longer than the load balancer's.

TLS problems

Some servers reset the connection when the TLS handshake fails, for example when the client only supports older protocols, or when no certificate matches the hostname.

bash
curl -v https://example.com/ 2>&1 | tail -n 20
# "Connection reset by peer" after "Client hello" points to TLS;
# after the request was sent points to the app or a firewall.
SSL certificate checkerCheck whether the HTTPS handshake succeeds and the certificate is valid.Open port checkerConfirm the port accepts connections from the internet at all.

Intermittent resets

Resets that happen to a few percent of requests usually come from keep-alive mismatches or workers being recycled. They're easy to miss by hand. Frequent outside checks, with every failure logged, show whether they cluster around deploys, peaks or specific times.

Related: ERR_EMPTY_RESPONSE is when the connection closes without a reset or any data, and ERR_SSL_PROTOCOL_ERROR covers handshake failures in detail.

Keep reading