请求协助:获取Linux服务器软件更新时连接的URL及端口列表
Hey there, let's figure out how to get those URLs and ports you need for your Linux server updates. The problem with netstat is that it only shows low-level IP/port info—URLs live in the application layer (HTTP/HTTPS), so we need tools that can peek into that traffic or track the update process directly. Here are your best options:
tcpdump + tshark This method lets you record actual network traffic during an update and extract the URLs/ports:
- First, start capturing traffic on common update ports (80 for HTTP, 443 for HTTPS):
tcpdump -i any port 80 or port 443 -w update_traffic.pcap - Run your update command (e.g.,
apt update,dnf update) in another terminal. Once it finishes, stoptcpdumpwithCtrl+C. - Use
tshark(Wireshark's command-line tool) to parse the capture. For HTTPS traffic, we can extract the SNI (Server Name Indication) which tells us the domain being accessed:tshark -r update_traffic.pcap -T fields -e ssl.handshake.extensions_server_name -e tcp.dstport | grep -v "^$" - For HTTP traffic, you can get the full URL directly:
tshark -r update_traffic.pcap -T fields -e http.request.full_uri -e tcp.dstport | grep -v "^$"
strace strace monitors system calls made by the update process, including domain lookups and network connections:
- Run your update command wrapped in
straceto filter network-related calls:
(Replacestrace -e trace=network apt update 2>&1 | grep -E "(connect|getaddrinfo)"apt updatewithyum updateordnf updatedepending on your distro.) - The output will show you the exact domains (e.g.,
deb.debian.org) and ports (e.g.,443) the process is connecting to. If you need to track a running update process, usestrace -p <PID>where<PID>is the process ID of your update tool.
Most Linux update tools log or store their repository URLs directly—this is often the easiest way:
- Debian/Ubuntu (apt):
- Check logs for recent update URLs:
cat /var/log/apt/term.log | grep -E "(GET|POST|https?://)" - View configured repositories directly:
cat /etc/apt/sources.list /etc/apt/sources.list.d/*.list
- Check logs for recent update URLs:
- RHEL/CentOS/Fedora (yum/dnf):
- Check logs:
cat /var/log/dnf.log | grep -E "https?://" - View repo configs:
ls /etc/yum.repos.d/ && cat /etc/yum.repos.d/*.repo
- Check logs:
- Ports are usually default (80 for HTTP, 443 for HTTPS) unless the URL explicitly specifies a custom port (e.g.,
https://repo.example.com:8443).
ss + Reverse DNS While ss (a modern replacement for netstat) doesn't show URLs, it can link connections to update processes, which you can then map to domains:
- List active connections tied to update tools:
ss -tulpn | grep -E "(apt|yum|dnf)" - For each IP address shown, run a reverse DNS lookup to get the domain:
nslookup <IP_ADDRESS> # Or use dig for more detail dig -x <IP_ADDRESS> - Note: This method is less reliable than the others, since one IP can host multiple domains, but it's a quick fallback if you can't run a full capture.
内容的提问来源于stack exchange,提问作者Simon Dunning

