Curl连接80/443端口被拒,curl_exec调用失败求助
post_to_callback Function Let’s dive into targeted troubleshooting steps for your issue—since this function worked reliably for months and only broke yesterday (while the URL loads fine in a browser), the problem is almost certainly tied to an environmental or network change, not core code logic. Here’s where to focus:
1. Validate Server-Level Network Restrictions
- Firewall/iptables Rules: Your application server may have had new firewall rules added (or existing ones modified) yesterday that block outbound traffic to
www.domain.co.zaon ports 80/443. Run commands likeiptables -L -n(Linux) or check your cloud provider’s firewall settings (AWS Security Groups, Azure NSGs) to confirm these ports are allowed for outbound requests. - Proxy Configuration: If your server uses a proxy for external requests, verify the proxy settings haven’t changed. Your browser might pick up system proxy settings automatically, but cURL in your function may rely on explicit configuration—check if
curl_setopt($ch, CURLOPT_PROXY, ...)is set correctly, or if system-wide proxy environment variables (HTTP_PROXY,HTTPS_PROXY) were altered.
2. Check Target Server IP Whitelisting
The www.domain.co.za server may have updated its IP whitelist and removed your application server’s public IP. Even though your browser (from a different IP) can access it, the target could be blocking requests from your app’s server. Reach out to the target service’s admin to confirm your server’s IP is still allowed, or test a cURL request from a machine with a known whitelisted IP to compare results.
3. Flush and Verify DNS Caching
- Your server might be caching an outdated IP for
www.domain.co.zathat’s no longer accepting connections. Flush the DNS cache on your server (e.g.,systemd-resolve --flush-cacheson systemd-based Linux, or restart the DNS service). - Compare the IP resolved by your server vs. your browser: run
nslookup www.domain.co.zaon your server and check if it matches the IP your browser uses (visible in the Network tab of browser dev tools). If they differ, your server is using a out-of-sync DNS resolver.
4. Add Verbose Logging to Your cURL Function
Since this is a private function, add verbose logging to get granular details about what cURL is doing during the connection attempt. Insert this code before curl_exec:
curl_setopt($ch, CURLOPT_VERBOSE, true); $verboseLog = fopen('php://temp', 'w+'); curl_setopt($ch, CURLOPT_STDERR, $verboseLog); // After curl_exec runs: rewind($verboseLog); $logContent = stream_get_contents($verboseLog); error_log('cURL Detailed Log: ' . $logContent);
This log will show exactly where the connection fails—whether it’s DNS resolution, a handshake error, or a direct refusal from the target.
5. Test Connectivity Outside of PHP
Rule out code-specific issues by testing port connectivity directly from your server:
- Run
telnet www.domain.co.za 443ornc -zv www.domain.co.za 443to check if port 443 is reachable. If these commands fail, the problem is network-level (not with your PHP function). - If port 80 fails but 443 works, the target may have deprecated plain HTTP—ensure your function uses
https://instead ofhttp://and enables redirect handling withcurl_setopt($ch, CURLOPT_FOLLOWLOCATION, true).
6. Check for Recent Server Environment Updates
Did your server get updated (OS, PHP, or cURL library) yesterday? A new cURL version might enforce stricter SSL settings or introduce compatibility bugs. Check your server’s update logs (e.g., /var/log/apt/history.log on Debian/Ubuntu) to see if cURL or PHP was upgraded, and test rolling back to the previous version temporarily if possible.
内容的提问来源于stack exchange,提问作者anthonytherockjohnson

