Home / Alt manpages / protocols(5)

  • protocols(5)
  • File format
  • linux

Read and Safely Audit /etc/protocols with getent

You will finish with a safe way to inspect the Linux protocol-name database, look up names and numbers through the system's configured name service, and recognise when local data needs investigation. The examples use the protocols(5) manpage from Linux man-pages 6.7, installed here from package manpages 6.7-2.

Allow about ten minutes. You need a shell and an ordinary account. This guide reads configuration and performs lookups only. It does not edit /etc/protocols, reload networking or send packets, so none of the commands need sudo.

1. Confirm the file and the installed contract

Start by checking that the file exists and reading the local manual. This avoids assuming that a different Unix implementation uses the same format:

$ command -v getent
/usr/bin/getent
$ dpkg-query -W -f='${Package} ${Version}\n' manpages
manpages 6.7-2
$ man 5 protocols

The manual describes /etc/protocols as a plain ASCII file for the protocols available to the TCP/IP subsystem. Its entries supply protocol information used in IP headers. The file is not a firewall policy and it does not enable or disable a protocol.

Checkpoint

You are working with the installed protocols(5) definition, not with a guessed format from another operating system.

2. Inspect entries without changing them

Read the file as an unprivileged user. The first field is the native protocol name, the second is its official number, and later fields are optional aliases:

$ sed -n '1,18p' /etc/protocols
# Internet (IP) protocols
#
# Updated from http://www.iana.org/assignments/protocol-numbers and other
...
icmp    1    ICMP    # internet control message protocol
tcp     6    TCP     # transmission control protocol
udp     17   UDP     # user datagram protocol

Your header and spacing may differ. Empty lines are ignored. A hash mark starts a comment, so the comment is not part of the protocol name, number or aliases. Spaces and tabs separate fields; do not treat the columns as fixed-width text.

Use a filtered view when you need one family of entries:

$ awk '!/^([[:space:]]*#|[[:space:]]*$)/ && ($1 == "icmp" || $1 == "tcp" || $1 == "udp")' /etc/protocols
icmp    1    ICMP    # internet control message protocol
tcp     6    TCP     # transmission control protocol
udp     17   UDP     # user datagram protocol

This command only prints matching lines. It does not validate that a number is currently assigned by IANA, and it does not prove that another machine has the same file.

3. Query the configured protocols database

For a program-facing check, use getent. It asks the Name Service Switch for the protocols database, which commonly includes /etc/protocols but can be configured differently. Query by name:

$ getent protocols tcp
tcp                   6 TCP
$ getent protocols udp
udp                   17 UDP
$ getent protocols icmp
icmp                  1 ICMP

Column spacing is presentation, not a value to parse by character position. The useful fields are the name, decimal number and aliases. The exact output can vary with the configured NSS sources.

Numbers work on this machine too:

$ getent protocols 6
tcp                   6 TCP
$ getent protocols 17
udp                   17 UDP

Check the exit status when scripting rather than relying on displayed text:

$ if getent protocols tcp >/dev/null; then
>     echo 'tcp is resolvable'
> else
>     echo 'tcp was not found' >&2
>     exit 1
> fi
tcp is resolvable

4. Distinguish local data from an authoritative assignment

The local file is operational input for name lookups, but protocol numbers are assigned by IANA. A local line can be stale, customised or present for a kernel-specific purpose. Conversely, the IANA registry can contain assignments that have not been copied into this host's file. Compare the decimal number and keyword with the IANA Protocol Numbers registry when reviewing a discrepancy.

Do not replace a local name with a number just because both appear familiar. The number is the value that appears in the IP header, while the name and aliases are the local lookup vocabulary. Applications should use the system lookup interfaces or getent, not hard-coded guesses.

For a quick comparison of common entries:

$ getent protocols tcp udp icmp
tcp                   6 TCP
udp                   17 UDP
icmp                  1 ICMP

If your implementation accepts only one key per invocation, run the three commands separately. Treat an absent result as a lookup failure, not as permission to invent a new number.

5. Do not edit /etc/protocols casually

The installed manual explicitly says to keep this file untouched because changes can result in incorrect IP packets. That is the key safety boundary. Editing a line can make software translate a name to the wrong number, or make different machines interpret the same name differently. It does not create a new protocol assignment.

Before any proposed change, record the current file and identify the application and authoritative source that require it. A privileged edit would also need a maintenance and rollback plan:

$ cp --preserve=all /etc/protocols /path/to/secure-backup/protocols.before-change
$ diff -u /etc/protocols /path/to/proposed-protocols

The first command requires permission to read /etc/protocols and write the chosen backup directory. Do not paste that placeholder path as-is. If a change has already caused trouble, restore only a known-good backup after checking its ownership and contents, then rerun the getent checks. Restoring the file does not undo packets already sent or repair applications that cached old results, so restart only the affected application when its own documentation requires it.

6. Diagnose the usual distractions

  • No output: the requested key was not found in the configured protocols database. Check spelling, case and the NSS configuration before inspecting a different machine.
  • Different aliases: aliases are optional and can differ between distributions. Use the native name and number returned by this host when diagnosing local software.
  • Unexpected entries: inspect /etc/protocols and the system's NSS configuration. Do not assume that getent read only this file.
  • Permission errors: fix the read permission or access path through normal administration. Do not make the file world-writable.

Keep packet capture and firewall testing separate from this file audit. A successful lookup says that a name-to-number record is available; it says nothing about routes, sockets, firewall rules or whether a peer supports the protocol.

Done means

  • You confirmed the installed protocols(5) version and file path.
  • You can read the three-field entry format and recognise comments and aliases.
  • getent protocols tcp, udp and icmp return the expected local records.
  • You check IANA when an assignment or number is in doubt.
  • You have not edited /etc/protocols or confused lookup data with firewall or network policy.