Debian 9下Docker配置求助:无法通过域名访问主机
sitename.loc DNS Resolution Issue on Debian 9 with Docker Hey there! Let's work through why your sitename.loc domain isn't resolving, even though you can reach the host via its IP (172.18.0.7). The errors you’re seeing—ERR_NAME_NOT_RESOLVED and DNS_PROBE_FINISHED_NXDOMAIN—point straight to a DNS resolution problem, so let’s start there before diving into iptables:
1. Check Local Hosts File (Quickest Fix for Local Domains)
.loc is a local-use domain that public DNS servers don’t recognize by default. If you’re accessing this from the same machine or a local network device, you probably need to manually map the domain to your host’s IP:
- On the device you’re using to access
sitename.loc, edit the hosts file:sudo nano /etc/hosts # For Linux/macOS # On Windows: Open C:\Windows\System32\drivers\etc\hosts with Notepad (run as admin) - Add this line at the bottom:
172.18.0.7 sitename.loc - Save the file, then try accessing the domain again. If this works, the issue was just a missing local DNS mapping.
2. Test DNS Resolution Directly
If the hosts file fix doesn’t work, let’s verify if your system can actually resolve the domain:
- Run these commands on your Debian 9 host to check DNS lookup:
nslookup sitename.loc dig sitename.loc - If both return
NXDOMAIN, your configured DNS servers have no record forsitename.loc. You have two options here:- Set up a local DNS server (like dnsmasq) on your network that can resolve
.locdomains to your host’s IP. - Add an A record pointing
sitename.locto172.18.0.7in your network’s main DNS server.
- Set up a local DNS server (like dnsmasq) on your network that can resolve
3. Check Docker's DNS Configuration
Docker sometimes modifies the host’s DNS settings, which could interfere with local domain resolution:
- Check your Debian host’s resolv.conf file:
cat /etc/resolv.conf - If you see Docker-specific DNS entries (like
127.0.0.11), override the DNS for your Docker services indocker-compose.ymlto use your local network DNS:services: your-service-name: # ... other service configs ... dns: - 192.168.1.1 # Replace with your local DNS server IP - 8.8.8.8 # Fallback to Google DNS - Recreate the containers with
docker-compose down && docker-compose up -dafter making this change.
4. Rule Out iptables (Less Likely, But Worth Checking)
Since you already disabled the firewall, iptables is probably not the culprit—but let’s confirm:
- List all iptables rules to check if DNS traffic (UDP port 53) is blocked:
iptables -L -n | grep 53 - If you see any
DROPrules targeting port 53, temporarily flush the rules to test:sudo iptables -F - Try accessing the domain again. If this works, adjust your iptables rules to allow DNS traffic permanently.
内容的提问来源于stack exchange,提问作者Juljan

