Ubuntu 17.10 DNS需根服务器响应的设计合理性咨询
Ubuntu 17.10 Default DNS Root Server Fallback Behavior
Yes, this is absolutely a default system behavior in Ubuntu 17.10, driven by the systemd-resolved service which was the default DNS resolver for that release. Let me break down what's happening:
- Ubuntu 17.10 uses
systemd-resolvedto handle all DNS resolution on the system. By default, this service runs a local stub resolver (listening on 127.0.0.53) that acts as the middleman for all DNS queries from apps and the OS itself. - When a DNS query comes in,
systemd-resolvedfirst tries to use your explicitly configured internal DNS server (192.168.1.50). However, if it encounters any issues communicating with that server—including if outgoing DNS requests from your Ubuntu system are blocked by the firewall—it falls back to directly querying root DNS servers (like a.root-servers.net) as a last-ditch effort to resolve the domain. - Your firewall rule only allows the internal DNS server to initiate DNS requests, so when
systemd-resolvedtries this fallback to root servers, those outgoing requests get blocked. The service interprets this as a complete DNS failure, which is why your system refuses to load internet resources. - When you allow the Ubuntu system to initiate its own DNS requests, both the initial query to your internal DNS and any fallback attempts (if needed) can go through, so resolution works normally again.
How to Disable This Fallback (If Needed)
If you want to align the system's behavior with your firewall rules and prevent it from querying root servers directly, you can adjust the systemd-resolved configuration:
- Open the resolved config file with your preferred editor:
sudo nano /etc/systemd/resolved.conf - Look for the
FallbackDNSline, uncomment it, and set it to your internal DNS server (to override the default fallback list):FallbackDNS=192.168.1.50 - Alternatively, you can disable the stub resolver entirely if you prefer to use your internal DNS directly (note this may affect other systemd integrations):
DNSStubListener=no - Save the file and restart the service to apply changes:
sudo systemctl restart systemd-resolved
内容的提问来源于stack exchange,提问作者user799575
相关产品推荐
相关产品推荐

