服务器DNS解析临时失败,resolvectl显示网卡eno8403无当前DNS服务器求助
Hey Ralph, let's break down this DNS issue step by step—since you can ping 8.8.8.8 but not resolve domain names like google.com, we know this is strictly a DNS resolution problem, not a basic network connectivity issue.
First, looking at your resolvectl status output:
- The Global section shows a Current DNS Server of 8.8.8.8, but your eno8403 link (which has the DefaultRoute set) lists DNS servers but no "Current DNS Server" entry. That's a key clue, and here are some possible causes and fixes to try:
1. Check if systemd-resolved is running properly
First, verify the service itself isn't glitching. Run this command to check its status:
systemctl status systemd-resolved
Look for any error messages or warnings—if the service isn't active or has failed, restart it with:
sudo systemctl restart systemd-resolved
Then re-run resolvectl status to see if the Current DNS Server shows up for eno8403.
2. Verify netplan configuration for eno8403
Even if you think netplan looks okay, double-check for conflicts. Open your netplan config file (usually in /etc/netplan/) and make sure:
- The
dns-serverslist for eno8403 is correctly set (you have 172.31.102.1, 1.1.1.1, 8.8.8.8 listed) - There's no conflicting DHCP or static config that might be overriding DNS settings. For example, if you're using DHCP, ensure
dhcp4-overrides.dnsisn't set to ignore server-provided DNS.
After making any changes, apply the config with:
sudo netplan apply
Then check resolvectl status again.
3. Test if DNS ports are blocked by the firewall
Since your server is hosted at a Ministry, it's entirely possible their hardware firewall is blocking DNS traffic (default port UDP 53, sometimes TCP 53 for large queries). Test this directly by querying a DNS server manually with dig:
dig @8.8.8.8 google.com
If this command times out or returns no results, that's a strong sign port 53 is blocked. You'll need to reach out to the Ministry's IT team to confirm and request access to DNS ports.
If dig does return a valid response, then the issue is local to your server's DNS resolver setup.
4. Check resolv.conf configuration
Your resolvectl shows resolv.conf mode: foreign, which means systemd-resolved isn't managing the /etc/resolv.conf file—another program (like NetworkManager or dhclient) is handling it. Run:
cat /etc/resolv.conf
Compare the nameserver entries here to what's listed in resolvectl status. If they don't match, you have a configuration conflict. You can switch to systemd-resolved managing resolv.conf by running:
sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
Then restart systemd-resolved and test DNS resolution again.
5. Test DNS resolution directly with resolvectl
Run this command to see exactly how systemd-resolved is trying to resolve a domain:
resolvectl query google.com
The output will show which DNS server it's using, any errors, and the resolution result. This can help pinpoint if it's failing to use the eno8403 DNS servers or if one of those servers is unresponsive.
Let me know what you find from these steps—happy to help troubleshoot further!
备注:内容来源于stack exchange,提问作者Ralph Elsaesser

