Ubuntu 20.04 Desktop DNS解析异常:仅指定DNS服务器时dig命令可正常工作
Ubuntu 20.04 Desktop DNS解析异常:仅指定DNS服务器时dig命令可正常工作
我这边装了Ubuntu 20.04 Desktop,最近碰到个棘手的问题——没法通过域名访问互联网或任何服务器,DNS查询彻底失败。环境里的DNS服务器包括两台Windows DC(10.0.1.22、10.0.1.21)和两台Cisco Umbrella代理设备(10.0.6.70、10.0.6.67),下面是我做的一系列排查:
一、DNS配置与dig测试结果
先通过nmcli查看当前系统识别的DNS服务器:
root@sdbuilder-NU591:/etc/network/interfaces.d# nmcli dev show | grep DNS IP4.DNS[1]: 10.0.6.67 IP4.DNS[2]: 10.0.6.70
然后用dig做测试,发现只有手动指定DNS服务器时才能正常解析:
- 直接执行
dig google.com会超时,完全连不上服务器:
root@sdbuilder-NU591:/home/sdbuilder# dig google.com ; <<>> DiG 9.16.1-Ubuntu <<>> google.com ;; global options: +cmd ;; connection timed out; no servers could be reached
- 指定10.0.6.70作为DNS服务器时,dig就能正常返回解析结果:
root@sdbuilder-NU591:/home/sdbuilder# dig google.com @10.0.6.70 ; <<>> DiG 9.16.1-Ubuntu <<>> google.com @10.0.6.70 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 10355 ;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;google.com. IN A ;; ANSWER SECTION: google.com. 300 IN A 142.251.116.100 google.com. 300 IN A 142.251.116.101 google.com. 300 IN A 142.251.116.102 google.com. 300 IN A 142.251.116.113 google.com. 300 IN A 142.251.116.138 google.com. 300 IN A 142.251.116.139 ;; Query time: 16 msec ;; SERVER: 10.0.6.70#53(10.0.6.70) ;; WHEN: Tue Dec 26 13:08:48 CST 2023 ;; MSG SIZE rcvd: 135
二、resolv.conf与域名解析测试
我的IP是通过DHCP获取的,也拿到了搜索域,但不管是短域名还是完整域名都解析失败:
root@sdbuilder-NU591:/home/sdbuilder# cat /etc/resolv.conf # Generated by NetworkManager search example.com nameserver 127.0.0.53 root@sdbuilder-NU591:/home/sdbuilder# ping server1 ping: server1: Temporary failure in name resolution root@sdbuilder-NU591:/home/sdbuilder# ping server1.example.com ping: server1.additech.com: Temporary failure in name resolution
用tcpdump抓包也验证了这一点——只有手动指定DNS服务器时,系统才会发送DNS请求;不指定的话,完全看不到任何DNS流量:
root@sdbuilder-NU591:/home/sdbuilder# tcpdump -n udp port 53 -v tcpdump: listening on enp3s0, link-type EN10MB (Ethernet), capture size 262144 bytes 13:16:05.308404 IP (tos 0x0, ttl 64, id 41787, offset 0, flags [none], proto UDP (17), length 79) 10.0.6.58.40227 > 10.0.6.70.53: 12769+ [1au] A? google.com. (51) 13:16:05.326976 IP (tos 0x0, ttl 64, id 58695, offset 0, flags [DF], proto UDP (17), length 163) 10.0.6.70.53 > 10.0.6.58.40227: 12769 6/0/1 google.com. A 142.251.116.138, google.com. A 142.251.116.139, google.com. A 142.251.116.100, google.com. A 142.251.116.101, google.com. A 142.251.116.102, google.com. A 142.251.116.113 (135) ^C 2 packets captured 3 packets received by filter 0 packets dropped by kernel 1 packet dropped by interface
三、系统服务与相关配置排查
一开始systemd-resolved是禁用且未运行的,我尝试启用并启动它,但还是没法正常解析域名,日志显示有其他进程占用了127.0.0.53:53端口:
Dec 26 13:26:00 sdbuilder-NU591 systemd-resolved[4652]: Using system hostname 'sdbuilder-NU591'. Dec 26 13:26:00 sdbuilder-NU591 systemd-resolved[4652]: Another process is already listening on TCP socket 127.0.0.53:53. Dec 26 13:26:00 sdbuilder-NU591 systemd-resolved[4652]: Turning off local DNS stub support. Dec 26 13:26:00 sdbuilder-NU591 systemd[1]: Started Network Name Resolution.
查看systemd-resolved的配置文件/etc/systemd/resolved.conf,里面指定了DNS和备用DNS:
root@sdbuilder-NU591:/etc/network/interfaces.d# cat /etc/systemd/resolved.conf # This file is part of systemd. # # systemd is free software; you can redistribute it and/or modify it # under the terms of the GNU Lesser General Public License as published by # the Free Software Foundation; either version 2.1 of the License, or # (at your option) any later version. # # Entries in this file show the compile time defaults. # You can change settings by editing this file. # Defaults can be restored by simply deleting this file. # # See resolved.conf(5) for details [Resolve] DNS=10.0.1.22 FallbackDNS=10.0.1.21 #Domains= #LLMNR=no #MulticastDNS=no #DNSSEC=no #DNSOverTLS=no #Cache=no-negative #DNSStubListener=yes #ReadEtcHosts=yes
用netstat排查端口占用情况,发现是dnsmasq在监听53端口:
root@sdbuilder-NU591:/etc/network/interfaces.d# netstat -tulpn | grep ":53 " tcp 0 0 0.0.0.0:53 0.0.0.0:* LISTEN 902/dnsmasq tcp6 0 0 :::53 :::* LISTEN 902/dnsmasq udp 0 0 0.0.0.0:53 0.0.0.0:* 902/dnsmasq udp6 0 0 :::53 :::* 902/dnsmasq
另外,netplan和网络接口配置文件如下:
root@sdbuilder-NU591:/home/sdbuilder# cat /etc/netplan/*.yaml # Let NetworkManager manage all devices on this system network: version: 2 renderer: NetworkManager root@sdbuilder-NU591:/home/sdbuilder# cat /etc/network/interfaces # interfaces(5) file used by ifup(8) and ifdown(8) # Include files from /etc/network/interfaces.d: source-directory /etc/network/interfaces.d
/etc/network/interfaces.d目录下没有任何文件。
备注:内容来源于stack exchange,提问作者rocky_alpine
相关产品推荐
相关产品推荐

