You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS EBS/RDS/S3/CloudWatch时持续出现域名解析失败警告求助

Fixing "Temporary failure in name resolution" Warning in AWS CloudWatch

Hey there, let's work through getting rid of that repeated DNS resolution warning popping up in your CloudWatch logs. I've dealt with similar AWS issues before, so here are practical, actionable steps to resolve it:

  • Check VPC DNS Core Settings
    First up, verify your VPC has proper DNS support enabled. Head to the AWS VPC console and confirm two critical settings for your VPC:

    • enableDnsSupport set to true
    • enableDnsHostnames set to true
      If either is disabled, toggle them on and restart any EC2 or RDS instances tied to this VPC—this ensures they pick up the updated DNS config. You can also validate via CLI with:
      aws ec2 describe-vpcs --vpc-ids YOUR_VPC_ID --query 'Vpcs[*].{EnableDnsSupport:EnableDnsSupport, EnableDnsHostnames:EnableDnsHostnames}'
  • Validate DHCP Options & DNS Servers
    Check your VPC's DHCP options set to make sure it's using reliable DNS servers. AWS recommends the VPC's default DNS (VPC CIDR range + 2, e.g., 10.0.0.2 for a 10.0.0.0/16 VPC) since it's optimized for internal AWS services.
    Test DNS resolution directly from an EC2 instance in the same VPC:
    nslookup 85.93.20.90 or dig -x 85.93.20.90
    If these commands fail, your DNS server can't resolve the IP's reverse record correctly.

  • Unblock DNS Traffic in Security Groups/Network ACLs
    Ensure your instance's security group allows outbound UDP port 53 (for standard DNS queries). Also, check your VPC's network ACLs to permit both inbound and outbound traffic on UDP 53 and TCP 53 (used for large DNS responses). Overly restrictive rules often block DNS requests, leading to temporary failures.

  • Troubleshoot RDS-Specific Issues (if applicable)
    If the warning comes from your RDS instance, it's probably trying to reverse-resolve the IP 85.93.20.90 (a client connecting to your database). Double-check that your RDS is in a VPC with correct DNS settings. You can adjust the log_warnings parameter in your RDS parameter group to reduce verbosity, but fixing the DNS issue is the cleaner long-term fix.

  • Verify Reverse DNS (PTR) Record for 85.93.20.90
    The warning triggers because the IP 85.93.20.90 doesn't have a valid reverse DNS (PTR) record. If this IP belongs to your own infrastructure, add a PTR record through your DNS provider. If it's an external client, you can either ignore the warning (if the client is trusted) or reach out to the IP's owner to set up the PTR record.

Most of the time, this issue traces back to VPC DNS misconfiguration or blocked DNS traffic. Start with the VPC DNS settings—they're the most common culprit!

内容的提问来源于stack exchange,提问作者Neeraj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:07:40