A system administrator needs to troubleshoot a server that is experiencing intermittent network connectivity issues. The administrator suspects that the issue might be related to DNS resolution, specifically with the server's ability to resolve external hostnames. Which command would be most effective to test the server's configured DNS resolvers and their ability to resolve an external hostname?
- A`cat /etc/resolv.conf` to view the configured DNS servers.
- B`netstat -tulpn | grep 53` to see if a local DNS server is running.
- C`dig @<dns_server_ip> google.com` to query a specific DNS server for a hostname.
- D`ping google.com` to check if the hostname resolves and is reachable.
Show answer & explanationAnswer & explanation
Correct answer: C. `dig @<dns_server_ip> google.com` to query a specific DNS server for a hostname.
While `cat /etc/resolv.conf` shows configured DNS servers and `ping google.com` tests overall reachability, `dig @<dns_server_ip> google.com` is the most effective command to directly test a *specific* DNS server (either the one configured in `resolv.conf` or an alternative) for its ability to resolve a given hostname. This isolates the DNS resolution process and helps identify if the issue is with the configured resolvers themselves.
Why the other options are wrong
- A. `cat /etc/resolv.conf` shows *which* DNS servers are configured, but doesn't test *if* they are working or can resolve the specific hostname.
- B. `netstat -tulpn | grep 53` checks for a local DNS server listening on port 53. This is relevant if the server is *supposed* to be its own recursive resolver, but doesn't test the ability of external configured resolvers to resolve external hostnames.
- D. `ping google.com` tests end-to-end connectivity, but if `ping` fails, it doesn't isolate whether the failure is due to DNS resolution, routing, or firewall issues. It's a symptom, not a diagnostic for DNS specifically.
dig for DNS Resolution Testing
The `dig` command is a powerful tool for querying DNS name servers. Using `dig @<dns_server_ip> <hostname>` allows direct testing of a specific DNS server's ability to resolve a hostname, which is critical for diagnosing DNS-related network connectivity issues.
- Queries DNS name servers directly.
- Allows specifying a particular DNS server.
- Provides detailed DNS response information.
Memory trick: DIG it up, the DNS truth you'll find.