A system administrator is troubleshooting a server that is unable to resolve external hostnames. Internal hostnames resolve correctly. A `dig www.example.com` command from the server returns `connection timed out; no servers could be reached`. Which of the following is the most likely issue?
- AThe `/etc/hosts` file has an incorrect entry for www.example.com.
- BThe `nsswitch.conf` file is misconfigured, prioritizing `files` over `dns`.
- CThe configured DNS servers in `/etc/resolv.conf` are unreachable or incorrect.
- DThe server's firewall is blocking outbound DNS queries (UDP port 53).
Show answer & explanationAnswer & explanation
Correct answer: C. The configured DNS servers in `/etc/resolv.conf` are unreachable or incorrect.
The error `connection timed out; no servers could be reached` from `dig` explicitly indicates that the DNS query could not reach any configured DNS server. This points directly to the `/etc/resolv.conf` file, which lists the DNS servers the system should use. If these servers are incorrect (e.g., wrong IP address) or unreachable (e.g., due to a network issue *between the server and the DNS server*), external hostname resolution will fail.
Why the other options are wrong
- A. `/etc/hosts` is checked before DNS, but if an entry existed for www.example.com, `dig` would not time out; it would use that entry or still try DNS if not found.
- B. `nsswitch.conf` defines the order of name resolution sources. If `files` was prioritized, it would just check `/etc/hosts` first, but if `dns` is still listed and fails, it would still try DNS, and the timeout indicates the server itself is the issue.
- D. While a firewall could block outbound DNS, the error `no servers could be reached` specifically points to the server *trying* to reach the configured DNS servers and failing, rather than a successful connection being refused or filtered.
DNS Resolver Configuration (/etc/resolv.conf)
The `/etc/resolv.conf` file specifies the IP addresses of DNS (Domain Name System) servers that a Linux system should use to resolve hostnames to IP addresses. Incorrect or unreachable entries prevent successful name resolution.
- Lists `nameserver` entries for DNS server IPs.
- Crucial for external (and sometimes internal) hostname resolution.
- Often managed by network managers (e.g., NetworkManager, systemd-resolved).
Memory trick: Resolve to check the nameservers.