Module 8 · Archives, compression and the network
DNS: nslookup and /etc/hosts
How a name becomes an address: the local /etc/hosts file first, then the DNS server named in /etc/resolv.conf, and nslookup to ask the question yourself.
What you will learn
- Explain the order in which a name is resolved: /etc/hosts, then DNS.
- Add local names to /etc/hosts and point the resolver at a server in /etc/resolv.conf.
- Query names with nslookup, optionally against a specific server.
Packets carry addresses, people type names. Turning httpbin.org into an IP address is called resolving the name, and every program does it through the same resolver library before it connects anywhere. The resolver looks in two places, in this order: the local file /etc/hosts, and then the DNS server named in /etc/resolv.conf. When something cannot find a host, those are the two files to read.
/etc/hosts
/etc/hosts is the oldest name system there is: one line per address, the IP first, then one or more names separated by spaces or tabs. Lines starting with # are comments. Because it is checked first, an entry here wins over DNS. Admins use it to name machines on a small lab network, to test a new server before DNS points at it, and to block a site by pointing its name at 127.0.0.1.
~% cat /etc/hosts
127.0.0.1 localhost
127.0.1.1 cat
~% echo '10.0.0.50 intranet intranet.lab' >> /etc/hosts
~% ping -c 1 intranet
PING intranet (10.0.0.50): 56 data bytes
Always append with >>. A single > would replace the file and lose localhost, which quietly breaks programs that expect it. Editing with vi is just as good.
/etc/resolv.conf and nslookup
Names not found in /etc/hosts are sent to the server on the nameserver line of /etc/resolv.conf. DHCP normally writes this file for you; in this VM, udhcpc writes nameserver 192.168.86.1. If the file is missing or empty, every lookup of a real name fails with bad address, while localhost keeps working: a classic clue.
nslookup NAME asks the question directly and shows who answered (Server:) and the result (Address). nslookup NAME SERVER asks a specific server instead of the configured one, which is how you tell *my resolver config is wrong* apart from *that name does not exist*. BusyBox's nslookup also consults /etc/hosts, so your local names show up too.
~% cat /etc/resolv.conf
nameserver 192.168.86.1 # eth0
~% nslookup httpbin.org
Server: 192.168.86.1
Address 1: 192.168.86.1
Name: httpbin.org
Address 1: 192.168.87.1
~% nslookup intranet
Name: intranet
Address 1: 10.0.0.50 intranet
Commands in this lesson
| Command | What it does |
|---|---|
cat /etc/hosts | Local name table, checked first. |
echo 'IP name' >> /etc/hosts | Add a local name (append, never overwrite). |
cat /etc/resolv.conf | Which DNS server the resolver uses. |
nslookup NAME | Resolve a name with the configured server. |
nslookup NAME SERVER | Ask a specific DNS server. |
Quiz
A name is in /etc/hosts with one address and in DNS with another. Which one do programs here use?
- The DNS one
- The /etc/hosts one, because it is checked first
- Both, alternately
- Neither; it is an error
Which file tells the resolver which DNS server to ask?
- /etc/hosts
- /etc/resolv.conf
- /etc/hostname
- /etc/network/interfaces
`localhost` resolves but every internet name fails with 'bad address'. Most likely?
- /etc/hosts is corrupt
- /etc/resolv.conf is missing or has no nameserver
- The loopback is down
- ping is not installed
Why use `>>` and not `>` when adding a line to /etc/hosts?
- `>` would replace the whole file, losing localhost
- `>>` is faster
- `>` needs root
- There is no difference
In TempMV, `nslookup does-not-exist.invalid` returns 192.168.87.2. Why?
- The name really exists
- The virtual DNS hands out a placeholder for every name; real lookups happen later, over HTTP
- /etc/hosts has a wildcard
- nslookup is broken
Practice
Add a line to `/etc/hosts` so that the name `intranet` resolves to `10.0.0.50`. Keep the existing lines.
Use `nslookup` to resolve the name `printer.lab` and save its output in `/root/lab/l77/printer.txt`.
The setup removed every `nameserver` line from `/etc/resolv.conf`, as a broken DHCP client might. Make the resolver use `192.168.86.1` again. (With the network on, `nslookup httpbin.org` works again once you are done.)
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.