Overview & Root Cause Summary: The error
Temporary failure in name resolutionis a system-wide Linux network resolution failure returned by standard C library resolver functions (getaddrinfo/gethostbyname). It occurs when applications (such asapt,curl,wget,git, or Docker) attempt to resolve a domain name to an IP address, but the system receives no response from the configured DNS servers. This is typically caused by an inactive or crashedsystemd-resolveddaemon, a broken/etc/resolv.confsymlink, network adapter changes following a VPN disconnect, or upstream router DHCP nameserver failure.
Understanding the Root Causes
- Unreachable or Missing Nameservers in /etc/resolv.conf: The resolver configuration file contains no active
nameserverentries, or lists upstream DNS IP addresses that are offline or unreachable from the current network interface. - systemd-resolved Local Stub Resolver Failure: On Ubuntu, Debian, and modern systemd distributions,
/etc/resolv.confpoints to the local loopback stub resolver (127.0.0.53). If thesystemd-resolvedbackground service crashes or freezes, all system DNS queries fail instantly. - Broken Symlink After VPN or Network Reconfiguration: Disconnecting from corporate VPN clients (e.g. OpenVPN, Cisco AnyConnect, WireGuard) often fails to restore the original
/etc/resolv.conf, leaving a dead file or orphaned configuration. - Firewall Dropping Outbound UDP Port 53: Host-level firewalls (UFW, iptables) or corporate network security gateways blocking outbound UDP/TCP port 53 traffic.
Step 1: Quick Fix (Configure Reliable Upstream Nameservers)
Restore immediate internet and package manager connectivity by adding public upstream DNS resolvers directly to your system configuration.
# 1. Temporarily populate /etc/resolv.conf with public DNS servers (Google and Cloudflare):
sudo bash -c 'cat <<EOF > /etc/resolv.conf
nameserver 8.8.8.8
nameserver 1.1.1.1
nameserver 8.8.4.4
EOF'
# 2. Test immediate name resolution:
ping -c 3 google.com
# 3. If resolution works, proceed to Step 2 to make the configuration permanent
# (otherwise NetworkManager or systemd-resolved will overwrite /etc/resolv.conf on reboot).
Step 2: Repair systemd-resolved and the resolv.conf Symlink
On modern Linux distributions, ensure the systemd DNS daemon is active and that resolv.conf links to the correct runtime directory.
# 1. Check systemd-resolved operational status:
sudo systemctl status systemd-resolved
# 2. Start and enable systemd-resolved if inactive:
sudo systemctl enable --now systemd-resolved
# 3. Re-link /etc/resolv.conf to the standard systemd-resolved stub file:
sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
# 4. If the stub resolver fails inside containers or VMs, link to the upstream file directly:
sudo ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf
# 5. Flush and restart the DNS cache:
sudo resolvectl flush-caches
sudo systemctl restart systemd-resolved
Step 3: Configure Permanent Static DNS via Netplan or NetworkManager
Make your DNS configuration permanent across reboots and DHCP renewals through your distribution’s primary network manager.
# --- For Netplan (Ubuntu Server / Desktop 18.04+) ---
# 1. Locate and edit your Netplan configuration file:
sudo nano /etc/netplan/01-netcfg.yaml
# 2. Under your primary network interface (e.g. eth0 or enp3s0), add nameservers:
network:
version: 2
renderer: networkd
ethernets:
eth0:
dhcp4: true
nameservers:
addresses: [8.8.8.8, 1.1.1.1]
# 3. Apply the Netplan configuration:
sudo netplan apply
# --- For NetworkManager (Desktop Linux / RHEL / Fedora) ---
# Set DNS via nmcli on your active connection:
nmcli connection show
nmcli connection modify "<Connection_Name>" ipv4.dns "8.8.8.8 1.1.1.1"
nmcli connection modify "<Connection_Name>" ipv4.ignore-auto-dns yes
nmcli connection up "<Connection_Name>"
Verification & Testing Steps
Confirm that DNS resolution is functioning properly and inspect active resolver endpoints.
# 1. Query the active DNS servers and link state using resolvectl:
resolvectl status
# Verify that "DNS Servers: 8.8.8.8 1.1.1.1" is displayed under your primary interface.
# 2. Test domain resolution using dig or nslookup:
dig google.com +short
# 3. Validate system package repository reachability:
sudo apt-get update
# (Or on RHEL/CentOS: sudo dnf check-update)
Summary Comparison Table
| Remediation Method | Applied Layer | Persistence Across Reboots | Recommended Context |
|---|---|---|---|
Direct /etc/resolv.conf Edit |
Resolver Stub | Temporary (Overwritten on boot) | Emergency CLI recovery & rescue shells |
systemd-resolved Symlink Fix |
System Daemon | Permanent | Standard Ubuntu & Debian systems |
| Netplan YAML Configuration | Network Layer | Permanent (Survives DHCP renewal) | Ubuntu Server & cloud VMs |
nmcli Connection Override |
NetworkManager | Permanent | Desktop distributions & RHEL/Fedora |
Leave a Reply