How can I troubleshoot issues with my Route 53 failover routing policy?
Last updated: 2020-06-11
I configured an Amazon Route 53 failover routing policy. However, when I test the DNS resolution I'm seeing unexpected results. How can I troubleshoot this issue?
When you associate health checks with only the primary failover record:
- If the primary record is unhealthy, the secondary record is returned in response to a DNS query
- If there's no health check for the secondary record, then the secondary record is always treated as healthy
When you associate health checks with both the primary and secondary failover records:
- If the primary record is healthy, the primary record is returned in response to a DNS query
- If the primary record is unhealthy and the secondary record is healthy, then the secondary record is returned in response to a DNS query
- If both records are unhealthy, then the primary record is returned in response to a DNS query
If you have an alias failover record with "Evaluate target health" set to "true":
- The health of the resource that the alias record references is checked prior to returning the alias record
- If you have a health check associated with the alias record, then the associated health check and your alias’s target health must be healthy to return the alias record
Note: If your alias target is in the same hosted zone as the record, the target record must have an associated health check. Otherwise, the alias record is considered healthy and is included among possible responses to queries.
1. Use the DNS checking tool to test the configuration of your record set.
$ dig abc.example.com +short $ nslookup abc.example.com
3. In the information you find in steps 1-2, determine if the issue is related to the primary or secondary record.
4. Check the health check configuration to determine if health checks are reporting as healthy. For more information, see How Amazon Route 53 checks the health of your resources. If you identify failing health checks, see Viewing health check status and the reason for health check failures.