Skip to content

DNS ​

概述 ​

Ubuntu 的 DNS 解析由以下几种方式管理:

  • systemd-resolved:Ubuntu 18.04+ 默认使用,提供本地 DNS 缓存与解析
  • resolvconf:传统方式,汇总多来源的 DNS 配置
  • /etc/resolv.conf:标准 DNS 配置文件(通常是符号链接)
  • Netplan:通过 YAML 配置网络接口 DNS

/etc/resolv.conf ​

标准 DNS 解析配置文件,指定 nameserver、search domain 等。

bash
# 查看当前内容
cat /etc/resolv.conf
txt
nameserver 8.8.8.8
nameserver 8.8.4.4
search example.com

Ubuntu 18.04+ 中该文件通常是 /run/systemd/resolve/stub-resolv.conf 的符号链接, 直接修改会在重启后被覆盖。


systemd-resolved ​

服务管理 ​

bash
# 查看状态
systemctl status systemd-resolved

# 启动 / 停止 / 重启
systemctl start  systemd-resolved
systemctl stop   systemd-resolved
systemctl restart systemd-resolved

# 开机自启
systemctl enable  systemd-resolved
systemctl disable systemd-resolved

查询 DNS 状态 ​

bash
# 查看各接口 DNS 配置及统计信息
resolvectl status

# 查看 DNS 缓存统计
resolvectl statistics

# 清空 DNS 缓存
resolvectl flush-caches

# 解析域名(调试)
resolvectl query example.com

# 旧版命令(等价)
systemd-resolve --status
systemd-resolve example.com

配置文件 ​

主配置文件:/etc/systemd/resolved.conf

ini
[Resolve]
DNS=8.8.8.8 8.8.4.4
FallbackDNS=1.1.1.1 1.0.0.1
Domains=~.
DNSSEC=no
DNSOverTLS=no
Cache=yes
DNSStubListener=yes

配置项说明:

参数说明
DNS全局 DNS 服务器地址,空格分隔
FallbackDNS备用 DNS
Domains搜索域,~. 表示作为所有域的默认 DNS
DNSSEC是否启用 DNSSEC 验证(yes/no/allow-downgrade)
DNSOverTLS是否启用 DNS over TLS
Cache是否启用缓存
DNSStubListener是否在 127.0.0.53:53 监听(本地 stub resolver)

修改后重启生效:

bash
systemctl restart systemd-resolved

/etc/resolv.conf 符号链接 ​

bash
# 查看当前链接目标
ls -la /etc/resolv.conf

# 使用 systemd-resolved 的 stub resolver(推荐)
ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf

# 使用真实上游 DNS(绕过 stub)
ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf

# 完全手动管理(取消符号链接)
cp /run/systemd/resolve/resolv.conf /etc/resolv.conf

Netplan 配置 DNS ​

Ubuntu 18.04+ 使用 Netplan 配置网络,DNS 在 YAML 中指定。

配置文件路径:/etc/netplan/*.yaml

yaml
network:
  version: 2
  ethernets:
    eth0:
      dhcp4: false
      addresses: [192.168.1.10/24]
      gateway4: 192.168.1.1
      nameservers:
        addresses: [8.8.8.8, 8.8.4.4]
        search: [example.com, local]

应用配置:

bash
netplan apply

resolvconf(传统方式) ​

bash
# 安装
apt install resolvconf

# 服务管理
systemctl enable resolvconf
systemctl start  resolvconf

# 手动添加 DNS(写入 /etc/resolvconf/resolv.conf.d/head)
echo "nameserver 8.8.8.8" >> /etc/resolvconf/resolv.conf.d/head

# 更新配置
resolvconf -u

本地 DNS 服务 ​

dnsmasq ​

bash
apt install dnsmasq

# 配置文件
vim /etc/dnsmasq.conf

常用配置:

ini
# 上游 DNS
server=8.8.8.8
server=8.8.4.4

# 本地域名解析
address=/myhost.local/192.168.1.100

# 缓存大小
cache-size=1000

# 监听接口
interface=lo
bind-interfaces
bash
systemctl restart dnsmasq
systemctl enable  dnsmasq

与 systemd-resolved 共存(避免 53 端口冲突):

ini
# /etc/systemd/resolved.conf
[Resolve]
DNSStubListener=no
bash
systemctl restart systemd-resolved

bind9 ​

bash
apt install bind9 bind9utils

# 配置目录
/etc/bind/

# 主配置
/etc/bind/named.conf.options
/etc/bind/named.conf.local

# 服务管理
systemctl enable  named
systemctl restart named

# 检查配置语法
named-checkconf
named-checkzone example.com /etc/bind/db.example.com

DNS 调试工具 ​

bash
# dig - 标准查询工具
dig example.com
dig @8.8.8.8 example.com A
dig example.com MX +short
dig -x 8.8.8.8           # 反向解析

# nslookup
nslookup example.com
nslookup example.com 8.8.8.8

# host
host example.com
host -t MX example.com

# systemd-resolved 查询
resolvectl query example.com

# 查看本机 DNS 缓存(需要 systemd-resolved)
resolvectl statistics

常见问题 ​

DNS 配置修改后不生效 ​

bash
# 重启 systemd-resolved 并刷新缓存
systemctl restart systemd-resolved
resolvectl flush-caches

53 端口冲突 ​

bash
# 查看占用 53 端口的进程
ss -tulnp | grep :53

systemd-resolved 默认占用 127.0.0.53:53,若要使用 dnsmasq/bind9,需禁用其 stub listener:

ini
# /etc/systemd/resolved.conf
[Resolve]
DNSStubListener=no

DHCP 自动覆盖 DNS ​

NetworkManager 或 dhclient 可能覆盖 DNS 配置。固定 DNS 的方式:

bash
# NetworkManager:编辑连接
nmcli con mod "连接名" ipv4.dns "8.8.8.8 8.8.4.4"
nmcli con mod "连接名" ipv4.ignore-auto-dns yes
nmcli con up "连接名"