DNS
概述
Ubuntu 的 DNS 解析由以下几种方式管理:
- systemd-resolved:Ubuntu 18.04+ 默认使用,提供本地 DNS 缓存与解析
- resolvconf:传统方式,汇总多来源的 DNS 配置
- /etc/resolv.conf:标准 DNS 配置文件(通常是符号链接)
- Netplan:通过 YAML 配置网络接口 DNS
/etc/resolv.conf
标准 DNS 解析配置文件,指定 nameserver、search domain 等。
bash
# 查看当前内容
cat /etc/resolv.conftxt
nameserver 8.8.8.8
nameserver 8.8.4.4
search example.comUbuntu 18.04+ 中该文件通常是
/run/systemd/resolve/stub-resolv.conf的符号链接, 直接修改会在重启后被覆盖。
systemd-resolved
服务管理
bash
# 查看状态
systemctl status systemd-resolved
# 启动 / 停止 / 重启
systemctl start systemd-resolved
systemctl stop systemd-resolved
systemctl restart systemd-resolved
# 开机自启
systemctl enable systemd-resolved
systemctl disable systemd-resolved查询 DNS 状态
bash
# 查看各接口 DNS 配置及统计信息
resolvectl status
# 查看 DNS 缓存统计
resolvectl statistics
# 清空 DNS 缓存
resolvectl flush-caches
# 解析域名(调试)
resolvectl query example.com
# 旧版命令(等价)
systemd-resolve --status
systemd-resolve example.com配置文件
主配置文件:/etc/systemd/resolved.conf
ini
[Resolve]
DNS=8.8.8.8 8.8.4.4
FallbackDNS=1.1.1.1 1.0.0.1
Domains=~.
DNSSEC=no
DNSOverTLS=no
Cache=yes
DNSStubListener=yes配置项说明:
| 参数 | 说明 |
|---|---|
DNS | 全局 DNS 服务器地址,空格分隔 |
FallbackDNS | 备用 DNS |
Domains | 搜索域,~. 表示作为所有域的默认 DNS |
DNSSEC | 是否启用 DNSSEC 验证(yes/no/allow-downgrade) |
DNSOverTLS | 是否启用 DNS over TLS |
Cache | 是否启用缓存 |
DNSStubListener | 是否在 127.0.0.53:53 监听(本地 stub resolver) |
修改后重启生效:
bash
systemctl restart systemd-resolved/etc/resolv.conf 符号链接
bash
# 查看当前链接目标
ls -la /etc/resolv.conf
# 使用 systemd-resolved 的 stub resolver(推荐)
ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
# 使用真实上游 DNS(绕过 stub)
ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf
# 完全手动管理(取消符号链接)
cp /run/systemd/resolve/resolv.conf /etc/resolv.confNetplan 配置 DNS
Ubuntu 18.04+ 使用 Netplan 配置网络,DNS 在 YAML 中指定。
配置文件路径:/etc/netplan/*.yaml
yaml
network:
version: 2
ethernets:
eth0:
dhcp4: false
addresses: [192.168.1.10/24]
gateway4: 192.168.1.1
nameservers:
addresses: [8.8.8.8, 8.8.4.4]
search: [example.com, local]应用配置:
bash
netplan applyresolvconf(传统方式)
bash
# 安装
apt install resolvconf
# 服务管理
systemctl enable resolvconf
systemctl start resolvconf
# 手动添加 DNS(写入 /etc/resolvconf/resolv.conf.d/head)
echo "nameserver 8.8.8.8" >> /etc/resolvconf/resolv.conf.d/head
# 更新配置
resolvconf -u本地 DNS 服务
dnsmasq
bash
apt install dnsmasq
# 配置文件
vim /etc/dnsmasq.conf常用配置:
ini
# 上游 DNS
server=8.8.8.8
server=8.8.4.4
# 本地域名解析
address=/myhost.local/192.168.1.100
# 缓存大小
cache-size=1000
# 监听接口
interface=lo
bind-interfacesbash
systemctl restart dnsmasq
systemctl enable dnsmasq与 systemd-resolved 共存(避免 53 端口冲突):
ini
# /etc/systemd/resolved.conf
[Resolve]
DNSStubListener=nobash
systemctl restart systemd-resolvedbind9
bash
apt install bind9 bind9utils
# 配置目录
/etc/bind/
# 主配置
/etc/bind/named.conf.options
/etc/bind/named.conf.local
# 服务管理
systemctl enable named
systemctl restart named
# 检查配置语法
named-checkconf
named-checkzone example.com /etc/bind/db.example.comDNS 调试工具
bash
# dig - 标准查询工具
dig example.com
dig @8.8.8.8 example.com A
dig example.com MX +short
dig -x 8.8.8.8 # 反向解析
# nslookup
nslookup example.com
nslookup example.com 8.8.8.8
# host
host example.com
host -t MX example.com
# systemd-resolved 查询
resolvectl query example.com
# 查看本机 DNS 缓存(需要 systemd-resolved)
resolvectl statistics常见问题
DNS 配置修改后不生效
bash
# 重启 systemd-resolved 并刷新缓存
systemctl restart systemd-resolved
resolvectl flush-caches53 端口冲突
bash
# 查看占用 53 端口的进程
ss -tulnp | grep :53systemd-resolved 默认占用 127.0.0.53:53,若要使用 dnsmasq/bind9,需禁用其 stub listener:
ini
# /etc/systemd/resolved.conf
[Resolve]
DNSStubListener=noDHCP 自动覆盖 DNS
NetworkManager 或 dhclient 可能覆盖 DNS 配置。固定 DNS 的方式:
bash
# NetworkManager:编辑连接
nmcli con mod "连接名" ipv4.dns "8.8.8.8 8.8.4.4"
nmcli con mod "连接名" ipv4.ignore-auto-dns yes
nmcli con up "连接名"