Skip to Content
文档服务器DNS / DHCP

DNS / DHCP 服务

本文介绍如何在 Ubuntu 26.04 上搭建 DNS 和 DHCP 服务,包括轻量级的 dnsmasq 方案以及功能完整的 BIND9 和 isc-dhcp-server 方案。

dnsmasq(轻量级 DNS + DHCP)

dnsmasq 同时提供 DNS 缓存/转发和 DHCP 服务,适合小型网络和家庭实验环境。

安装与配置

# Ubuntu 26.04 默认使用 systemd-resolved,会占用 53 端口 # 推荐做法(更温和):仅关闭其 DNS 监听存根,保留 resolved 的其余功能 # 编辑 /etc/systemd/resolved.conf,在 [Resolve] 段设置: # DNSStubListener=no sudo sed -i 's/^#\?DNSStubListener=.*/DNSStubListener=no/' /etc/systemd/resolved.conf sudo systemctl restart systemd-resolved # 关闭存根后,默认的 /etc/resolv.conf 仍指向已失效的 127.0.0.53, # 本机会立即断网(包括下面的 apt update)。需改指向 resolved 自身的 # 上游解析结果,恢复本机 DNS: sudo ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf # 备选做法(彻底禁用 systemd-resolved): # sudo systemctl stop systemd-resolved # sudo systemctl disable systemd-resolved # sudo rm /etc/resolv.conf # echo "nameserver 223.5.5.5" | sudo tee /etc/resolv.conf # 安装 dnsmasq(此时本机 DNS 已恢复,apt update 不会断网) sudo apt update sudo apt install dnsmasq -y

DNS 配置

sudo tee /etc/dnsmasq.conf << 'EOF' # 监听接口 interface=eth0 bind-interfaces # 上游 DNS 服务器 server=223.5.5.5 server=8.8.8.8 # DNS 缓存大小 cache-size=1000 # 本地域名 domain=homelab.local local=/homelab.local/ # 自定义域名解析(类似 /etc/hosts) address=/nas.homelab.local/192.168.1.10 address=/router.homelab.local/192.168.1.1 # 也可以读取 /etc/hosts 中的记录 expand-hosts # 日志(调试时启用) # log-queries # log-facility=/var/log/dnsmasq.log EOF

DHCP 配置

# 在 /etc/dnsmasq.conf 中追加 DHCP 配置 sudo tee -a /etc/dnsmasq.conf << 'EOF' # DHCP 地址池范围和租约时间 dhcp-range=192.168.1.100,192.168.1.200,255.255.255.0,12h # 默认网关 dhcp-option=option:router,192.168.1.1 # DNS 服务器(指向自身) dhcp-option=option:dns-server,192.168.1.5 # NTP 服务器 dhcp-option=option:ntp-server,192.168.1.1 # 域名 dhcp-option=option:domain-name,homelab.local # 静态 IP 绑定(MAC 地址绑定) dhcp-host=aa:bb:cc:dd:ee:01,server1,192.168.1.11 dhcp-host=aa:bb:cc:dd:ee:02,server2,192.168.1.12 # DHCP 租约文件 dhcp-leasefile=/var/lib/dnsmasq/dnsmasq.leases # PXE 启动(可选) # dhcp-boot=pxelinux.0,pxeserver,192.168.1.5 EOF

启动服务

# 测试配置 dnsmasq --test # 重启服务 sudo systemctl restart dnsmasq sudo systemctl enable dnsmasq # 防火墙 sudo ufw allow 53/tcp sudo ufw allow 53/udp sudo ufw allow 67/udp sudo ufw allow 68/udp # 测试 DNS dig @localhost homelab.local nslookup nas.homelab.local 127.0.0.1 # 查看 DHCP 租约 cat /var/lib/dnsmasq/dnsmasq.leases

BIND9(权威 DNS 服务器)

BIND9 是最广泛使用的 DNS 服务器软件,适合需要完整 DNS 功能的场景。

安装

sudo apt update sudo apt install bind9 bind9-utils bind9-dnsutils -y sudo systemctl enable --now named

主配置

# /etc/bind/named.conf.options sudo tee /etc/bind/named.conf.options << 'EOF' options { directory "/var/cache/bind"; // 转发模式 forwarders { 223.5.5.5; 8.8.8.8; }; forward only; // 监听地址 listen-on { 127.0.0.1; 192.168.1.5; }; listen-on-v6 { none; }; // 允许查询的客户端 allow-query { localhost; 192.168.1.0/24; }; // 允许递归查询 recursion yes; allow-recursion { localhost; 192.168.1.0/24; }; // 安全设置 dnssec-validation auto; auth-nxdomain no; // 隐藏版本号 version "not available"; }; EOF

配置正向区域

# 添加区域声明 sudo tee /etc/bind/named.conf.local << 'EOF' // 正向区域 zone "example.local" { type master; file "/etc/bind/zones/db.example.local"; allow-transfer { 192.168.1.6; }; // 从服务器 IP }; // 反向区域 zone "1.168.192.in-addr.arpa" { type master; file "/etc/bind/zones/db.192.168.1"; allow-transfer { 192.168.1.6; }; }; EOF # 创建区域文件目录 sudo mkdir -p /etc/bind/zones

正向区域文件

sudo tee /etc/bind/zones/db.example.local << 'EOF' $TTL 604800 @ IN SOA ns1.example.local. admin.example.local. ( 2026032401 ; Serial (年月日+序号) 3600 ; Refresh 1800 ; Retry 604800 ; Expire 86400 ) ; Negative Cache TTL ; 名称服务器 @ IN NS ns1.example.local. @ IN NS ns2.example.local. ; A 记录 ns1 IN A 192.168.1.5 ns2 IN A 192.168.1.6 web IN A 192.168.1.10 db IN A 192.168.1.11 mail IN A 192.168.1.12 ; CNAME 记录 www IN CNAME web.example.local. ftp IN CNAME web.example.local. ; MX 记录 @ IN MX 10 mail.example.local. EOF

反向区域文件

sudo tee /etc/bind/zones/db.192.168.1 << 'EOF' $TTL 604800 @ IN SOA ns1.example.local. admin.example.local. ( 2026032401 ; Serial 3600 ; Refresh 1800 ; Retry 604800 ; Expire 86400 ) ; Negative Cache TTL @ IN NS ns1.example.local. @ IN NS ns2.example.local. ; PTR 记录 5 IN PTR ns1.example.local. 6 IN PTR ns2.example.local. 10 IN PTR web.example.local. 11 IN PTR db.example.local. 12 IN PTR mail.example.local. EOF

验证与启动

# 检查主配置语法 sudo named-checkconf # 检查区域文件 sudo named-checkzone example.local /etc/bind/zones/db.example.local sudo named-checkzone 1.168.192.in-addr.arpa /etc/bind/zones/db.192.168.1 # 重启服务 sudo systemctl restart named # 测试解析 dig @192.168.1.5 web.example.local dig @192.168.1.5 -x 192.168.1.10 nslookup web.example.local 192.168.1.5

isc-dhcp-server

对于大型网络或需要高级 DHCP 功能的场景,使用独立的 DHCP 服务器。

注意:isc-dhcp-server 已进入生命周期末期,ISC 推荐迁移到 Kea DHCP。以下同时介绍两者。

isc-dhcp-server 配置

# 安装 sudo apt install isc-dhcp-server -y # 指定监听接口 sudo tee /etc/default/isc-dhcp-server << 'EOF' INTERFACESv4="eth0" INTERFACESv6="" EOF
# 编辑主配置文件 sudo tee /etc/dhcp/dhcpd.conf << 'EOF' # 全局选项 option domain-name "example.local"; option domain-name-servers 192.168.1.5, 223.5.5.5; default-lease-time 43200; # 12 小时 max-lease-time 86400; # 24 小时 authoritative; # 子网定义 subnet 192.168.1.0 netmask 255.255.255.0 { range 192.168.1.100 192.168.1.200; option routers 192.168.1.1; option subnet-mask 255.255.255.0; option broadcast-address 192.168.1.255; option ntp-servers 192.168.1.1; } # 固定 IP 分配 host server1 { hardware ethernet aa:bb:cc:dd:ee:01; fixed-address 192.168.1.11; option host-name "server1"; } host server2 { hardware ethernet aa:bb:cc:dd:ee:02; fixed-address 192.168.1.12; option host-name "server2"; } # 组配置(共享选项) group { option domain-name "dev.example.local"; host dev1 { hardware ethernet aa:bb:cc:dd:ee:10; fixed-address 192.168.1.50; } host dev2 { hardware ethernet aa:bb:cc:dd:ee:11; fixed-address 192.168.1.51; } } EOF
# 检查配置语法 sudo dhcpd -t -cf /etc/dhcp/dhcpd.conf # 启动服务 sudo systemctl restart isc-dhcp-server sudo systemctl enable isc-dhcp-server # 查看租约 cat /var/lib/dhcp/dhcpd.leases

Kea DHCP(推荐替代方案)

# 安装 Kea DHCP sudo apt install kea-dhcp4-server -y
# 配置 /etc/kea/kea-dhcp4.conf sudo tee /etc/kea/kea-dhcp4.conf << 'EOF' { "Dhcp4": { "interfaces-config": { "interfaces": ["eth0"] }, "lease-database": { "type": "memfile", "persist": true, "name": "/var/lib/kea/dhcp4.leases" }, "valid-lifetime": 43200, "subnet4": [ { "subnet": "192.168.1.0/24", "pools": [ { "pool": "192.168.1.100 - 192.168.1.200" } ], "option-data": [ { "name": "routers", "data": "192.168.1.1" }, { "name": "domain-name-servers", "data": "192.168.1.5, 223.5.5.5" }, { "name": "domain-name", "data": "example.local" } ], "reservations": [ { "hw-address": "aa:bb:cc:dd:ee:01", "ip-address": "192.168.1.11", "hostname": "server1" } ] } ] } } EOF sudo systemctl restart kea-dhcp4-server sudo systemctl enable kea-dhcp4-server

DNS + DHCP 联动

让 DHCP 分配的主机名自动注册到 DNS:

dnsmasq 方案(自动联动)

dnsmasq 天然支持 DNS-DHCP 联动,DHCP 客户端发送的主机名会自动可解析。

BIND9 + DHCP 动态更新

# 生成 TSIG 密钥 tsig-keygen -a hmac-sha256 dhcp-key > /etc/bind/dhcp-key.conf # 在 BIND 中引入密钥并允许动态更新 # /etc/bind/named.conf.local 中添加: include "/etc/bind/dhcp-key.conf"; zone "example.local" { type master; file "/var/lib/bind/db.example.local"; allow-update { key dhcp-key; }; };

故障排查

# DNS 排查 dig @server-ip example.local +trace dig @server-ip example.local +short host example.local server-ip # DHCP 排查 sudo journalctl -u isc-dhcp-server -f sudo journalctl -u dnsmasq -f # 监听端口检查 ss -ulnp | grep -E "(53|67|68)" # 抓包分析 DHCP 流量 sudo tcpdump -i eth0 port 67 or port 68 -n # 客户端手动请求 DHCP sudo dhclient -v eth0
Last updated on