Skip to Content
DocsServerDNS & DHCP

DNS / DHCP Services

This article explains how to set up DNS and DHCP services on Ubuntu 26.04, including the lightweight dnsmasq solution as well as the full-featured BIND9 and isc-dhcp-server approach.

dnsmasq (Lightweight DNS + DHCP)

dnsmasq provides both DNS caching/forwarding and DHCP services, making it ideal for small networks and home lab environments.

Installation and Configuration

# Ubuntu 26.04 uses systemd-resolved by default, which occupies port 53. # Recommended (gentler) approach: only disable its DNS stub listener while # keeping the rest of resolved's functionality. # Edit /etc/systemd/resolved.conf and set the following in the [Resolve] section: # DNSStubListener=no sudo sed -i 's/^#\?DNSStubListener=.*/DNSStubListener=no/' /etc/systemd/resolved.conf sudo systemctl restart systemd-resolved # After disabling the stub, the default /etc/resolv.conf still points at the # now-dead 127.0.0.53, so this host loses DNS immediately (including the # apt update below). Repoint it to resolved's own upstream results to restore # local DNS: sudo ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf # Alternative approach (fully disable systemd-resolved): # sudo systemctl stop systemd-resolved # sudo systemctl disable systemd-resolved # sudo rm /etc/resolv.conf # echo "nameserver 8.8.8.8" | sudo tee /etc/resolv.conf # Install dnsmasq (local DNS is restored now, so apt update will not break) sudo apt update sudo apt install dnsmasq -y

DNS Configuration

sudo tee /etc/dnsmasq.conf << 'EOF' # Listen interface interface=eth0 bind-interfaces # Upstream DNS servers server=8.8.8.8 server=1.1.1.1 # DNS cache size cache-size=1000 # Local domain domain=homelab.local local=/homelab.local/ # Custom DNS records (similar to /etc/hosts) address=/nas.homelab.local/192.168.1.10 address=/router.homelab.local/192.168.1.1 # Also read records from /etc/hosts expand-hosts # Logging (enable for debugging) # log-queries # log-facility=/var/log/dnsmasq.log EOF

DHCP Configuration

# Append DHCP configuration to /etc/dnsmasq.conf sudo tee -a /etc/dnsmasq.conf << 'EOF' # DHCP address pool range and lease time dhcp-range=192.168.1.100,192.168.1.200,255.255.255.0,12h # Default gateway dhcp-option=option:router,192.168.1.1 # DNS server (point to self) dhcp-option=option:dns-server,192.168.1.5 # NTP server dhcp-option=option:ntp-server,192.168.1.1 # Domain name dhcp-option=option:domain-name,homelab.local # Static IP bindings (MAC address reservations) dhcp-host=aa:bb:cc:dd:ee:01,server1,192.168.1.11 dhcp-host=aa:bb:cc:dd:ee:02,server2,192.168.1.12 # DHCP lease file dhcp-leasefile=/var/lib/dnsmasq/dnsmasq.leases # PXE boot (optional) # dhcp-boot=pxelinux.0,pxeserver,192.168.1.5 EOF

Start the Service

# Test the configuration dnsmasq --test # Restart the service sudo systemctl restart dnsmasq sudo systemctl enable dnsmasq # Firewall rules sudo ufw allow 53/tcp sudo ufw allow 53/udp sudo ufw allow 67/udp sudo ufw allow 68/udp # Test DNS dig @localhost homelab.local nslookup nas.homelab.local 127.0.0.1 # View DHCP leases cat /var/lib/dnsmasq/dnsmasq.leases

BIND9 (Authoritative DNS Server)

BIND9 is the most widely used DNS server software, suitable for scenarios requiring full DNS functionality.

Installation

sudo apt update sudo apt install bind9 bind9-utils bind9-dnsutils -y sudo systemctl enable --now named

Main Configuration

# /etc/bind/named.conf.options sudo tee /etc/bind/named.conf.options << 'EOF' options { directory "/var/cache/bind"; // Forwarding mode forwarders { 8.8.8.8; 1.1.1.1; }; forward only; // Listen addresses listen-on { 127.0.0.1; 192.168.1.5; }; listen-on-v6 { none; }; // Allowed query clients allow-query { localhost; 192.168.1.0/24; }; // Allow recursive queries recursion yes; allow-recursion { localhost; 192.168.1.0/24; }; // Security settings dnssec-validation auto; auth-nxdomain no; // Hide version number version "not available"; }; EOF

Configure a Forward Zone

# Add zone declarations sudo tee /etc/bind/named.conf.local << 'EOF' // Forward zone zone "example.local" { type master; file "/etc/bind/zones/db.example.local"; allow-transfer { 192.168.1.6; }; // Secondary server IP }; // Reverse zone zone "1.168.192.in-addr.arpa" { type master; file "/etc/bind/zones/db.192.168.1"; allow-transfer { 192.168.1.6; }; }; EOF # Create the zone file directory sudo mkdir -p /etc/bind/zones

Forward Zone File

sudo tee /etc/bind/zones/db.example.local << 'EOF' $TTL 604800 @ IN SOA ns1.example.local. admin.example.local. ( 2026032401 ; Serial (YYYYMMDD + sequence) 3600 ; Refresh 1800 ; Retry 604800 ; Expire 86400 ) ; Negative Cache TTL ; Name servers @ IN NS ns1.example.local. @ IN NS ns2.example.local. ; A records ns1 IN A 192.168.1.5 ns2 IN A 192.168.1.6 web IN A 192.168.1.10 db IN A 192.168.1.11 mail IN A 192.168.1.12 ; CNAME records www IN CNAME web.example.local. ftp IN CNAME web.example.local. ; MX records @ IN MX 10 mail.example.local. EOF

Reverse Zone File

sudo tee /etc/bind/zones/db.192.168.1 << 'EOF' $TTL 604800 @ IN SOA ns1.example.local. admin.example.local. ( 2026032401 ; Serial 3600 ; Refresh 1800 ; Retry 604800 ; Expire 86400 ) ; Negative Cache TTL @ IN NS ns1.example.local. @ IN NS ns2.example.local. ; PTR records 5 IN PTR ns1.example.local. 6 IN PTR ns2.example.local. 10 IN PTR web.example.local. 11 IN PTR db.example.local. 12 IN PTR mail.example.local. EOF

Validate and Start

# Check main configuration syntax sudo named-checkconf # Check zone files sudo named-checkzone example.local /etc/bind/zones/db.example.local sudo named-checkzone 1.168.192.in-addr.arpa /etc/bind/zones/db.192.168.1 # Restart the service sudo systemctl restart named # Test resolution dig @192.168.1.5 web.example.local dig @192.168.1.5 -x 192.168.1.10 nslookup web.example.local 192.168.1.5

isc-dhcp-server

For large networks or scenarios requiring advanced DHCP features, use a standalone DHCP server.

Note: isc-dhcp-server has reached end-of-life. ISC recommends migrating to Kea DHCP. Both are covered below.

isc-dhcp-server Configuration

# Install sudo apt install isc-dhcp-server -y # Specify the listening interface sudo tee /etc/default/isc-dhcp-server << 'EOF' INTERFACESv4="eth0" INTERFACESv6="" EOF
# Edit the main configuration file sudo tee /etc/dhcp/dhcpd.conf << 'EOF' # Global options option domain-name "example.local"; option domain-name-servers 192.168.1.5, 8.8.8.8; default-lease-time 43200; # 12 hours max-lease-time 86400; # 24 hours authoritative; # Subnet definition subnet 192.168.1.0 netmask 255.255.255.0 { range 192.168.1.100 192.168.1.200; option routers 192.168.1.1; option subnet-mask 255.255.255.0; option broadcast-address 192.168.1.255; option ntp-servers 192.168.1.1; } # Fixed IP assignments host server1 { hardware ethernet aa:bb:cc:dd:ee:01; fixed-address 192.168.1.11; option host-name "server1"; } host server2 { hardware ethernet aa:bb:cc:dd:ee:02; fixed-address 192.168.1.12; option host-name "server2"; } # Group configuration (shared options) group { option domain-name "dev.example.local"; host dev1 { hardware ethernet aa:bb:cc:dd:ee:10; fixed-address 192.168.1.50; } host dev2 { hardware ethernet aa:bb:cc:dd:ee:11; fixed-address 192.168.1.51; } } EOF
# Check configuration syntax sudo dhcpd -t -cf /etc/dhcp/dhcpd.conf # Start the service sudo systemctl restart isc-dhcp-server sudo systemctl enable isc-dhcp-server # View leases cat /var/lib/dhcp/dhcpd.leases
# Install Kea DHCP sudo apt install kea-dhcp4-server -y
# Configure /etc/kea/kea-dhcp4.conf sudo tee /etc/kea/kea-dhcp4.conf << 'EOF' { "Dhcp4": { "interfaces-config": { "interfaces": ["eth0"] }, "lease-database": { "type": "memfile", "persist": true, "name": "/var/lib/kea/dhcp4.leases" }, "valid-lifetime": 43200, "subnet4": [ { "subnet": "192.168.1.0/24", "pools": [ { "pool": "192.168.1.100 - 192.168.1.200" } ], "option-data": [ { "name": "routers", "data": "192.168.1.1" }, { "name": "domain-name-servers", "data": "192.168.1.5, 8.8.8.8" }, { "name": "domain-name", "data": "example.local" } ], "reservations": [ { "hw-address": "aa:bb:cc:dd:ee:01", "ip-address": "192.168.1.11", "hostname": "server1" } ] } ] } } EOF sudo systemctl restart kea-dhcp4-server sudo systemctl enable kea-dhcp4-server

DNS + DHCP Integration

Automatically register DHCP-assigned hostnames in DNS:

dnsmasq Approach (Automatic)

dnsmasq natively supports DNS-DHCP integration. Hostnames sent by DHCP clients are automatically resolvable.

BIND9 + DHCP Dynamic Updates

# Generate a TSIG key tsig-keygen -a hmac-sha256 dhcp-key > /etc/bind/dhcp-key.conf # Include the key in BIND and allow dynamic updates # Add to /etc/bind/named.conf.local: include "/etc/bind/dhcp-key.conf"; zone "example.local" { type master; file "/var/lib/bind/db.example.local"; allow-update { key dhcp-key; }; };

Troubleshooting

# DNS troubleshooting dig @server-ip example.local +trace dig @server-ip example.local +short host example.local server-ip # DHCP troubleshooting sudo journalctl -u isc-dhcp-server -f sudo journalctl -u dnsmasq -f # Check listening ports ss -ulnp | grep -E "(53|67|68)" # Capture DHCP traffic sudo tcpdump -i eth0 port 67 or port 68 -n # Manually request a DHCP lease on the client sudo dhclient -v eth0
Last updated on