DNS / DHCP Services
This article explains how to set up DNS and DHCP services on Ubuntu 26.04, including the lightweight dnsmasq solution as well as the full-featured BIND9 and isc-dhcp-server approach.
dnsmasq (Lightweight DNS + DHCP)
dnsmasq provides both DNS caching/forwarding and DHCP services, making it ideal for small networks and home lab environments.
Installation and Configuration
# Ubuntu 26.04 uses systemd-resolved by default, which occupies port 53.
# Recommended (gentler) approach: only disable its DNS stub listener while
# keeping the rest of resolved's functionality.
# Edit /etc/systemd/resolved.conf and set the following in the [Resolve] section:
# DNSStubListener=no
sudo sed -i 's/^#\?DNSStubListener=.*/DNSStubListener=no/' /etc/systemd/resolved.conf
sudo systemctl restart systemd-resolved
# After disabling the stub, the default /etc/resolv.conf still points at the
# now-dead 127.0.0.53, so this host loses DNS immediately (including the
# apt update below). Repoint it to resolved's own upstream results to restore
# local DNS:
sudo ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf
# Alternative approach (fully disable systemd-resolved):
# sudo systemctl stop systemd-resolved
# sudo systemctl disable systemd-resolved
# sudo rm /etc/resolv.conf
# echo "nameserver 8.8.8.8" | sudo tee /etc/resolv.conf
# Install dnsmasq (local DNS is restored now, so apt update will not break)
sudo apt update
sudo apt install dnsmasq -yDNS Configuration
sudo tee /etc/dnsmasq.conf << 'EOF'
# Listen interface
interface=eth0
bind-interfaces
# Upstream DNS servers
server=8.8.8.8
server=1.1.1.1
# DNS cache size
cache-size=1000
# Local domain
domain=homelab.local
local=/homelab.local/
# Custom DNS records (similar to /etc/hosts)
address=/nas.homelab.local/192.168.1.10
address=/router.homelab.local/192.168.1.1
# Also read records from /etc/hosts
expand-hosts
# Logging (enable for debugging)
# log-queries
# log-facility=/var/log/dnsmasq.log
EOFDHCP Configuration
# Append DHCP configuration to /etc/dnsmasq.conf
sudo tee -a /etc/dnsmasq.conf << 'EOF'
# DHCP address pool range and lease time
dhcp-range=192.168.1.100,192.168.1.200,255.255.255.0,12h
# Default gateway
dhcp-option=option:router,192.168.1.1
# DNS server (point to self)
dhcp-option=option:dns-server,192.168.1.5
# NTP server
dhcp-option=option:ntp-server,192.168.1.1
# Domain name
dhcp-option=option:domain-name,homelab.local
# Static IP bindings (MAC address reservations)
dhcp-host=aa:bb:cc:dd:ee:01,server1,192.168.1.11
dhcp-host=aa:bb:cc:dd:ee:02,server2,192.168.1.12
# DHCP lease file
dhcp-leasefile=/var/lib/dnsmasq/dnsmasq.leases
# PXE boot (optional)
# dhcp-boot=pxelinux.0,pxeserver,192.168.1.5
EOFStart the Service
# Test the configuration
dnsmasq --test
# Restart the service
sudo systemctl restart dnsmasq
sudo systemctl enable dnsmasq
# Firewall rules
sudo ufw allow 53/tcp
sudo ufw allow 53/udp
sudo ufw allow 67/udp
sudo ufw allow 68/udp
# Test DNS
dig @localhost homelab.local
nslookup nas.homelab.local 127.0.0.1
# View DHCP leases
cat /var/lib/dnsmasq/dnsmasq.leasesBIND9 (Authoritative DNS Server)
BIND9 is the most widely used DNS server software, suitable for scenarios requiring full DNS functionality.
Installation
sudo apt update
sudo apt install bind9 bind9-utils bind9-dnsutils -y
sudo systemctl enable --now namedMain Configuration
# /etc/bind/named.conf.options
sudo tee /etc/bind/named.conf.options << 'EOF'
options {
directory "/var/cache/bind";
// Forwarding mode
forwarders {
8.8.8.8;
1.1.1.1;
};
forward only;
// Listen addresses
listen-on { 127.0.0.1; 192.168.1.5; };
listen-on-v6 { none; };
// Allowed query clients
allow-query { localhost; 192.168.1.0/24; };
// Allow recursive queries
recursion yes;
allow-recursion { localhost; 192.168.1.0/24; };
// Security settings
dnssec-validation auto;
auth-nxdomain no;
// Hide version number
version "not available";
};
EOFConfigure a Forward Zone
# Add zone declarations
sudo tee /etc/bind/named.conf.local << 'EOF'
// Forward zone
zone "example.local" {
type master;
file "/etc/bind/zones/db.example.local";
allow-transfer { 192.168.1.6; }; // Secondary server IP
};
// Reverse zone
zone "1.168.192.in-addr.arpa" {
type master;
file "/etc/bind/zones/db.192.168.1";
allow-transfer { 192.168.1.6; };
};
EOF
# Create the zone file directory
sudo mkdir -p /etc/bind/zonesForward Zone File
sudo tee /etc/bind/zones/db.example.local << 'EOF'
$TTL 604800
@ IN SOA ns1.example.local. admin.example.local. (
2026032401 ; Serial (YYYYMMDD + sequence)
3600 ; Refresh
1800 ; Retry
604800 ; Expire
86400 ) ; Negative Cache TTL
; Name servers
@ IN NS ns1.example.local.
@ IN NS ns2.example.local.
; A records
ns1 IN A 192.168.1.5
ns2 IN A 192.168.1.6
web IN A 192.168.1.10
db IN A 192.168.1.11
mail IN A 192.168.1.12
; CNAME records
www IN CNAME web.example.local.
ftp IN CNAME web.example.local.
; MX records
@ IN MX 10 mail.example.local.
EOFReverse Zone File
sudo tee /etc/bind/zones/db.192.168.1 << 'EOF'
$TTL 604800
@ IN SOA ns1.example.local. admin.example.local. (
2026032401 ; Serial
3600 ; Refresh
1800 ; Retry
604800 ; Expire
86400 ) ; Negative Cache TTL
@ IN NS ns1.example.local.
@ IN NS ns2.example.local.
; PTR records
5 IN PTR ns1.example.local.
6 IN PTR ns2.example.local.
10 IN PTR web.example.local.
11 IN PTR db.example.local.
12 IN PTR mail.example.local.
EOFValidate and Start
# Check main configuration syntax
sudo named-checkconf
# Check zone files
sudo named-checkzone example.local /etc/bind/zones/db.example.local
sudo named-checkzone 1.168.192.in-addr.arpa /etc/bind/zones/db.192.168.1
# Restart the service
sudo systemctl restart named
# Test resolution
dig @192.168.1.5 web.example.local
dig @192.168.1.5 -x 192.168.1.10
nslookup web.example.local 192.168.1.5isc-dhcp-server
For large networks or scenarios requiring advanced DHCP features, use a standalone DHCP server.
Note:
isc-dhcp-serverhas reached end-of-life. ISC recommends migrating to Kea DHCP. Both are covered below.
isc-dhcp-server Configuration
# Install
sudo apt install isc-dhcp-server -y
# Specify the listening interface
sudo tee /etc/default/isc-dhcp-server << 'EOF'
INTERFACESv4="eth0"
INTERFACESv6=""
EOF# Edit the main configuration file
sudo tee /etc/dhcp/dhcpd.conf << 'EOF'
# Global options
option domain-name "example.local";
option domain-name-servers 192.168.1.5, 8.8.8.8;
default-lease-time 43200; # 12 hours
max-lease-time 86400; # 24 hours
authoritative;
# Subnet definition
subnet 192.168.1.0 netmask 255.255.255.0 {
range 192.168.1.100 192.168.1.200;
option routers 192.168.1.1;
option subnet-mask 255.255.255.0;
option broadcast-address 192.168.1.255;
option ntp-servers 192.168.1.1;
}
# Fixed IP assignments
host server1 {
hardware ethernet aa:bb:cc:dd:ee:01;
fixed-address 192.168.1.11;
option host-name "server1";
}
host server2 {
hardware ethernet aa:bb:cc:dd:ee:02;
fixed-address 192.168.1.12;
option host-name "server2";
}
# Group configuration (shared options)
group {
option domain-name "dev.example.local";
host dev1 {
hardware ethernet aa:bb:cc:dd:ee:10;
fixed-address 192.168.1.50;
}
host dev2 {
hardware ethernet aa:bb:cc:dd:ee:11;
fixed-address 192.168.1.51;
}
}
EOF# Check configuration syntax
sudo dhcpd -t -cf /etc/dhcp/dhcpd.conf
# Start the service
sudo systemctl restart isc-dhcp-server
sudo systemctl enable isc-dhcp-server
# View leases
cat /var/lib/dhcp/dhcpd.leasesKea DHCP (Recommended Replacement)
# Install Kea DHCP
sudo apt install kea-dhcp4-server -y# Configure /etc/kea/kea-dhcp4.conf
sudo tee /etc/kea/kea-dhcp4.conf << 'EOF'
{
"Dhcp4": {
"interfaces-config": {
"interfaces": ["eth0"]
},
"lease-database": {
"type": "memfile",
"persist": true,
"name": "/var/lib/kea/dhcp4.leases"
},
"valid-lifetime": 43200,
"subnet4": [
{
"subnet": "192.168.1.0/24",
"pools": [
{ "pool": "192.168.1.100 - 192.168.1.200" }
],
"option-data": [
{ "name": "routers", "data": "192.168.1.1" },
{ "name": "domain-name-servers", "data": "192.168.1.5, 8.8.8.8" },
{ "name": "domain-name", "data": "example.local" }
],
"reservations": [
{
"hw-address": "aa:bb:cc:dd:ee:01",
"ip-address": "192.168.1.11",
"hostname": "server1"
}
]
}
]
}
}
EOF
sudo systemctl restart kea-dhcp4-server
sudo systemctl enable kea-dhcp4-serverDNS + DHCP Integration
Automatically register DHCP-assigned hostnames in DNS:
dnsmasq Approach (Automatic)
dnsmasq natively supports DNS-DHCP integration. Hostnames sent by DHCP clients are automatically resolvable.
BIND9 + DHCP Dynamic Updates
# Generate a TSIG key
tsig-keygen -a hmac-sha256 dhcp-key > /etc/bind/dhcp-key.conf
# Include the key in BIND and allow dynamic updates
# Add to /etc/bind/named.conf.local:
include "/etc/bind/dhcp-key.conf";
zone "example.local" {
type master;
file "/var/lib/bind/db.example.local";
allow-update { key dhcp-key; };
};Troubleshooting
# DNS troubleshooting
dig @server-ip example.local +trace
dig @server-ip example.local +short
host example.local server-ip
# DHCP troubleshooting
sudo journalctl -u isc-dhcp-server -f
sudo journalctl -u dnsmasq -f
# Check listening ports
ss -ulnp | grep -E "(53|67|68)"
# Capture DHCP traffic
sudo tcpdump -i eth0 port 67 or port 68 -n
# Manually request a DHCP lease on the client
sudo dhclient -v eth0