Knot Resolver
Knot Resolver (a.k.a. kresd) is a full (recursive), caching DNS resolver. It is designed to scale from small home-office networks to providing DNS servers at the scale of ISPs. Knot Resolver supports DNSSEC validation, which is enabled by default.
Installation
Install the knot-resolver package.
Configuration
Start/enable knot-resolver.service.
To use Knot Resolver as the local resolver, configure 127.0.0.1 and ::1 as your nameservers in resolv.conf(5). For example:
/etc/resolv.conf
nameserver ::1 nameserver 127.0.0.1 options edns0 trust-ad
By default, the resolver will listen on 127.0.0.1 and ::1, ports 53. If the resolver should be accessible from other hosts, configure other network interfaces in /etc/knot-resolver/config.yaml.
/etc/knot-resolver/config.yaml
workers: 2
network:
listen:
- interface:
- 127.0.0.1
- ::1
do-ipv4: true
do-ipv6: true
Refer to Knot Resolver documentation for more information.
0.0.0.0 and ::).If the resolver should respect entries from the /etc/hosts file, add the following local-data block with addresses-files.
/etc/knot-resolver/config.yaml
local-data:
addresses-files:
- /etc/hosts
Forwarding
Forwarding configuration instructs resolver to forward cache-miss queries from clients to manually specified DNS resolvers or in other words routing queries with specific domains or TLDs to a specific server. This is useful to access to internal (non-routed or private) domains or public alternative top-level domains (like OpenNIC extensions).
To match all queries, use . as subtree value.
/etc/knot-resolver/config.yaml
forward:
# encrypted public resolver, for all names
- subtree: .
servers:
- address: [ 2001:148f:fffe::1, 193.17.47.1 ]
transport: tls
hostname: odvr.nic.cz
# use a local authoritative server for an internal-only zone
- subtree: internal.example.com
servers: [ 10.0.0.53 ]
options:
authoritative: true
dnssec: false
subtree can accept a list of domains or TLDs.
/etc/knot-resolver/config.yaml
forward:
- subtree:
- company.example
- internal.example
servers:
- 192.0.2.44
options:
authoritative: true
dnssec: false
More about it on the upstream documentation.
Before starting the service, check your configuration is valid with kresctl.
kresctl validate --strict
Working along dnsmasq
If dnsmasq is used for managing DHCP, then advertising a kresd instance works like any other external DNS server would: By adding an dhcp-option=option:dns-server,<Server Address> line to the dnsmasq configuration file.
Note that a default configuration of dnsmasq will clash with the default configuration of kresd, since both will attempt to use port 53. Disable the dnsmasq DNS functionality (port=0), or assign a different port to either service.
Tips and tricks
Example of configuration for split-forwarding local resolver
This configurations only listen on 127.0.0.1 and ::1 since it's used as local resolver. It will resolve /etc/hosts as well all OpenNIC alternative TLDs (using DNS-over-TLS with custom ports), an local .internal domain on ISP box and fallback for any public domain on Quad9 DNS (with DNSSEC).
/etc/knot-resolver/config.yaml
workers: 2
network:
listen:
- interface: lo
do-ipv4: true
do-ipv6: true
logging:
level: info
local-data:
addresses-files:
- /etc/hosts
forward:
- subtree: # OpenNIC alternative TLDs
- bbs
- chan
- cyb
- dyn
- epic
- geek
- gopher
- indy
- libre
- neo
- 'null'
- o
- oss
- oz
- parody
- pirate
servers:
- address: [ 2a03:4000:2b:1217::1@853, 193.31.24.55@853 ] # DE
transport: tls
hostname: dns.n4x2.com # ns3.de.dns.opennic.glue
- address: [ 2a03:4000:006b:0191:9825:1cff:fe34:0bbe@853, 152.53.15.127@853 ] # DE
transport: tls
hostname: jabber-germany.de # ns28.de.dns.opennic.glue
- address: [ 2003:a:133:1500::8@65533, 217.91.179.72@65533 ] # DE
transport: tls
hostname: dot.kekew.info # ns27.de.dns.opennic.glue
- address: [ 2003:a:64b:3b00::4@65533, 80.152.203.134@65533 ] # DE
transport: tls
hostname: dot.kekew.info # ns2.de.dns.opennic.glue
- address: [ 2003:a:812:5700::6@65533, 80.153.146.105@65533 ] # DE
transport: tls
hostname: dot.kekew.info # ns4.de.dns.opennic.glue
options:
dnssec: false # Most OpenNIC domains are unsigned
- subtree: internal # Local DNS
servers:
- address: [ fe80::6e38:a1ff:febd:a6f, 192.168.1.1 ]
options:
dnssec: false
- subtree: . # Forward everything else to Quad9
servers:
- address: [ 2620:fe::fe, 9.9.9.9, 2620:fe::9, 149.112.112.112 ]
transport: tls
hostname: dns.quad9.net
options:
dnssec: true # Enable DNSSEC validation for Quad9