Difference between revisions of "Dnsmasq"

From ArchWiki
Jump to: navigation, search
(DHCP Server Setup)
(DHCP Server Setup)
Line 31: Line 31:
(Deprecated since the removal of tcp_wrappers from the official repos) If you choose not to bind the interfaces, the domain port will need to be allowed in {{ic|/etc/hosts.allow}}:
(Deprecated since the removal of {{AUR|tcp_wrappers}} from the official repos). If you choose not to bind the interfaces, the domain port will need to be allowed in {{ic|/etc/hosts.allow}}:
  domain ALL : ALLOW
  domain ALL : ALLOW

Revision as of 17:46, 24 April 2012

This template has only maintenance purposes. For linking to local translations please use interlanguage links, see Help:i18n#Interlanguage links.

Local languages: Català – Dansk – English – Español – Esperanto – Hrvatski – Indonesia – Italiano – Lietuviškai – Magyar – Nederlands – Norsk Bokmål – Polski – Português – Slovenský – Česky – Ελληνικά – Български – Русский – Српски – Українська – עברית – العربية – ไทย – 日本語 – 正體中文 – 简体中文 – 한국어

External languages (all articles in these languages should be moved to the external wiki): Deutsch – Français – Română – Suomi – Svenska – Tiếng Việt – Türkçe – فارسی

Dnsmasq provides services as a DNS cacher and a DHCP server. As a Domain Name Server (DNS), it can cache DNS queries to improve connection speed to previously visited sites. As a DHCP server, dnsmasq can be used to provide internal IP addresses and routes to computers on a LAN. Either or both of these services can be implemented. Dnsmasq is considered to be lightweight and easy to configure; it is designed for personal computer use or for use on a network with less than 50 computers.


Install dnsmasq from the official repositories.

DHCP Server Setup

The Dnsmasq configuration file needs to be configured (/etc/dnsmasq.conf). The most likely settings you'll need to configure are:

# Only listen to routers' LAN NIC.  Doing so opens up tcp/udp port 53 to
# localhost and udp port 67 to world:

# dnsmasq will open tcp/udp port 53 and udp port 67 to world to help with
# dynamic interfaces (assigning dynamic ips). Dnsmasq will discard world
# requests to them, but the paranoid might like to close them and let the 
# kernel handle them:

# Dynamic range of IPs to make available to LAN pc

# If you’d like to have dnsmasq assign static IPs, bind the LAN computer's
# NIC MAC address:

(Deprecated since the removal of tcp_wrappersAUR from the official repos). If you choose not to bind the interfaces, the domain port will need to be allowed in /etc/hosts.allow:

domain ALL : ALLOW

DNS Cache Setup

If you set up Dnsmasq as a DHCP server, it is already setup to record DNS queries and relay them to an internal network. To set up Dnsmasq as a DNS caching daemon on a single computer edit /etc/dnsmasq.conf and add the localhost listening address:


If you use this computer to act as a default DNS specify the (fixed) IP-addresse of this computer instead of

listen-address= #replace this with the IP-address of your computer

After you have configured Dnsmasq, you will need to tell your DHCP client to prepend the localhost address to the known DNS addresses file (/etc/resolv.conf). This sends all queries to Dnsmasq first before trying to resolve them to an external DNS server. After your DHCP client is configured, you will need to restart the network for changes to take effect.


dhcpcd has the ability to prepend or append nameservers to /etc/resolv.conf by creating (or editing) the /etc/resolv.conf.head and /etc/resolv.conf.tail files respectively:

echo "nameserver" > /etc/resolv.conf.head


If you use dhclient, you will need to add to (or create) to /etc/dhclient.conf:

prepend domain-name-servers;


Since the upgrade of NetworkManager to 0.7, Arch Linux now calls dhcpcd directly instead of the common default with dhclient. Because of the arguments set with dhcpcd, it no longer sources the /etc/resolv.conf.head, and /etc/resolv.conf.tail settings for insertion of name servers. There are three workarounds to fix this:

The first would be to use NetworkManager with dhclient which can be found in networkmanager-dhclientAUR.

The second workaround would be to go into NetworkManagers' settings (usually by right-clicking the applet) and entering your settings manually. Depending on the type of front-end you use for NetworkManager, the process usually involves right-clicking on the applet, editing (or creating) a profile, and then choosing DHCP type as 'Automatic (specify addresses).' The DNS ddresses are usually entered in such form:, DNS-server-one, ....

The third workaround is to put a script like this in /etc/Networkmanager/dispatcher.d/ and do not forget to make it executable:

# Override /etc/resolv.conf and tell
# NetworkManagerDispatcher to go pluck itself.
# scripts in the /etc/NetworkManager/dispatcher.d/ directory
# are called alphabetically and are passed two parameters:
# $1 is the interface name, and $2 is "up" or "down" as the
# case may be.
# Here, no matter what interface or state, override the
# created resolver config with my config.
cp -f /etc/resolv.conf.myDNSoverride /etc/resolv.conf

Then create a file with the nameservers (in this case opendns ones), according to what you specified on the script (/etc/resolv.conf.myDNSoverride):


Of course you'll have to start the daemon networkmanager-dispatcher.

Alternatively, if you want to keep your current resolv.conf file, use a script similar to

# Creates a copy of resolv.conf with "nameserver" as first line.  
cat - /etc/resolv.conf <<<"nameserver"  > /etc/resolv.conf.new
cp -f /etc/resolv.conf.new /etc/resolv.conf

Start the Daemon

Dnsmasq runs as a daemon. But before we start it, let's do a quick check of what our current speed for resolving is by issuing this command (dig is part of the dnsutils package) :

$ dig archlinux.org | grep Query

Now let's start it :

# /etc/rc.d/dnsmasq start

To have dnsmasq to load upon startup, add dnsmasq to your daemons array in /etc/rc.conf:

DAEMONS=(network dnsmasq ...)

To see if dnsmasq started properly, check the log; dnsmasq sends its messages to /var/log/messages.log. You will also need to restart the network so that dhcpd can recreate /etc/resolv.conf.

# /etc/rc.d/network restart

Now we will test our DNS lookup and measure the time response :

$ dig archlinux.org | grep "Query time"

The Query time should have decreased. Also if you remove the grep, you can see the server used (the line under Query time), and now it should be localhost aka

Test DHCP Server

From a computer that is connected to the one with dnsmasq on it, configure it to use DHCP for automatic IP address assignment, then attempt to log into the network as you normally would.


Prevent OpenDNS Redirecting Google Queries

To prevent OpenDNS from redirecting all Google queries to their own search server, add to /etc/dnsmasq.conf:


Replace X.X.X.X with your ISP's DNS server/Router IP.