Jump to content

Knot Resolver

From ArchWiki

Knot Resolver (a.k.a. kresd) is a full (recursive), caching DNS resolver. It is designed to scale from small home-office networks to providing DNS servers at the scale of ISPs. Knot Resolver supports DNSSEC validation, which is enabled by default.

Installation

Install the knot-resolver package.

Configuration

Start/enable knot-resolver.service.

To use Knot Resolver as the local resolver, configure 127.0.0.1 and ::1 as your nameservers in resolv.conf(5). For example:

/etc/resolv.conf
nameserver ::1
nameserver 127.0.0.1
options edns0 trust-ad

By default, the resolver will listen on 127.0.0.1 and ::1, ports 53. If the resolver should be accessible from other hosts, configure other network interfaces in /etc/knot-resolver/config.yaml.

/etc/knot-resolver/config.yaml
workers: 2
network:
  listen:
    - interface:
        - 127.0.0.1
        - ::1
  do-ipv4: true
  do-ipv6: true

Refer to Knot Resolver documentation for more information.

Warning Unless you specifically want to run an open DNS resolver, do not configure the resolver to listen on public (internet-facing) IP addresses or all IP addresses (0.0.0.0 and ::).

If the resolver should respect entries from the /etc/hosts file, add the following local-data block with addresses-files.

/etc/knot-resolver/config.yaml
local-data:
  addresses-files:
    - /etc/hosts

Forwarding

Forwarding configuration instructs resolver to forward cache-miss queries from clients to manually specified DNS resolvers or in other words routing queries with specific domains or TLDs to a specific server. This is useful to access to internal (non-routed or private) domains or public alternative top-level domains (like OpenNIC extensions).

To match all queries, use . as subtree value.

/etc/knot-resolver/config.yaml
forward:
  # encrypted public resolver, for all names
  - subtree: .
    servers:
      - address: [ 2001:148f:fffe::1, 193.17.47.1 ]
        transport: tls
        hostname: odvr.nic.cz

  # use a local authoritative server for an internal-only zone
  - subtree: internal.example.com
    servers: [ 10.0.0.53 ]
    options:
      authoritative: true
      dnssec: false

subtree can accept a list of domains or TLDs.

/etc/knot-resolver/config.yaml
forward:
  - subtree:
      - company.example
      - internal.example
    servers:
      - 192.0.2.44
    options:
      authoritative: true
      dnssec: false

More about it on the upstream documentation.


Before starting the service, check your configuration is valid with kresctl.


kresctl validate --strict

Working along dnsmasq

If dnsmasq is used for managing DHCP, then advertising a kresd instance works like any other external DNS server would: By adding an dhcp-option=option:dns-server,<Server Address> line to the dnsmasq configuration file.

Note that a default configuration of dnsmasq will clash with the default configuration of kresd, since both will attempt to use port 53. Disable the dnsmasq DNS functionality (port=0), or assign a different port to either service.

Tips and tricks

Example of configuration for split-forwarding local resolver

This configurations only listen on 127.0.0.1 and ::1 since it's used as local resolver. It will resolve /etc/hosts as well all OpenNIC alternative TLDs (using DNS-over-TLS with custom ports), an local .internal domain on ISP box and fallback for any public domain on Quad9 DNS (with DNSSEC).

/etc/knot-resolver/config.yaml
workers: 2
network:
  listen:
    - interface: lo
  do-ipv4: true
  do-ipv6: true
logging:
  level: info
local-data:
  addresses-files:
    - /etc/hosts
forward:
  - subtree: # OpenNIC alternative TLDs
      - bbs
      - chan
      - cyb
      - dyn
      - epic
      - geek
      - gopher
      - indy
      - libre
      - neo
      - 'null'
      - o
      - oss
      - oz
      - parody
      - pirate
    servers:
      - address: [ 2a03:4000:2b:1217::1@853, 193.31.24.55@853 ] # DE
        transport: tls
        hostname: dns.n4x2.com # ns3.de.dns.opennic.glue
      - address: [ 2a03:4000:006b:0191:9825:1cff:fe34:0bbe@853, 152.53.15.127@853 ] # DE
        transport: tls
        hostname: jabber-germany.de # ns28.de.dns.opennic.glue
      - address: [ 2003:a:133:1500::8@65533, 217.91.179.72@65533 ] # DE
        transport: tls
        hostname: dot.kekew.info # ns27.de.dns.opennic.glue
      - address: [ 2003:a:64b:3b00::4@65533, 80.152.203.134@65533 ] # DE
        transport: tls
        hostname: dot.kekew.info # ns2.de.dns.opennic.glue
      - address: [ 2003:a:812:5700::6@65533, 80.153.146.105@65533 ] # DE
        transport: tls
        hostname: dot.kekew.info # ns4.de.dns.opennic.glue
    options:
      dnssec: false # Most OpenNIC domains are unsigned
  - subtree: internal # Local DNS
    servers:
      - address: [ fe80::6e38:a1ff:febd:a6f, 192.168.1.1 ]
    options:
      dnssec: false
  - subtree: . # Forward everything else to Quad9
    servers:
      - address: [ 2620:fe::fe, 9.9.9.9, 2620:fe::9, 149.112.112.112 ]
        transport: tls
        hostname: dns.quad9.net
    options:
      dnssec: true                 # Enable DNSSEC validation for Quad9

See also