diff --git a/docs/modules/ROOT/pages/administration/dnsmasq.adoc b/docs/modules/ROOT/pages/administration/dnsmasq.adoc index 9eb01a7..fa10175 100644 --- a/docs/modules/ROOT/pages/administration/dnsmasq.adoc +++ b/docs/modules/ROOT/pages/administration/dnsmasq.adoc @@ -184,16 +184,33 @@ Allow ports for DHCP and DNS (53) service on the public interface. […]# firewall-cmd --list-all ---- -6. Restart NetworkManager to start dnsmasq +6. Disabling the systemd-resolved stub resolver ++ +Inhibit the stub resolver and remove the symlink /etc/resolv.conf so that Network Manager will generate a new resolv.conf directing queries to dnsmasq. For more info, see the man page for "systemd-resolved" under the heading "/ETC/RESOLV.CONF". + [source,] ---- + […]# find /etc/resolv.conf -printf '%p -> %l\n' + /etc/resolv.conf -> ../run/systemd/resolve/stub-resolv.conf + […]# rm -f /etc/resolv.conf + […]# mkdir -p /etc/systemd/resolved.conf.d + […]# echo -e "[Resolve]\nDNSStubListener=no" > /etc/systemd/resolved.conf.d/no-stub-listener.conf +---- + +7. Restart systemd-resolved and restart NetworkManager to start dnsmasq ++ +The first time we restart systemd-resolved, it will no longer be running the stub resolver. The second time, we are reloading the configuration to prompt systemd-resolved to re-assess the /etc/resolv.conf generated by NetworkManager, but systemd-resolved does not support the "reload" unit command. ++ +[source,] +---- + […]# systemctl restart systemd-resolved […]# systemctl restart NetworkManager + […]# systemctl restart systemd-resolved ---- + NetworkManager adjusts now the nameserver entries in /etc/resolv. They are replaced by 127.0.0.1 and processed via dnsmasq. -7. Test the installation +8. Test the installation a. The dnsmasp internal self test + [source,]