User Tools

Site Tools


wireguard

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
wireguard [2026/08/17 21:19] – djgallowaywireguard [2026/08/24 15:23] (current) – djgalloway
Line 207: Line 207:
  
  
-===== More about DNS Configuration on Linux =====+===== DNS Configuration using dnsmasq on Linux =====
  
 If you're using systemd-resolved, stop.  It is incapable of handling split DNS.  I would not use resolvconf. If you're using systemd-resolved, stop.  It is incapable of handling split DNS.  I would not use resolvconf.
Line 255: Line 255:
 Now lookups of shortname or shortname.front or shortname.ipmi should work.  Note that dig does not respect the search domains in /etc/resolv.conf by default; you must use dig +search <domain> Now lookups of shortname or shortname.front or shortname.ipmi should work.  Note that dig does not respect the search domains in /etc/resolv.conf by default; you must use dig +search <domain>
  
 +===== Split DNS on systemd-resolved distros (Fedora, recent Ubuntu, etc.) =====
  
 +If all web browsing / external DNS stops working while connected to the Sepia VPN, but works again after ''sudo resolvectl revert sepia'', your distro is using systemd-resolved and wg-quick has set the lab DNS server as the **default** resolver for all queries — not just Sepia ones.
 +
 +Do **not** use ''resolvectl revert'' as a workaround; it also breaks resolution of lab hostnames. Configure split DNS instead so only Sepia domains are sent to the lab resolver:
 +
 +  - Edit ''/etc/wireguard/sepia.conf''
 +  - **Remove** (or comment out) the ''DNS ='' line
 +  - Add the following lines under ''[Interface]'':
 +
 +<code>
 +PostUp = resolvectl dns %i 10.20.192.13
 +PostUp = resolvectl domain %i ~sepia.ceph.com ~front.sepia.ceph.com ~ipmi.sepia.ceph.com
 +PostUp = resolvectl default-route %i false
 +</code>
 +
 +Then restart the tunnel:
 +
 +<code>
 +sudo wg-quick down sepia && sudo wg-quick up sepia
 +</code>
 +
 +Verify:
 +
 +<code>
 +resolvectl status sepia
 +</code>
 +
 +You should see ''Default Route: no'' and the three sepia domains listed. Lab hostnames (e.g. ''smithi001.front.sepia.ceph.com'') will resolve via the VPN; everything else uses your normal DNS.
 +
 +==== Alternative: NetworkManager ====
 +
 +On Fedora you can instead import the tunnel into NetworkManager, which handles split DNS natively:
 +
 +<code>
 +sudo nmcli connection import type wireguard file /etc/wireguard/sepia.conf
 +sudo nmcli connection modify sepia ipv4.dns-search "~sepia.ceph.com;front.sepia.ceph.com;ipmi.sepia.ceph.com" ipv4.dns-priority 50
 +sudo nmcli connection up sepia
 +</code>
 +
 +Only use one method — don't run wg-quick and the NetworkManager connection at the same time.
wireguard.1787001566.txt.gz · Last modified: by djgalloway