WireGuard隧道下systemd-resolve搜索域配置问题:无法解析mgmt.local域主机
看起来你碰上了WireGuard连接管理网后,systemd-resolved没能正确识别mgmt.local搜索域的麻烦,而且之前一切正常,升级系统和安装KVM/QEMU后就出问题了——我帮你一步步排查解决。
首先看你的配置现状:/etc/resolv.conf里只有home.local的搜索域,而mgmt.local的域需要和WireGuard接口绑定,因为systemd-resolved是按接口来管理DNS配置的,大概率是升级或KVM安装过程中,WireGuard的DNS相关配置被重置或者没正确生效。
解决步骤:
1. 修正WireGuard接口配置
找到你的WireGuard配置文件(通常是/etc/wireguard/wg0.conf,名字可能根据你的接口调整),在[Interface]段添加DNS服务器和搜索域配置:
[Interface] PrivateKey = 你的WireGuard私钥 Address = 你的隧道内IP/子网 # 添加下面两行,替换成你的管理网AD DNS服务器IP DNS = 192.168.x.x # 这里填mgmt.local域的AD控制器DNS地址 Domains = mgmt.local
这里的Domains项会告诉systemd-resolved:所有mgmt.local结尾的域名解析,都走这个WireGuard接口的DNS服务器;而DNS指定了管理网的权威DNS(也就是你的AD控制器)。
2. 重启WireGuard服务使配置生效
执行命令重启WireGuard接口:
sudo wg-quick down wg0 && sudo wg-quick up wg0
然后用resolvectl status wg0检查接口的DNS配置,你应该能看到类似这样的输出:
Link 3 (wg0)
Current Scopes: DNS
Protocols: +DefaultRoute +LLMNR -mDNS -DNSOverTLS DNSSEC=no/unsupported
DNS Servers: 192.168.x.x
DNS Domain: mgmt.local
确认DNS Domain里有mgmt.local,说明配置已经生效。
3. 测试解析是否正常
现在尝试ping或者nslookup测试:
ping vcenter.mgmt.local nslookup vcenter.mgmt.local
如果还是有问题,可以指定用WireGuard接口的DNS来解析,验证DNS服务器本身是否正常:
nslookup vcenter.mgmt.local 192.168.x.x # 替换成你的AD DNS IP
4. 排查潜在的systemd-resolved全局配置问题
如果上面的步骤没解决,检查全局搜索域有没有冲突:
resolvectl
看Global段的DNS Domain,如果全局有设置,接口级的Domains应该会优先生效,但如果全局配置覆盖了,你可以用resolvectl domain wg0 mgmt.local手动给WireGuard接口绑定搜索域,然后重启systemd-resolved服务:
sudo systemctl restart systemd-resolved
为什么之前正常现在出问题?
系统升级或者KVM/QEMU的安装,可能触发了systemd-resolved的配置更新,或者WireGuard的配置文件被意外重置(比如某些包更新会覆盖默认配置模板),导致原本绑定的mgmt.local搜索域丢失了。
备注:内容来源于stack exchange,提问作者per källström

