Une option par ligne :
<option>=<valeur>
les options valides sont les mêmes que celles sur la ligne de commande.
Pour plus de détails, voir
...@...:~$ /usr/sbin/dnsmasq --help
ou
...@...:~$ man 8 dnsmasq
; port=5353
; domain-needed et bogus-priv
; domain-needed
; bogus-priv
; conf-file et dnssec
; conf-file=%%PREFIX%%/share/dnsmasq/trust-anchors.conf
; dnssec
; dnssec-check-unsigned
; filterwin2k
; resolv-file=
; strict-order
; no-resolv
; no-poll
; server
; server=/localnet/192.168.0.1
; server=/3.168.192.in-addr.arpa/10.1.2.3
; server=10.1.2.3@eth1
; server=10.1.2.3@192.168.1.1#55
; local
; local=/localnet/
; address
; address=/double-click.net/127.0.0.1
; address=/www.thekelleys.org.uk/fe80::20d:60ff:fe36:f83
; ipset
; ipset=/yahoo.com/google.com/vpn,search
; server
; user et group
; user=
; group=
; interface, except-interface, listen-address, no-dhcp-interface
; interface=
; except-interface=
; listen-address=
; no-dhcp-interface=
; bind-interfaces
; no-hosts
; addn-hosts=/etc/banner_add_hosts
; expand-hosts
; domain
; domain=thekelleys.org.uk
; domain=wireless.thekelleys.org.uk,192.168.2.0/24
; domain=reserved.thekelleys.org.uk,192.68.3.100,192.168.3.200
; dhcp-range
; dhcp-range=192.168.0.50,192.168.0.150,12h
; dhcp-range=192.168.0.50,192.168.0.150,255.255.255.0,12h
; dhcp-range=set:red,192.168.0.50,192.168.0.150
; dhcp-range=tag:green,192.168.0.50,192.168.0.150,12h
; dhcp-range=192.168.0.0,static
; dhcp-range=1234::2, 1234::500, 64, 12h
; dhcp-range=1234::, ra-only
; dhcp-range=1234::, ra-names
; dhcp-range=1234::, ra-only, 48h
; dhcp-range=1234::2, 1234::500, slaac
; dhcp-range=1234::, ra-stateless
; dhcp-range=1234::, ra-stateless, ra-names
; enable-ra
; dhcp-host
; dhcp-host=11:22:33:44:55:66,192.168.0.60
; dhcp-host=11:22:33:44:55:66,fred
; dhcp-host=11:22:33:44:55:66,fred,192.168.0.60,45m
; dhcp-host=11:22:33:44:55:66,12:34:56:78:90:12,192.168.0.60
; dhcp-host=bert,192.168.0.70,infinite
; dhcp-host=id:01:02:02:04,192.168.0.60
; dhcp-host=id:ff:00:00:00:00:00:02:00:00:02:c9:00:f4:52:14:03:00:28:05:81,192.168.0.61
; dhcp-host=id:marjorie,192.168.0.60
; dhcp-host=judge
; dhcp-host=11:22:33:44:55:66,ignore
; dhcp-host=11:22:33:44:55:66,id:*
; dhcp-host=11:22:33:44:55:66,set:red
; dhcp-host=11:22:33:*:*:*,set:red
; dhcp-host=id:00:01:00:01:16:d2:83:fc:92:d4:19:e2:d8:b2, fred, [1234::5]
; dhcp-ignore=tag:!known
; dhcp-vendorclass=set:red,Linux
; dhcp-userclass=set:red,accounts
; dhcp-mac=set:red,00:60:8C:*:*:*
; read-ethers
; dhcp-option
; dhcp-option=3,1.2.3.4
; dhcp-option=option:router,1.2.3.4
; dhcp-option=3
; dhcp-option=option:ntp-server,192.168.0.4,10.10.0.5
; dhcp-option=option6:dns-server,[1234::77],[1234::88]
; dhcp-option=option6:dns-server,[::],[1234::88]
; dhcp-option=option6:information-refresh-time,6h
; dhcp-option=option:T1,1m
; dhcp-option=option:T2,2m
; dhcp-option=42,0.0.0.0
; dhcp-option=40,welly
; dhcp-option=23,50
; dhcp-option=27,1
; dhcp-option=128,e4:45:74:68:00:00
; dhcp-option = tag:red, option:ntp-server, 192.168.1.1
; The following DHCP options
; dhcp-option=19,0
; dhcp-option=44,0.0.0.0
; dhcp-option=45,0.0.0.0
; dhcp-option=46,8
; dhcp-option=252,“\n”
; dhcp-option=option:domain-search,eng.apple.com,marketing.apple.com
; dhcp-option=121,192.168.1.0/24,1.2.3.4,10.0.0.0/8,5.6.7.8
; dhcp-option=vendor:PXEClient,1,0.0.0.0
; dhcp-option=vendor:MSFT,2,1i
; dhcp-option=vendor:Etherboot,60,“Etherboot”
; dhcp-option-force
; dhcp-option-force=208,f1:00:74:7e
; dhcp-option-force=209,configs/common
; dhcp-option-force=210,/tftpboot/pxelinux/files/
; dhcp-option-force=211,30i
; dhcp-boot
; dhcp-boot=pxelinux.0
; dhcp-boot=pxelinux,server.name,192.168.1.100
; Boot for iPXE
; dhcp-boot=undionly.kpxe
; dhcp-match=set:ipxe,175 # iPXE sends a 175 option.
; dhcp-boot=tag:ipxe,http://boot.ipxe.org/demo/boot.php
; Encapsulated options for iPXE.
; dhcp-option=encap:175, 1, 5b
; dhcp-option=encap:175, 176, 1b
; dhcp-option=encap:175, 177, string
; dhcp-option=encap:175, 189, 1b
; dhcp-option=encap:175, 190, user
; dhcp-option=encap:175, 191, pass
; dhcp-match
; dhcp-match=peecees, option:client-arch, 0 #x86-32
; pxe-prompt=“What system shall I netboot?”
; pxe-prompt=“Press F8 for menu.”, 60
; pxe-service
; pxe-service=x86PC, “Boot from local disk”
; pxe-service=x86PC, “Install Linux”, pxelinux
; pxe-service=x86PC, “Install Linux”, pxelinux, 1.2.3.4
; pxe-service=x86PC, “Install windows from RIS server”, 1
; pxe-service=x86PC, “Install windows from RIS server”, 1, 1.2.3.4
; multicast-FTP
; enable-tftp
; tftp-root=/var/ftpd
; tftp-no-fail
; tftp-secure
; tftp-no-blocksize
; dhcp-boot
; dhcp-boot=tag:red,pxelinux.red-net
; dhcp-boot=/var/ftpd/pxelinux.0,boothost,192.168.0.3
; dhcp-boot=/var/ftpd/pxelinux.0,boothost,tftp_server_name
; dhcp-lease
; dhcp-lease-max=150
; dhcp-leasefile=/var/lib/misc/dnsmasq.leases
; dhcp-authoritative
; dhcp-rapid-commit
; dhcp-script=/bin/echo
; cache-size=150
; no-negcache
; local-ttl=
Normally responses which come from /etc/hosts and the DHCP lease file have Time-To-Live set as zero, which conventionally means do not cache further. If you are happy to trade lower load on the server for potentially stale date, you can set a time-to-live (in seconds) here. ; bogus-nxdomain=64.94.110.11 : If you want dnsmasq to detect attempts by Verisign to send queries to unregistered .com and .net hosts to its sitefinder service and have dnsmasq instead return the correct NXDOMAIN response, uncomment this line. You can add similar lines to do the same for other registries which have implemented wildcard A records. ; alias : If you want to fix up DNS results from upstream servers, use the alias option. This only works for IPv4. ; alias=1.2.3.4,5.6.7.8 : This alias makes a result of 1.2.3.4 appear as 5.6.7.8 ; alias=1.2.3.0,5.6.7.0,255.255.255.0 : and this maps 1.2.3.x to 5.6.7.x ; alias=192.168.0.10-192.168.0.40,10.0.0.0,255.255.255.0 : and this maps 192.168.0.10->192.168.0.40 to 10.0.0.10->10.0.0.40 ; MX records : Change these lines if you want dnsmasq to serve MX records. ; mx-host=maildomain.com,servermachine.com,50 : Return an MX record named "maildomain.com" with target servermachine.com and preference 50 ; mx-target=servermachine.com : Set the default target for MX records created using the localmx option. ; localmx : Return an MX record pointing to the mx-target for all local machines. ; selfmx : Return an MX record pointing to itself for all local machines. ; srv-host : Change the following lines if you want dnsmasq to serve SRV records. These are useful if you want to serve ldap requests for Active Directory and other windows-originated DNS requests. : See RFC 2782. : You may add multiple srv-host lines. : The fields are <name>,<target>,<port>,<priority>,<weight> : If the domain part if missing from the name (so that is just has the service and protocol sections) then the domain given by the domain= config option is used. (Note that expand-hosts does not need to be set for this to work.) ; srv-host=_ldap._tcp.example.com,ldapserver.example.com,389 : A SRV record sending LDAP for the example.com domain to ldapserver.example.com port 389 ; domain=example.com\\ srv-host=_ldap._tcp,ldapserver.example.com,389 : A SRV record sending LDAP for the example.com domain to ldapserver.example.com port 389 (using domain=) ; srv-host=_ldap._tcp.example.com,ldapserver.example.com,389,1\\ srv-host=_ldap._tcp.example.com,ldapserver.example.com,389,2 : Two SRV records for LDAP, each with different priorities ; srv-host=_ldap._tcp.example.com : A SRV record indicating that there is no LDAP server for the domain example.com ; ptr-record=_http._tcp.dns-sd-services,"New Employee Page._http._tcp.dns-sd-services" : The following line shows how to make dnsmasq serve an arbitrary PTR record. This is useful for DNS-SD. (Note that the domain-name expansion done for SRV records _does_not occur for PTR records.) ; txt-record : Change the following lines to enable dnsmasq to serve TXT records. : These are used for things like SPF and zeroconf. (Note that the domain-name expansion done for SRV records _does_not occur for TXT records.) ; txt-record=example.com,"v=spf1 a -all" : Example SPF. ; txt-record=_http._tcp.example.com,name=value,paper=A4 : Example zeroconf ; cname=bertand,bert : Provide an alias for a "local" DNS name. Note that this _only_ works for targets which are names from DHCP or /etc/hosts. Give host "bert" another name, bertrand ; log-queries : For debugging purposes, log each DNS query as it passes through dnsmasq. ; log-dhcp : Log lots of extra information about DHCP transactions. ; conf-file=/etc/dnsmasq.more.conf ; conf-dir=/etc/dnsmasq.d : Include another lot of configuration options. ; conf-dir=/etc/dnsmasq.d,.bak : Include all the files in a directory except those ending in .bak ; conf-dir=/etc/dnsmasq.d/,*.conf : Include all files in a directory which end in .conf ; dhcp-name-match=set:wpad-ignore,wpad ; dhcp-ignore-names=tag:wpad-ignore : If a DHCP client claims that its name is "wpad", ignore that. : This fixes a security hole. see CERT Vulnerability VU#598349
===== Voir aussi =====
Basé sur « Article » par Auteur.