From Fedora Project Wiki
< Tools | NetworkManager
dnssec-trigger
NetworkManager doesn't work well with dnssec-trigger as unbound DNS server will not recieve the list of recursive nameservers and will thus resolve using the global DNS systems. This is incompatible with VPNs with their own private DNS zones.
firewalld
NetworkManager supports firewall zones for firewalld.