1. 程式人生 > >Linux DNS主從配置

Linux DNS主從配置

linux

Linux主從DNS配置

系統環境:CentOS 6.5

主DNS服務器:dns1.test.com 172.16.1.20

輔DNS服務器:dns2.test.com 172.16.1.30

主DNS配置:yum –y installbind bind-utils bind-libs bind-chroot(可選)

/etc/named.conf

//

// named.conf

//

// Provided by Red Hat bind package to configure the ISC BINDnamed(8) DNS

// server as a caching only nameserver (as a localhost DNSresolver only).

//

// See /usr/share/doc/bind*/sample/ for example namedconfiguration files.

//

options {

listen-on port 53 { any; };

listen-on-v6 port 53 { ::1; };

directory "/var/named";

dump-file "/var/named/data/cache_dump.db";

statistics-file"/var/named/data/named_stats.txt";

memstatistics-file"/var/named/data/named_mem_stats.txt";

allow-query { any; };

recursion yes;

// dnssec-enable yes;

// dnssec-validationyes;

// dnssec-lookasideauto;

bindkeys-file"/etc/named.iscdlv.key";

managed-keys-directory "/var/named/dynamic";

};

logging {

channeldefault_debug {

file"data/named.run";

severitydynamic;

};

};

file"named.ca";

};

include "/etc/named.rfc1912.zones";

include "/etc/named.root.key";

/etc/named.rfc1912.zones

// named.rfc1912.zones:

//

// Provided by Red Hat caching-nameserver package

//

// ISC BIND named zone configuration for zones recommended by

// RFC 1912 section 4.1 : localhost TLDs and address zones

// andhttp://www.ietf.org/internet-drafts/draft-ietf-dnsop-default-local-zones-02.txt

// (c)2007 R W Franks

//

// See /usr/share/doc/bind*/sample/ for example namedconfiguration files.

//

zone "localhost.localdomain" IN {

type master;

file"named.localhost";

allow-update {none; };

};

zone "localhost" IN {

type master;

file"named.localhost";

allow-update {none; };

};

zone"1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa"IN {

type master;

file"named.loopback";

allow-update {none; };

};

zone "1.0.0.127.in-addr.arpa" IN {

type master;

file"named.loopback";

allow-update {none; };

};

zone "0.in-addr.arpa" IN {

type master;

file"named.empty";

allow-update {none; };

};

zone "test.com" IN {

type master;

file "test.com.zone";

notify yes;

also-notify {172.16.1.30; };

allow-transfer {172.16.1.30; };

allow-update { none; };

};

zone "1.16.172.in-addr.arpa" IN {

type master;

file "1.16.172.zone";

notifyyes;

also-notify {172.16.1.30; };

allow-transfer {172.16.1.30; };

allow-update { none; };

};

/var/named/test.com.zone

$TTL 1D

@ IN SOA @ rname.invalid. (

5 ; serial

1D ; refresh

1H ; retry

1W ; expire

3H ) ; minimum

NS @

A 172.16.1.20

A 172.16.1.30

dns1 A 172.16.1.20

dns2 A 172.16.1.30

www A 172.16.1.40

/var/named/1.16.172.zone

$TTL 1D

@ IN SOA @ rname.invalid. (

5 ; serial

1D ; refresh

1H ; retry

1W ; expire

3H ) ; minimum

NS test.com.

20 PTR test.com.

30 PTR test.com.

20 PTR dns1.test.com.

30 PTR dns2.test.com.

40 PTR www.test.com.

/etc/resolv.conf

; generated by /sbin/dhclient-script

nameserver 172.16.1.20

nameserver 172.16.1.30

service named restart

輔DNS配置:yum –y installbind bind-utils bind-libs bind-chroot(可選)

/etc/named.conf

//

// named.conf

//

// Provided by Red Hat bindpackage to configure the ISC BIND named(8) DNS

// server as a caching onlynameserver (as a localhost DNS resolver only).

//

// See/usr/share/doc/bind*/sample/ for example named configuration files.

//

options {

# listen-on port 53 { 127.0.0.1; };

# listen-on-v6 port 53 { ::1; };

directory "/var/named";

dump-file "/var/named/data/cache_dump.db";

statistics-file"/var/named/data/named_stats.txt";

memstatistics-file"/var/named/data/named_mem_stats.txt";

# allow-query { localhost; };

recursion yes;

// dnssec-enable yes;

// dnssec-validation yes;

// dnssec-lookaside auto;

/* Path to ISC DLV key */

bindkeys-file"/etc/named.iscdlv.key";

managed-keys-directory"/var/named/dynamic";

};

logging {

channel default_debug {

file"data/named.run";

severity dynamic;

};

};

zone "." IN {

type hint;

file "named.ca";

};

include"/etc/named.rfc1912.zones";

include"/etc/named.root.key";

/etc/named.rfc1912.zones

// named.rfc1912.zones:

//

// Provided by Red Hat caching-nameserver package

//

// ISC BIND named zone configuration for zones recommended by

// RFC 1912 section 4.1 : localhost TLDs and address zones

// and http://www.ietf.org/internet-drafts/draft-ietf-dnsop-default-local-zones-02.txt

// (c)2007 R W Franks

//

// See /usr/share/doc/bind*/sample/ for example namedconfiguration files.

//

zone "localhost.localdomain" IN {

type master;

file"named.localhost";

allow-update { none; };

};

zone "localhost" IN {

type master;

file"named.localhost";

allow-update {none; };

};

zone"1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa"IN {

type master;

file"named.loopback";

allow-update {none; };

};

zone "1.0.0.127.in-addr.arpa" IN {

type master;

file"named.loopback";

allow-update {none; };

};

zone "0.in-addr.arpa" IN {

type master;

file "named.empty";

allow-update {none; };

};

zone "test.com" IN {

type slave;

file"slaves/slave.test.com.zone";

masters {172.16.1.20; };

};

zone "1.16.172.in-addr.arpa" IN {

type slave;

file "slaves/slave.1.16.172.zone";

masters {172.16.1.20; };

};

/etc/resolv.conf

; generated by /sbin/dhclient-script

nameserver 172.16.1.20

nameserver 172.16.1.30

service named restart

註意:

  1. 1. bind-chroot這個包主要功能是將DNS服務器在chroot模式下運行,在這種模式下運行的話,它會將所有和DNS相關的文件都鎖定到/var/named/chroot目錄下,就是說bind的訪問範圍僅僅定位於這個目錄中,無法進一步提升到系統中的其它目錄,這樣可以提高系統的安全性。這樣聽起來很美,但是配置起來會出現許多的問題,建議不要使用。如果你使用了的話,所有配置修改需要到/var/named/chroot下,例如配置文件在/var/named/chroot/etc/named.conf。

  2. 2. 確認一下/var/named/test.com.zone文件權限,所屬組是named。

  3. 3. 放行防火墻規則,或者關閉防火墻。

  4. 4. 修改主DNS服務器上test.com.zone和1.16.172.zone區域文件時,增加主機記錄,需修改serial值,修改完成後,使用service named reload重新加載配置文件,這樣才能同步到輔DNS服務器。


Linux DNS主從配置