基於linux下的dns解析的部署
阿新 • • 發佈:2019-01-21
域名系統(Domain Name System縮寫DNS,Domain Name被譯為域名)是因特網的一項核心服務,它作為可以將域名和IP地址相互對映的一個分散式資料庫,能夠使人更方便的訪問網際網路,而不用去記住能夠被機器直接讀取的IP數串。
(1)快取記憶體設定
伺服器:
yum install bing 下載dns伺服器
vim /etc/resolv.conf 配置linux系統DNS伺服器的配置檔案
nameserver 114.114.114.114 設定DNS伺服器的ip地址
systemctl restart network 重啟網路
vim /etc/named.conf dns配置檔案的設定
11 listen-on port 53 { any; }; 設定任何使用者都可以訪問53介面
17 allow-query { any; };
18 forwarders { 114.114.114.114; };
32 dnssec-validation no;
systemctl restart named
ping www.baidu.com (出錯,查詢閘道器設定)
客戶機:
vim /etc/resolv.conf
nameserver 172.25.254.109
驗證:
dig www.baidu.com (第二次查詢速度更快)
(2)DNS正向解析(給定ip求取域名)
vim /etc/resolv.conf
nameserver 172.25.254.109
vim /etc/named.conf
刪除forwarders
systemctl restart named
cp -p /var/named/named.localhost westos.com.zone
vim /etc/named.rfc1912.zones
編輯如下:
zone "westos.com" IN {
type master;
file "westos.com.zone";
allow-update {none;};
};
vim /var/named/westos.com.zone
dig www.westos.com 一個域名對應多個ip
(3)dns反向解析(給定ip求取域名)
vim /etc/named.rfc1912.zones
zone "1.0.0.127.in-addr.arpa" IN {
type master;
file "named.loopback";
allow-update { none; };
};
zone "0.in-addr.arpa" IN {
type master;
file "named.empty";
allow-update { none; };
};
zone "254.25.172.in-addr.arpa" IN {
type master;
file "westos.com.ptr";
allow-update { none; };
};
cd /var/named ls
cp -p named.loopback westos.com.ptr ls
vim westos.com.ptr
NS dns.westos.com.
dns A 172.25.254.109
111 PTR www.westos.com.
222 PTR linux.wetos.com.
systemctl restart named(重啟不了的排錯檢視/var/log/messages)
驗證
dig -x 172.25.254.111
dig -x 172.25.254.222
(4)不同網段的dns解析,雙向解析
伺服器
cd /var/named
cp -p westos.com.zone westos.com.inter
vim westos.com.inter
改變ip
cp -p /etc/named.rfc1912.zones /etc/named.rfc1912.inter
vim /etc/named.rfc1912.inter
vim /etc/named.conf
systemctl restart named
測試
客戶機
vim /etc/resolv.conf
nameserver 172.25.88.56
驗證:
dig www.westos.com 出現改正後的ip
(5)dns的叢集
伺服器
vim /etc/named.rfc1912.zones
輔助伺服器
vim /etc/resolv.conf
nameserver 172.25.254.109
dig www.westos.com
vim /etc/named.rfc1912.zones
systemctl restart named
systemctl stop firewalld
dig www.westos.com
(6) dns的更新
主dns伺服器
cp -p /var/named/westos.com.zone /mnt/
ll -d /var/named
chmod 770 /var/named 賦予目錄下的檔案有寫的許可權
vim /etc/named.rfc1912.zones
getenforce查詢selinux狀態是否為disabled狀態
systemctl restart named
測試機
vim /etc/resolv.conf
檢查nameserver 172.25.254.109
主dns伺服器
systemctl restart named
vim /var/named/westos.com.zone 檢視,test.westos.com 172.25.254.231已更新
cd /var/named
rm -fr westos.com.zone*
cp -p /mnt/westos.com.zone . 進行實驗還原
(6)dns解析加密
vim /etc/rndc.key
dnssec-keygen -a HMAC-MD5 -b 128 -n HOST westos
ls
cat Kwestos.+157+50214.key
cat Kwestos.+157+50214.private
cp /etc/rndc.key /etc/westos.key -p
vim /etc/westos.key
vim /etc/named.conf
vim /etc/named.rfc1912.zones
伺服器
scp Kwestos.+157+50214.* root@172.25.254.9:/mnt 傳送鑰匙給客戶端
客戶端
測試
cd /mnt
ls
伺服器端驗證
systemctl restart named
vim /var/named/westos.com.zone
7)
動態域名解析(花生殼)
主dns伺服器
yum install dhcp
cp /usr/share/doc/dhcp-4.2.5/dhcpd.conf.example /etc/dhcp/dhcpd.conf
vim /etc/dhcp/dhcpd.conf
systemctl restart network
systemctl start dhcpd
測試機
vim /etc/sysconfig/network-scripts/ifcfg-eth0
測試機
systemctl restart network
hostnamectl set-hostname linux.westos.com
dig linux.westos.com
systemctl retsrat network
systemctl restart named
測試機
systemctl restart network
dig wn.westos.com