- named.conf 重點內容
- Slave 主機向 Master 要求傳送 Zone File 的時機
- Zone File 檔案結構
named.conf 重點內容
Master:Slave 主機向 Master 要求傳送 Zone File 的時機
vi /etc/named.confSlave:
acl “trusted” { 127.0.0.1; 192.168.1.0/24; };
options {
allow-recursion { trusted; }; //避免變成 Open DNS};
allow-transfer { none; }; //預設禁止 Zone Transfer
notify no; //預設不通知轄區 DNS Server
zone “mydomain.com” in {
type master;};
file “mydomain.com.zone”;
allow-transfer { slave.ip.address; };
notify yes;
zone “1.168.192.in-addr.arpa” in {
type master;};
file “192.168.1.zone”;
allow-transfer { slave.ip.address; };
notify yes;
vi /etc/named.conf
zone “mydomain.com” in {
type slave;};
file “slave/mydomain.com.zone”;
masters { master.ip.address; };
zone “1.168.192.in-addr.arpa” in {
type slave;};
file “slave/192.168.1.zone”;
masters { master.ip.address; };
- master 主機上的 named 啟動、Reload 時, 發送 dns notify 信號通知 NS 主機 (除本身外) 比對 zone file serial, 且 master serial 大於 slave serial 時.
- slave 主機上的 named 啟動時, 發現 master serial 大於 slave serial, 或無 zone file 存在時.
- slave 主機每隔 refresh 時間, 向 master 查詢 zone file serial, 發現 master serial 大於 slave serial 時.
Forward Lookup / 正解Resources:
Reverse Lookup / 反解
$TTL 1W @ IN SOA master_dns_fqdn zone_admin ( 2006092001 ;serial 2D ;refresh 4H ;retry 6W ;expire 1W ) ;TTL IN NS master_dns_fqdn IN NS slave_dns_fqdn IN MX 10 mail_server_fqdn master_dns_hostname IN A ip_address slave_dns_hostname IN A ip_address mail_server_hostname IN A ip_address some_hostname IN CNAME another_hostname_has_A_record
Ref: Microsoft Support – Description of DNS Reverse Lookups
$TTL 1W @ IN SOA master_dns_fqdn zone_admin ( 2006092001 ;serial 2D ;refresh 4H ;retry 6W ;expire 1W ) ;TTL IN NS master_dns_fqdn entry_in_*.in-addr.arpa IN PTR some_host_fqdn
ex1. zone: 20.10.150.in-addr.arpa
in the zone file: 1 IN PTR ms1.mydomain.com
retult: ms1.mydomain.com=150.10.20.1ex2. zone: 10.150.in-addr.arpa
in the zone file: 2.20 IN PTR ms1.mydomain.com
retult: ms1.mydomain.com=150.10.20.2
Root Domain Zone File: ftp://ftp.internic.net/domain/named.root
- BIND Official Website
- PHP5 網管實驗室 – 於 Fedora Core 上的 bind 設定
- 鳥哥的 Linux 私房菜 – 簡易 DNS 伺服器設定
- Study Area – 架設 DNS
沒有留言:
張貼留言