码迷,mamicode.com
首页 > 系统相关 > 详细

linux-第十三课时笔记-[DNS从域名服务器]-[04]

时间:2017-09-07 19:40:16      阅读:287      评论:0      收藏:0      [点我收藏+]

标签:nes   slave   att   ip add   def   查看   sla   director   修改   

Dns从域名服务器

 

  主机名:ns2.dns.com ip:192.168.200.102

      Nameserver 192.168.200.102

      Nameserver 192.168.200.101

 

  配置

    [root@ns2 Packages]# vim /etc/named.conf

    options {

            listen-on port 53 { 192.168.200.102; };

      //      listen-on-v6 port 53 { ::1; };

              directory       "/var/named";

      //      dump-file       "/var/named/data/cache_dump.db";

      //      statistics-file "/var/named/data/named_stats.txt";

      //      memstatistics-file "/var/named/data/named_mem_stats.txt";

              allow-query     { any; };

       

              /*

               - If you are building an AUTHORITATIVE DNS server, do NOT enable recursion.

               - If you are building a RECURSIVE (caching) DNS server, you need to enable

                 recursion.

               - If your recursive DNS server has a public IP address, you MUST enable access

                 control to limit queries to your legitimate users. Failing to do so will

               cause your server to become part of large scale DNS amplification

               attacks. Implementing BCP38 within your network would greatly

                 reduce such attack surface

            */

            recursion yes;

 

      //      dnssec-enable yes;

      //      dnssec-validation yes;

      //      dnssec-lookaside auto;

       

              /* Path to ISC DLV key */

      //      bindkeys-file "/etc/named.iscdlv.key";

       

      //      managed-keys-directory "/var/named/dynamic";

       

      //      pid-file "/run/named/named.pid";

      //      session-keyfile "/run/named/session.key";

      };

      logging {

              channel default_debug {

                      file "data/named.run";

                    severity dynamic;

            };

      };

      //zone "." IN {

      //      type hint;

      //      file "named.ca";

      //};

 

      //include "/etc/named.rfc1912.zones";

      //include "/etc/named.root.key";

 

      zone "dns.com" IN {

            type slave;

            masters { 192.168.200.101; };

            file "slaves/dns.com.zone";

      };

         

      zone "200.168.192.in-addr.arpa" IN {

              type slave;

              masters { 192.168.200.101; };

              file "slaves/192.168.200.arpa";

      };

 

    检查配置文件:

      [root@ns2 Packages]# named-checkconf /etc/named.conf

       

    启动服务查看结果:

      [root@ns2 Packages]# /usr/sbin/named -u named   #因为是centos7

      [root@ns2 Packages]#

      [root@ns2 Packages]# ll /var/named/slaves/

      total 8

      -rw-r--r--. 1 named named 534 Sep  7 17:53 192.168.200.arpa

      -rw-r--r--. 1 named named 444 Sep  7 17:53 dns.com.zone

      [root@ns2 Packages]# 

       

    修改客户机dns

      [root@client ~]# vim /etc/resolv.conf

        # Generated by NetworkManager

        nameserver 192.168.200.102

        nameserver 192.168.200. 101

       

    结果:

       技术分享

   

域名更新 修改日期+1  重启会同步!

 

 

linux-第十三课时笔记-[DNS从域名服务器]-[04]

标签:nes   slave   att   ip add   def   查看   sla   director   修改   

原文地址:http://www.cnblogs.com/msl23/p/7491206.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!