This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revision Both sides next revision | ||
сервис_dns [2020/08/26 06:58] val [Настройка вторичного сервера зоны dns] |
сервис_dns [2020/09/02 10:33] val [Ограничение доступа к DNS серверу] |
||
---|---|---|---|
Line 122: | Line 122: | ||
==== Настройка сервера перенаправляющего запросы на DNS cервер провайдера ==== | ==== Настройка сервера перенаправляющего запросы на DNS cервер провайдера ==== | ||
- | === FreeBSD === | + | === Debian/Ubuntu === |
<code> | <code> | ||
- | server# cat named.conf | + | root@server:~# cat /etc/bind/named.conf.options |
</code><code> | </code><code> | ||
- | options { | ||
... | ... | ||
forwarders { | forwarders { | ||
Line 132: | Line 131: | ||
}; | }; | ||
... | ... | ||
- | }; | + | // dnssec-validation auto; |
... | ... | ||
+ | }; | ||
</code><code> | </code><code> | ||
- | [server:~] # named-checkconf | + | root@server:~# named-checkconf |
- | [server:~] # service named restart | + | root@server:~# service bind9 restart |
</code> | </code> | ||
- | === Debian/Ubuntu === | + | === FreeBSD === |
<code> | <code> | ||
- | root@server:~# cat /etc/bind/named.conf.options | + | server# cat named.conf |
</code><code> | </code><code> | ||
+ | options { | ||
... | ... | ||
forwarders { | forwarders { | ||
Line 149: | Line 150: | ||
}; | }; | ||
... | ... | ||
- | // dnssec-validation auto; | + | }; |
... | ... | ||
- | }; | ||
</code><code> | </code><code> | ||
- | root@server:~# named-checkconf | + | [server:~] # named-checkconf |
- | root@server:~# service bind9 restart | + | [server:~] # service named restart |
</code> | </code> | ||
- | |||
==== Настройка мастер сервера зоны corpX.un ==== | ==== Настройка мастер сервера зоны corpX.un ==== | ||
Line 349: | Line 348: | ||
Создание файла зоны corpX.un для внутренних и внешних пользователей | Создание файла зоны corpX.un для внутренних и внешних пользователей | ||
- | === FreeBSD === | + | === Debian/Ubuntu === |
<code> | <code> | ||
- | [server:~] # cd /usr/local/etc/namedb/master/ | + | server# cat /etc/bind/corpX.un |
- | </code> | + | |
- | + | ||
- | === Ubuntu === | + | |
- | <code> | + | |
- | root@server:~# cd /etc/bind/ | + | |
- | </code> | + | |
- | + | ||
- | === FreeBSD/Ubuntu === | + | |
- | <code> | + | |
- | server# cat corpX.un | + | |
</code><code> | </code><code> | ||
$TTL 3h | $TTL 3h | ||
Line 369: | Line 358: | ||
MX 1 server | MX 1 server | ||
+ | | ||
+ | A 192.168.X.10 | ||
ns A 192.168.X.10 | ns A 192.168.X.10 | ||
Line 384: | Line 375: | ||
MX 1 server | MX 1 server | ||
- | + | ||
+ | A 172.16.1.X | ||
+ | | ||
ns A 172.16.1.X | ns A 172.16.1.X | ||
server A 172.16.1.X | server A 172.16.1.X | ||
Line 393: | Line 386: | ||
Настройка сервера | Настройка сервера | ||
- | === FreeBSD === | ||
- | <code> | ||
- | server# named.conf | ||
- | </code><code> | ||
- | options { | ||
- | ... | ||
- | }; | ||
- | view "inside" { | ||
- | match-clients { | ||
- | 192.168.X/24; | ||
- | 127/8; | ||
- | }; | ||
- | zone "corpX.un" { | ||
- | type master; | ||
- | file "/usr/local/etc/namedb/master/corpX.un"; | ||
- | }; | ||
- | zone "X.168.192.IN-ADDR.ARPA" { | + | === Debian/Ubuntu === |
- | type master; | + | |
- | file "/usr/local/etc/namedb/master/corpX.rev"; | + | |
- | }; | + | |
- | }; | + | |
- | view "outside" { | + | |
- | zone "corpX.un" { | + | |
- | type master; | + | |
- | file "/usr/local/etc/namedb/master/corpX.un.out"; | + | |
- | }; | + | |
- | }; | + | |
- | </code><code> | + | |
- | [server:~] # service named reload | + | |
- | </code> | + | |
- | + | ||
- | === Ubuntu === | + | |
<code> | <code> | ||
root@server:~# cat /etc/bind/named.conf.local | root@server:~# cat /etc/bind/named.conf.local | ||
Line 513: | Line 475: | ||
==== Ограничение доступа к DNS серверу ==== | ==== Ограничение доступа к DNS серверу ==== | ||
- | === Ubuntu === | + | === Debian/Ubuntu === |
<code> | <code> | ||
# cat /etc/bind/named.conf.options | # cat /etc/bind/named.conf.options | ||
- | + | </code><code> | |
- | # cat /etc/bind/named.conf.local | + | |
- | </code> | + | |
- | + | ||
- | === FreeBSD === | + | |
- | <code> | + | |
- | # cat named.conf | + | |
- | </code> | + | |
- | + | ||
- | === Ubuntu/FreeBSD === | + | |
- | <code> | + | |
options { | options { | ||
... | ... | ||
Line 532: | Line 484: | ||
... | ... | ||
}; | }; | ||
- | ... | + | </code><code> |
+ | # cat /etc/bind/named.conf.local | ||
+ | </code><code> | ||
zone "corpX.un" { | zone "corpX.un" { | ||
... | ... | ||
Line 538: | Line 492: | ||
... | ... | ||
}; | }; | ||
- | ... | + | </code><code> |
+ | gate.isp.un$ nslookup -q=AXFR corpX.un 192.168.X.10 | ||
</code> | </code> | ||
+ | |||
==== Мониторинг DNS сервера ==== | ==== Мониторинг DNS сервера ==== |