溫馨提示×

您好,登錄后才能下訂單哦!

密碼登錄×
登錄注冊(cè)×
其他方式登錄
點(diǎn)擊 登錄注冊(cè) 即表示同意《億速云用戶服務(wù)條款》

Centos7搭建主從DNS服務(wù)器的教程

發(fā)布時(shí)間:2020-09-06 16:41:32 來(lái)源:腳本之家 閱讀:130 作者:桄椿 欄目:服務(wù)器

1、準(zhǔn)備

例:兩臺(tái)192.168.11.10(主),192.168.11.11(從),域名www.test1.com

# 主從DNS服務(wù)器均需要安裝bind、bind-chroot、bind-utils
yum -y install bind bind-utils bind-chroot
# 如果防火墻開(kāi)啟,配置防火墻,添加服務(wù)(防火墻已禁用則忽略)
firewall-cmd --permanent --add-service=dns
firewall-cmd --reload

2、主DNS服務(wù)器(192.168.11.10)配置

# 編輯配置文件
vim /etc/named.conf
# 找到其中兩行
  listen-on port 53 { 127.0.0.1; }; 
  allow-query { localhost; };
# 修改為
  listen-on port 53 { any; };
  allow-query   { any; };

3、配置正向解析

# 編輯文件/etc/named.rfc1912.zones,在末尾添加需要解析的域
  zone "test1.com" IN {
   type master;
   file "data/test1.com.zone";
};
# 創(chuàng)建test1.com.zone解析域
vim /var/named/data/test1.com.zone
  $TTL 3H 
  @     IN SOA test1.com. root (
                        20180928 ; serial 
                        1D ; refresh 
                        1H ; retry 
                        1W ; expire 
                        3H ) ; minimum 
       IN   NS   @
       IN   A   192.168.11.10
  www   IN   A   192.168.11.10
  ftp   IN   A   192.168.11.10
# 編輯/etc/resolv.conf,添加
  search localdomain
  nameserver 192.168.11.10

4、重啟DNS服務(wù)器

# 重啟named
systemctl restart named
# 查看狀態(tài)
systemctl status named

5、檢查解析是否成功

# ping命令驗(yàn)證
ping -c 4 www.test1.com
# 輸出如下即解析成功
  PING www.test1.com (192.168.11.10) 56(84) bytes of data.
  64 bytes from ftp.test1.com (192.168.11.10): icmp_seq=1 ttl=64 time=0.033 ms
  64 bytes from ftp.test1.com (192.168.11.10): icmp_seq=2 ttl=64 time=0.058 ms
  64 bytes from ftp.test1.com (192.168.11.10): icmp_seq=3 ttl=64 time=0.066 ms
  64 bytes from ftp.test1.com (192.168.11.10): icmp_seq=4 ttl=64 time=0.057 ms
  --- www.test1.com ping statistics ---
  4 packets transmitted, 4 received, 0% packet loss, time 3000ms
  rtt min/avg/max/mdev = 0.033/0.053/0.066/0.014 ms
# nslookup命令驗(yàn)證
nslookup
>www.test1.com
# 輸出如下即解析成功
  Server:    192.168.11.10
  Address:  192.168.11.10#53
  Name:  www.test1.com
  Address: 192.168.11.10

6、配置反向解析

# 編輯文件/etc/named.rfc1912.zones,在末尾添加 
vim etc/named.rfc1912.zones
  zone "11.168.192.in-addr.arpa" IN {
     type master;
     file "data/11.168.192.zone"; 
  };
# 創(chuàng)建11.168.192.zone解析域
vim /var/named/data/11.168.192.zone
  $TTL 3H
  @    IN SOA  web3.com. root (
                    20180928; serial
                    1D   ; refresh
                    1H   ; retry
                    1W   ; expire
                    3H )  ; minimum
  @   IN   NS    www.test1.com.
  10   IN   PTR   www.test1.com.
  10   IN   PTR   ftp.test1.com.

7、重啟DNS服務(wù)器

# 重啟named
systemctl restart named
# 查看狀態(tài)
systemctl status named

8、檢查解析是否成功

# ping命令驗(yàn)證
ping -c 4 192.168.11.10
# 輸出如下即解析成功
  PING 192.168.11.10 (192.168.11.10) 56(84) bytes of data.
  64 bytes from 192.168.11.10: icmp_seq=1 ttl=64 time=0.061 ms
  64 bytes from 192.168.11.10: icmp_seq=2 ttl=64 time=0.058 ms
  64 bytes from 192.168.11.10: icmp_seq=3 ttl=64 time=0.081 ms
  64 bytes from 192.168.11.10: icmp_seq=4 ttl=64 time=0.060 ms
  --- 192.168.11.10 ping statistics ---
  4 packets transmitted, 4 received, 0% packet loss, time 3000ms
  rtt min/avg/max/mdev = 0.058/0.065/0.081/0.009 ms
# nslookup命令驗(yàn)證
nslookup 192.168.11.10
# 輸出如下即解析成功
  Server:    192.168.11.10
  Address:    192.168.11.10#53
  10.11.168.192.in-addr.arpa  name = ftp.test1.com.
  10.11.168.192.in-addr.arpa  name = www.test1.com.

9、配置從DNS服務(wù)器(192.168.11.11)

# 先修改主DNS服務(wù)器(192.168.11.10)的配置/etc/named.rfc1912.zones
vim /etc/named.rfc1912.zones
  zone "test1.com" IN {
   type master;
   file "data/test1.com.zone";
   allow-transfer {192.168.11.11;};
      notify       yes;
      also-notify {192.168.11.11;};
};
  zone "11.168.192.in-addr.arpa" IN {
   type master;
   file "data/11.168.192.zone";
   allow-transfer {192.168.11.11;}; 
      notify       yes;  
      also-notify {192.168.11.11;}; 
};

10、配置從DNS服務(wù)器(192.168.11.11)正向解析

# 編輯named.conf文件
vim /etc/named.conf
  # 找到其中兩行  
  listen-on port 53 { 127.0.0.1; };   
  allow-query { localhost; };
  # 修改為
  listen-on port 53 { any; };
  allow-query   { any; };
# 編輯文件/etc/named.rfc1912.zones,在末尾添加需要解析的域 
vim /etc/named.rfc1912.zones
  zone "test1.com" IN { 
      type slave; 
      file "data/test1.com.zone"; }; 
      masters { 192.168.11.10; };
# 創(chuàng)建test1.com.zonek空文件 
touch /var/named/data/test1.com.zone 
# 設(shè)置所有者  
chown named:named test1.com.zone
# 編輯/etc/resolv.conf,添加
vim /etc/resolv.conf
  search localdomain
  nameserver 192.168.11.11

11、重啟DNS服務(wù)器

# 重啟named
systemctl restart named
# 查看狀態(tài)
systemctl status named

12、檢測(cè)解析是否成功

# ping命令驗(yàn)證
ping -c 4 www.test1.com
# 輸出如下即解析成功
  PING www.test1.com (192.168.11.10) 56(84) bytes of data.
  64 bytes from ftp.test1.com (192.168.11.10): icmp_seq=1 ttl=64 time=0.033 ms
  64 bytes from ftp.test1.com (192.168.11.10): icmp_seq=2 ttl=64 time=0.058 ms
  64 bytes from ftp.test1.com (192.168.11.10): icmp_seq=3 ttl=64 time=0.066 ms
  64 bytes from ftp.test1.com (192.168.11.10): icmp_seq=4 ttl=64 time=0.057 ms
  --- www.test1.com ping statistics ---
  4 packets transmitted, 4 received, 0% packet loss, time 3000ms
  rtt min/avg/max/mdev = 0.033/0.053/0.066/0.014 ms
# nslookup命令驗(yàn)證
nslookup
>www.test1.com
# 輸出如下即解析成功
  Server:    192.168.11.11
  Address:  192.168.11.11#53
  Name:  www.test1.com
  Address: 192.168.11.10

13、配置從DNS服務(wù)器(192.168.11.11)反向解析

# 在文件/etc/named.rfc1912.zones中添加 
vim etc/named.rfc1912.zones
  zone "11.168.192.in-addr.arpa" IN {
     type master;
     file "data/11.168.192.zone";
      masters { 192.168.11.10; };   
};
# 創(chuàng)建空文件11.168.192.zone
touch /var/named/data/11.168.192.zone
# 設(shè)置所有者  
chown named:named 11.168.192.zone

14、重啟DNS服務(wù)器

# 重啟named
systemctl restart named
# 查看狀態(tài)
systemctl status named

15、查看文件/var/named/data/test1.com.zone和/var/named/data/11.168.192.zone是否有二進(jìn)制數(shù)據(jù)

cat /var/named/data/test1.com.zone
cat /var/named/data/11.168.192.zone

16、檢查解析是否成功

# ping命令驗(yàn)證
ping -c 4 192.168.11.11
# 輸出如下即解析成功
  PING 192.168.11.11 (192.168.11.11) 56(84) bytes of data.
  64 bytes from 192.168.11.11: icmp_seq=1 ttl=64 time=0.061 ms
  64 bytes from 192.168.11.11: icmp_seq=2 ttl=64 time=0.058 ms
  64 bytes from 192.168.11.11: icmp_seq=3 ttl=64 time=0.081 ms
  64 bytes from 192.168.11.11: icmp_seq=4 ttl=64 time=0.060 ms
  --- 192.168.11.11 ping statistics ---
  4 packets transmitted, 4 received, 0% packet loss, time 3000ms
  rtt min/avg/max/mdev = 0.058/0.065/0.081/0.009 ms
# nslookup命令驗(yàn)證
nslookup 192.168.11.11
# 輸出如下即解析成功
  Server:    192.168.11.11
  Address:    192.168.11.11#53
  10.11.168.192.in-addr.arpa  name = ftp.test1.com.
  10.11.168.192.in-addr.arpa  name = www.test1.com.

總結(jié)

以上所述是小編給大家介紹的Centos7搭建主從DNS服務(wù)器的教程,希望對(duì)大家有所幫助,如果大家有任何疑問(wèn)請(qǐng)給我留言,小編會(huì)及時(shí)回復(fù)大家的。在此也非常感謝大家對(duì)億速云網(wǎng)站的支持!
如果你覺(jué)得本文對(duì)你有幫助,歡迎轉(zhuǎn)載,煩請(qǐng)注明出處,謝謝!

向AI問(wèn)一下細(xì)節(jié)

免責(zé)聲明:本站發(fā)布的內(nèi)容(圖片、視頻和文字)以原創(chuàng)、轉(zhuǎn)載和分享為主,文章觀點(diǎn)不代表本網(wǎng)站立場(chǎng),如果涉及侵權(quán)請(qǐng)聯(lián)系站長(zhǎng)郵箱:is@yisu.com進(jìn)行舉報(bào),并提供相關(guān)證據(jù),一經(jīng)查實(shí),將立刻刪除涉嫌侵權(quán)內(nèi)容。

AI