创建密钥
$ cd /usr/local/bind $ sbin/dnssec-keygen -a hmac-md5 -b 128 -n HOST worldhello.![]()
创建配置文件:etc/rndc.conf
rndc: 远程域名服务控制器(The remote name daemon control:rndc)。是管理员用来控制域名服务器的应用程序,用于动态加载、停止、配置 DNS服务。它需要的配置文件为 /etc/rndc.conf:
key worldhello. {
algorithm "hmac-md5";
secret "nvNpPbfDZixmFzqSUVJn6w==";
};
options {
default-server localhost;
default-key worldhello. ;
};
server localhost {
key worldhello. ;
};
创建配置文件:etc/named.conf
named.conf 是域名服务器的主配置文件。zone 是配置文件中的最重要的组成部分,描述了一个授权域名下的域名解析信息。一个复杂的配置例子如下:
key worldhello. {
algorithm "hmac-md5";
secret "nvNpPbfDZixmFzqSUVJn6w==";
};
controls {
inet 127.0.0.1 allow { localhost; } keys { worldhello.; };
};
acl bogus-nets { 0.0.0.0/8; 1.0.0.0/8; 2.0.0.0/8;};
acl our-inner-nets { 127.0.0.1/32; 10.0.0.0/8; };
acl our-outer-nets { 192.168.0.0/16; };
acl transfer-inner-ips { 10.0.0.2; };
acl transfer-outer-ips { 192.168.0.2; };
options {
version "$Id, worldhello.net";
directory "/var/named";
allow-query { any; };
allow-recursion { our-inner-nets; our-outer-nets; };
blackhole { bogus-nets; };
notify yes;
recursion yes;
forward first;
forwarders{
202.106.0.20;
};
listen-on-v6 { none; };
auth-nxdomain no;
};
view "internal" {
match-clients { our-inner-nets; };
recursion yes;
zone "0.0.127.in-addr.arpa"{
type master;
file "named.local";
notify no;
};
zone "0.0.10.in-addr.arpa"{
type master;
file "named.10.0.0";
notify yes;
allow-transfer{ transfer-inner-ips; };
};
zone "worldhello.net"{
type master;
file "named.inner.worldhello.net";
allow-query { any; };
allow-transfer{ transfer-inner-ips; };
notify yes;
};
};
view "external" {
match-clients { any; };
recursion no;
zone "0.0.127.in-addr.arpa"{
type master;
file "named.local";
notify no;
};
zone "0.0.10.in-addr.arpa"{
type master;
file "named.10.0.0";
notify yes;
allow-transfer{ transfer-inner-ips; };
};
zone "worldhello.net"{
type master;
file "named.outer.worldhello.net";
allow-query { any; };
allow-transfer{ transfer-outer-ips; };
notify yes;
};
};
/var/named/named.local
$TTL 3600
@ IN SOA localhost. root.localhost. (
2001030801 ; serial
28800 ; refresh
14400 ; retry
3600000 ; expire
86400 ; default_ttl
)
@ IN NS localhost.
1 IN PTR localhost.
; End of File
/var/named/named.10.0.0
$TTL 3600
@ IN SOA ns1.worldhello.net. johnson.worldhello.net. (
2001030801 ; serial
600 ; refresh
600 ; retry
3600000 ; expire
3400 ; default_ttl
)
@ IN NS ns1.worldhello.net.
@ IN NS ns2.worldhello.net.
1 IN PTR ns1.worldhello.net.
2 IN PTR ns2.worldhello.net.
10 IN PTR johnson.worldhello.net.
; End of File
/var/named/named.inner.worldhello.net
$TTL 3600
@ IN SOA ns1.worldhello.net. johnson.worldhello.net. (
2001021802 ; serial
300 ; refresh
300 ; retry
7200000 ; expire
3600 ; default_ttl
)
@ IN NS ns1.worldhello.net.
@ IN NS ns2.worldhello.net.
@ IN MX 5 mail.worldhello.net.
@ IN MX 10 mail2.worldhello.net.
@ IN A 10.0.0.1
localhost IN A 127.0.0.1
ns1 IN A 10.0.0.1
ns2 IN A 10.0.0.2
johnson IN A 10.0.0.10
www IN A 10.0.0.1
mail IN A 10.0.0.2
mail2 IN A 10.0.0.3
* IN CNAME johnson
/var/named/named.outer.worldhello.net
$TTL 3600
@ IN SOA ns1.worldhello.net. johnson.worldhello.net. (
2001021802 ; serial
300 ; refresh
300 ; retry
7200000 ; expire
3600 ; default_ttl
)
@ IN NS ns1.worldhello.net.
@ IN NS ns2.worldhello.net.
@ IN MX 5 mail.worldhello.net.
@ IN MX 10 mail2.worldhello.net.
@ IN A 192.169.0.100
localhost IN A 127.0.0.1
ns1 IN A 192.168.0.1
ns2 IN A 192.168.0.2
www IN A 192.168.0.1
johnson IN A 192.168.0.10
mail IN A 192.168.0.2
mail2 IN A 192.168.0.3
/var/named/named.192.168.0
$TTL 3600
@ IN SOA ns1.worldhello.net. johnson.worldhello.net. (
2001030801 ; serial
600 ; refresh
600 ; retry
3600000 ; expire
3400 ; default_ttl
)
@ IN NS ns2.worldhello.net.
@ IN NS ns1.worldhello.net.
1 IN PTR ns1.worldhello.net.
2 IN PTR ns2.worldhello.net.
10 IN PTR johnson.worldhello.net.
; End of File
Copyright © 2006 WorldHello 开放文档之源 计划 |