centos7.x 部署主、從DNS服務器

一、準備

例:兩臺192.168.219.146(主), 192.168.219.147(從), 域名www.panyangduola.com

主、從DNS服務器均須要安裝bind、bind-chroot、bind-utils

yum -y install bind bind-utils bind-chroot

若是防火牆開啓,配置防火牆,添加服務(防火牆已禁用則忽略)

firewall-cmd --permanent --add-service=dns
firewall-cmd --reload

二、主DNS服務器(192.168.219.146)配置

編輯配置文件

vim /etc/named.conf

找到其中兩行

  1. listen-on port 53 { 127.0.0.1; };
  2. allow-query { localhost; };

修改成

  1. listen-on port 53 { any; };
  2. allow-query { any; };

2-一、配置正向解析

編輯文件/etc/named.rfc1912.zones,在末尾添加須要解析的域

vim /etc/named.rfc1912.zones
zone "panyangduola.com" IN {
      type master;
      file "data/panyangduola.com.zone";
};

建立panyangduola.com.zone解析域

vim /var/named/data/panyangduola.com.zone
$TTL 3600
$ORIGIN panyangduola.com.
@       IN      SOA   panyangduola.com. admin.panyangduola.com. (
        2018042101
        1D
        1H
        1W
        3H
)
@       IN      NS      ns1.panyangduola.com.
@       IN      NS      ns2.panyangduola.com.
ns1     IN      A       192.168.219.146
ns2     IN      A       192.168.219.147
www     IN      A       192.168.219.146
web     IN      CNAME   www

2-二、配置反向解析

編輯文件/etc/named.rfc1912.zones,在末尾添加須要解析的域

vim /etc/named.rfc1912.zones
zone "219.168.192.in-addr.arpa" IN {
          type master;
          file "data/219.168.192.zone"; 
};

建立219.168.192.zone解析域

vim /var/named/data/219.168.192.zone
$TTL 3600
$ORIGIN  219.168.192.in-addr.arpa.
@       IN      SOA  panyangduola.com. admin.panyangduola.com. (
        2018042101
        1D
        1H
        1W
        3H
)
@       IN      NS      ns1.panyangduola.com.
@       IN      NS      ns2.panyangduola.com.
146      IN      PTR     ns1.panyangduola.com.
147      IN      PTR     ns2.panyangduola.com.
146      IN      PTR     www.panyangduola.com.

2-三、對DNS配置文件進行一下語法檢查:

cd /etc
named-checkconf named.conf
named-checkconf named.rfc1912.zones
cd /var/named/data
named-checkzone panyangduola.com panyangduola.com.zone
named-checkzone 219.168.192.in-addr.arpa 219.168.192.zone

2-四、編輯/etc/resolv.conf,添加

vim /etc/resolv.conf
search localdomain
nameserver 192.168.219.146

2-五、若是2-3步驟沒有錯誤發生的話,啓動named服務

重啓named

systemctl restart named

查看狀態

systemctl status named

2-六、檢查主DNS服務器解析是否成功

ping命令驗證

ping -c 4 www.panyangduola.com

nslookup命令驗證

nslookup
>www.panyangduola.com
nslookup
>192.168.219.146

三、從DNS服務器(192.168.219.147)配置

編輯named.conf文件

vim /etc/named.conf

找到其中兩行  

  1. listen-on port 53 { 127.0.0.1; };   
  2. allow-query { localhost; };

修改成

  1. listen-on port 53 { any; };
  2. allow-query { any; };

3-一、修改主DNS服務器(192.168.219.146)的配置/etc/named.rfc1912.zones

vim /etc/named.rfc1912.zones
zone "panyangduola.com" IN {
      type master;
      file "data/panyangduola.com.zone";
      allow-transfer {192.168.219.147;};
      notify yes;
      also-notify {192.168.219.147;};
};
zone "219.168.192.in-addr.arpa" IN {
      type master;
      file "data/219.168.192.zone";
      allow-transfer {192.168.219.147;}; 
      notify yes;   
      also-notify {192.168.219.147;};  
};

3-二、配置從DNS服務器(192.168.219.147)正向解析

編輯文件/etc/named.rfc1912.zones,在末尾添加須要解析的域

vim /etc/named.rfc1912.zones
zone "panyangduola.com" IN {
  type slave;
  file "data/panyangduola.com.zone";
  masters { 192.168.219.146; };
};

建立panyangduola.com.zone空文件

touch /var/named/data/panyangduola.com.zone

設置全部者  

cd /var/named/data
chown named:named panyangduola.com.zone

3-三、配置從DNS服務器(192.168.219.147)反向解析

在文件/etc/named.rfc1912.zones中添加

vim etc/named.rfc1912.zones
zone "219.168.192.in-addr.arpa" IN {
    type slave;
    file "data/219.168.192.zone";
    masters { 192.168.219.146; };   
};

建立空文件219.168.192.zone

touch /var/named/data/219.168.192.zone

設置全部者

cd /var/named/data
chown named:named 219.168.192.zone

3-四、對DNS配置文件進行一下語法檢查:

cd /etc
named-checkconf named.conf
named-checkconf named.rfc1912.zones

3-五、編輯/etc/resolv.conf,添加

vim /etc/resolv.conf
search localdomain
nameserver 192.168.219.147

3-六、若是3-4步驟沒有錯誤發生的話,啓動named服務

重啓named

systemctl restart named

查看狀態

systemctl status named

3-七、查看文件/var/named/data/panyangduola.com.zone和/var/named/data/219.168.192.zone是否有二進制數據

cat /var/named/data/panyangduola.com.zone
cat /var/named/data/219.168.192.zone

3-八、檢查從DNS服務器解析是否成功

ping命令驗證

ping -c 4 www.panyangduola.com

nslookup命令驗證

nslookup
>192.168.219.147

原文出處:https://www.cnblogs.com/panyangduola/p/11650289.htmlhtml

相關文章
相關標籤/搜索