Показаны различия между двумя версиями страницы.
| — |
bind9-1 [2026/06/11 12:15] (текущий) |
||
|---|---|---|---|
| Строка 1: | Строка 1: | ||
| + | ====== Сервер Доменных Имен- Domain Name Service (DNS) ====== | ||
| + | |||
| + | Чтобы установить DNS сервер, | ||
| + | Находясь в терминале выполните две команды, | ||
| + | |||
| + | < | ||
| + | |||
| + | Вторая пакет с утилитами для проверки и тестирования работы сервера DNS: | ||
| + | |||
| + | < | ||
| + | |||
| + | ====== Конфигурирование сервера ====== | ||
| + | |||
| + | |||
| + | Как Вы можете настроить свой BIND9. | ||
| + | Имеется несколько вариантов, | ||
| + | |||
| + | * When configured as a caching nameserver BIND9 will find the answer to name queries and remember the answer when the domain is queried again. | ||
| + | * As a primary master server BIND9 reads the data for a zone from a file on it's host and is authoritative for that zone. | ||
| + | * In a secondary master configuration BIND9 gets the zone data from another nameserver authoritative for the zone. | ||
| + | |||
| + | ===== Overview ===== | ||
| + | |||
| + | |||
| + | The DNS configuration files are stored in the /etc/bind directory. The primary configuration file is / | ||
| + | |||
| + | The include line specifies the filename which contains the DNS options. The directory line in the / | ||
| + | |||
| + | The file named / | ||
| + | |||
| + | It is possible to configure the same server to be a caching name server, primary master, and secondary master. A server can be the Start of Authority (SOA) for one zone, while providing secondary service for another zone. All the while providing caching services for hosts on the local LAN. | ||
| + | |||
| + | ===== Сервер кэширования доменных имен ===== | ||
| + | |||
| + | |||
| + | По умолчанию первичные настройки предполагаю использование DNS сервера, | ||
| + | |||
| + | < | ||
| + | 1.2.3.4; | ||
| + | 5.6.7.8; | ||
| + | | ||
| + | |||
| + | {{: | ||
| + | |||
| + | |||
| + | Перезагрузите ваш DNS сервер, | ||
| + | |||
| + | < | ||
| + | |||
| + | Смотрите раздел “dig”, чтобы проверить работу Вашего вновь созданного сервера кэширования доменных имен. | ||
| + | |||
| + | ===== Первичный DNS сервер (Primary Master) ===== | ||
| + | |||
| + | |||
| + | В этом разделе настроим BIND9, как Primary Master. В качестве примера будем использовать в качестве примера имя example.com. Вы можете заменить его на то которое у Вас есть. | ||
| + | Работаем с файлом Forward Zone | ||
| + | |||
| + | To add a DNS zone to BIND9, turning BIND9 into a Primary Master server, the first step is to edit / | ||
| + | |||
| + | < | ||
| + | type master; | ||
| + | file "/ | ||
| + | };</ | ||
| + | |||
| + | Now use an existing zone file as a template to create the / | ||
| + | |||
| + | < | ||
| + | |||
| + | Edit the new zone file / | ||
| + | |||
| + | Also, create an A record for ns.example.com. The name server in this example: | ||
| + | < | ||
| + | ; | ||
| + | ; BIND data file for local loopback interface | ||
| + | ; | ||
| + | $TTL 604800 | ||
| + | @ | ||
| + | 2 ; Serial | ||
| + | | ||
| + | 86400 ; Retry | ||
| + | 2419200 | ||
| + | | ||
| + | ; | ||
| + | @ | ||
| + | @ | ||
| + | @ | ||
| + | ns IN A | ||
| + | |||
| + | You must increment the Serial Number every time you make changes to the zone file. If you make multiple changes before restarting BIND9, simply increment the Serial once. | ||
| + | |||
| + | Now, you can add DNS records to the bottom of the zone file. See the section called “Common Record Types” for details. | ||
| + | |||
| + | {{: | ||
| + | |||
| + | Once you have made a change to the zone file BIND9 will need to be restarted for the changes to take effect: | ||
| + | |||
| + | < | ||
| + | |||
| + | ===== Reverse Zone File ===== | ||
| + | |||
| + | |||
| + | Now that the zone is setup and resolving names to IP Adresses a Reverse zone is also required. A Reverse zone allows DNS to resolve an address to a name. | ||
| + | |||
| + | Edit / | ||
| + | |||
| + | < | ||
| + | type master; | ||
| + | notify no; | ||
| + | file "/ | ||
| + | };</ | ||
| + | |||
| + | {{: | ||
| + | |||
| + | Now create the / | ||
| + | |||
| + | sudo cp / | ||
| + | |||
| + | Next edit / | ||
| + | |||
| + | ; | ||
| + | ; BIND reverse data file for local loopback interface | ||
| + | ; | ||
| + | $TTL 604800 | ||
| + | @ | ||
| + | 2 ; Serial | ||
| + | | ||
| + | 86400 ; Retry | ||
| + | 2419200 | ||
| + | | ||
| + | ; | ||
| + | @ | ||
| + | 10 IN PTR | ||
| + | |||
| + | The Serial Number in the Reverse zone needs to be incremented on each changes as well. For each A record you configure in / | ||
| + | |||
| + | After creating the reverse zone file restart BIND9: | ||
| + | |||
| + | sudo / | ||
| + | |||
| + | ===== Secondary Master ===== | ||
| + | |||
| + | |||
| + | Once a Primary Master has been configured a Secondary Master is needed in order to maintain the availability of the domain should the Primary become unavailable. | ||
| + | |||
| + | First, on the Primary Master server, the zone transfer needs to be allowed. Add the allow-transfer option to the example Forward and Reverse zone definitions in / | ||
| + | |||
| + | zone " | ||
| + | type master; | ||
| + | file "/ | ||
| + | allow-transfer { 192.168.1.11; | ||
| + | }; | ||
| + | |||
| + | zone " | ||
| + | type master; | ||
| + | notify no; | ||
| + | file "/ | ||
| + | allow-transfer { 192.168.1.11; | ||
| + | }; | ||
| + | |||
| + | FIXME | ||
| + | |||
| + | Replace 192.168.1.11 with the IP Address of your Secondary nameserver. | ||
| + | |||
| + | Next, on the Secondary Master, install the bind9 package the same way as on the Primary. Then edit the / | ||
| + | |||
| + | zone " | ||
| + | type slave; | ||
| + | file "/ | ||
| + | masters { 192.168.1.10; | ||
| + | }; | ||
| + | | ||
| + | zone " | ||
| + | type slave; | ||
| + | file "/ | ||
| + | masters { 192.168.1.10; | ||
| + | }; | ||
| + | |||
| + | [Note] | ||
| + | |||
| + | Replace 192.168.1.10 with the IP Address of your Primary nameserver. | ||
| + | |||
| + | Restart BIND9 on the Secondary Master: | ||
| + | |||
| + | sudo / | ||
| + | |||
| + | In / | ||
| + | |||
| + | slave zone " | ||
| + | slave zone " | ||
| + | |||
| + | [Note] | ||
| + | |||
| + | Note: A zone is only transferred if the Serial Number on the Primary is larger than the one on the Secondary. | ||
| + | [Note] | ||
| + | |||
| + | The default directory for non-authoritative zone files is / | ||
| + | |||
| + | ===== Troubleshooting ===== | ||
| + | |||
| + | |||
| + | This section covers ways to help determine the cause when problems happen with DNS and BIND9. | ||
| + | Testing | ||
| + | resolv.conf | ||
| + | |||
| + | The first step in testing BIND9 is to add the nameserver' | ||
| + | |||
| + | nameserver 192.168.1.10 | ||
| + | nameserver 192.168.1.11 | ||
| + | |||
| + | [Note] :!: | ||
| + | |||
| + | You should also add the IP Address of the Secondary nameserver in case the Primary becomes unavailable. | ||
| + | dig | ||
| + | |||
| + | If you installed the dnsutils package you can test your setup using the DNS lookup utility dig: | ||
| + | |||
| + | * | ||
| + | |||
| + | After installing BIND9 use dig against the loopback interface to make sure it is listening on port 53. From a terminal prompt: | ||
| + | |||
| + | dig -x 127.0.0.1 | ||
| + | |||
| + | You should see lines similar to the following in the command output: | ||
| + | |||
| + | ;; Query time: 1 msec | ||
| + | ;; SERVER: 192.168.1.10# | ||
| + | |||
| + | * | ||
| + | |||
| + | If you have configured BIND9 as a Caching nameserver " | ||
| + | |||
| + | dig ubuntu.com | ||
| + | |||
| + | Note the query time toward the end of the command output: | ||
| + | |||
| + | ;; Query time: 49 msec | ||
| + | |||
| + | After a second dig there should be improvement: | ||
| + | |||
| + | ;; Query time: 1 msec | ||
| + | |||
| + | ping | ||
| + | |||
| + | Now to demonstrate how applications make use of DNS to resolve a host name use the ping utility to send an ICMP echo request. From a terminal prompt enter: | ||
| + | |||
| + | ping example.com | ||
| + | |||
| + | This tests if the nameserver can resolve the name ns.example.com to an IP Address. The command output should resemble: | ||
| + | |||
| + | PING ns.example.com (192.168.1.10) 56(84) bytes of data. | ||
| + | 64 bytes from 192.168.1.10: | ||
| + | 64 bytes from 192.168.1.10: | ||
| + | |||
| + | named-checkzone | ||
| + | |||
| + | A great way to test your zone files is by using the named-checkzone utility installed with the bind9 package. This utility allows you to make sure the configuration is correct before restarting BIND9 and making the changes live. | ||
| + | |||
| + | * | ||
| + | |||
| + | To test our example Forward zone file enter the following from a command prompt: | ||
| + | |||
| + | named-checkzone example.com / | ||
| + | |||
| + | If everything is configured correctly you should see output similar to: | ||
| + | |||
| + | zone example.com/ | ||
| + | OK | ||
| + | |||
| + | * | ||
| + | |||
| + | Similarly, to test the Reverse zone file enter the following: | ||
| + | |||
| + | named-checkzone example.com / | ||
| + | |||
| + | The output should be similar to: | ||
| + | |||
| + | zone example.com/ | ||
| + | OK | ||
| + | |||
| + | [Note] | ||
| + | |||
| + | The Serial Number of your zone file will probably be different. | ||
| + | Logging | ||
| + | |||
| + | BIND9 has a wide variety of logging configuration options available. There are two main options. The channel option configures where logs go, and the category option determines what information to log. | ||
| + | |||
| + | If no logging option is configured the default option is: | ||
| + | |||
| + | logging { | ||
| + | | ||
| + | | ||
| + | }; | ||
| + | |||
| + | This section covers configuring BIND9 to send debug messages related to DNS queries to a separate file. | ||
| + | |||
| + | * | ||
| + | |||
| + | First, we need to configure a channel to specify which file to send the messages to. Edit / | ||
| + | |||
| + | logging { | ||
| + | channel query.log { | ||
| + | file "/ | ||
| + | severity debug 3; | ||
| + | }; | ||
| + | }; | ||
| + | |||
| + | * | ||
| + | |||
| + | Next, configure a category to send all DNS queries to the query file: | ||
| + | |||
| + | logging { | ||
| + | channel query.log { | ||
| + | file "/ | ||
| + | severity debug 3; | ||
| + | }; | ||
| + | category queries { query.log; }; | ||
| + | }; | ||
| + | |||
| + | [Note] | ||
| + | |||
| + | Note: the debug option can be set from 1 to 3. If a level isn't specified level 1 is the default. | ||
| + | |||
| + | * | ||
| + | |||
| + | Since the named daemon runs as the bind user the / | ||
| + | |||
| + | sudo touch / | ||
| + | sudo chown bind / | ||
| + | |||
| + | * | ||
| + | |||
| + | Before named daemon can write to the new log file the AppArmor profile must be updated. First, edit / | ||
| + | |||
| + | / | ||
| + | |||
| + | Next, reload the profile: | ||
| + | |||
| + | cat / | ||
| + | |||
| + | For more information on AppArmor see the section called “AppArmor” | ||
| + | * | ||
| + | |||
| + | Now restart BIND9 for the changes to take effect: | ||
| + | |||
| + | sudo / | ||
| + | |||
| + | You should see the file / | ||
| + | |||
| + | ===== References ===== | ||
| + | |||
| + | **Common Record Types** | ||
| + | |||
| + | This section covers some of the most common DNS record types. | ||
| + | |||
| + | * | ||
| + | |||
| + | A record: This record maps an IP Address to a hostname. | ||
| + | |||
| + | www IN A 192.168.1.12 | ||
| + | |||
| + | * | ||
| + | |||
| + | CNAME record: Used to create an alias to an existing A record. You cannot create a CNAME record pointing to another CNAME record. | ||
| + | |||
| + | web | ||
| + | |||
| + | * | ||
| + | |||
| + | MX record: Used to define where email should be sent to. Must point to an A record, not a CNAME. | ||
| + | |||
| + | IN MX 1 | ||
| + | mail IN A | ||
| + | |||
| + | * | ||
| + | |||
| + | NS record: Used to define which servers serve copies of a zone. It must point to an A record, not a CNAME. This is where Primary and Secondary servers are defined. | ||
| + | |||
| + | IN NS | ||
| + | IN NS | ||
| + | ns IN A 192.168.1.10 | ||
| + | ns2 IN | ||
| + | | ||
| + | |||
| + | ===== More Information ===== | ||
| + | |||
| + | * | ||
| + | |||
| + | The DNS HOWTO explains more advanced options for configuring BIND9. | ||
| + | * | ||
| + | |||
| + | For in depth coverage of DNS and BIND9 see Bind9.net. | ||
| + | * | ||
| + | |||
| + | DNS and BIND is a popular book now in it's fifth edition. | ||
| + | * | ||
| + | |||
| + | A great place to ask for BIND9 assistance, and get involved with the Ubuntu Server community, is the # | ||
| + | * | ||
| + | |||
| + | Also, see the BIND9 Server HOWTO in the Ubuntu Wiki. | ||
| + | | ||