欢迎您访问程序员文章站本站旨在为大家提供分享程序员计算机编程知识!
您现在的位置是: 首页  >  科技

centos7.x 部署主、从DNS服务器

程序员文章站 2022-06-14 16:02:39
1、准备 例:两台192.168.219.146(主), 192.168.219.147(从), 域名www.panyangduola.com 主、从DNS服务器均需要安装bind、bind chroot、bind utils [^_^]: (This is a comment, it will n ......

1、准备

例:两台192.168.219.146(主), 192.168.219.147(从), 域名www.panyangduola.com

主、从dns服务器均需要安装bind、bind-chroot、bind-utils

yum -y install bind bind-utils bind-chroot

如果防火墙开启,配置防火墙,添加服务(防火墙已禁用则忽略)

firewall-cmd --permanent --add-service=dns
firewall-cmd --reload

2、主dns服务器(192.168.219.146)配置

编辑配置文件

vim /etc/named.conf

找到其中两行

  1. listen-on port 53 { 127.0.0.1; };
  2. allow-query { localhost; };

    修改为

  3. listen-on port 53 { any; };
  4. allow-query { any; };

2-1、配置正向解析

编辑文件/etc/named.rfc1912.zones,在末尾添加需要解析的域

vim /etc/named.rfc1912.zones
zone "panyangduola.com" in {
      type master;
      file "data/panyangduola.com.zone";
};

创建panyangduola.com.zone解析域

vim /var/named/data/panyangduola.com.zone
$ttl 3600
$origin panyangduola.com.
@       in      soa   panyangduola.com. admin.panyangduola.com. (
        2018042101
        1d
        1h
        1w
        3h
)
@       in      ns      ns1.panyangduola.com.
@       in      ns      ns2.panyangduola.com.
ns1     in      a       192.168.219.146
ns2     in      a       192.168.219.147
www     in      a       192.168.219.146
web     in      cname   www

2-2、配置反向解析

编辑文件/etc/named.rfc1912.zones,在末尾添加需要解析的域

vim /etc/named.rfc1912.zones
zone "219.168.192.in-addr.arpa" in {
          type master;
          file "data/219.168.192.zone"; 
};

创建219.168.192.zone解析域

vim /var/named/data/219.168.192.zone
$ttl 3600
$origin  219.168.192.in-addr.arpa.
@       in      soa  panyangduola.com. admin.panyangduola.com. (
        2018042101
        1d
        1h
        1w
        3h
)
@       in      ns      ns1.panyangduola.com.
@       in      ns      ns2.panyangduola.com.
146      in      ptr     ns1.panyangduola.com.
147      in      ptr     ns2.panyangduola.com.
146      in      ptr     www.panyangduola.com.

2-3、对dns配置文件进行一下语法检查:

cd /etc
named-checkconf named.conf
named-checkconf named.rfc1912.zones
cd /var/named/data
named-checkzone panyangduola.com panyangduola.com.zone
named-checkzone 219.168.192.in-addr.arpa 219.168.192.zone

2-4、编辑/etc/resolv.conf,添加

vim /etc/resolv.conf
search localdomain
nameserver 192.168.219.146

2-5、如果2-3步骤没有错误发生的话,启动named服务

重启named

systemctl restart named

查看状态

systemctl status named

2-6、检查主dns服务器解析是否成功

ping命令验证

ping -c 4 www.panyangduola.com

nslookup命令验证

nslookup
>www.panyangduola.com
nslookup
>192.168.219.146

3、从dns服务器(192.168.219.147)配置

编辑named.conf文件

vim /etc/named.conf

找到其中两行  

  1. listen-on port 53 { 127.0.0.1; };   
  2. allow-query { localhost; };

修改为

  1. listen-on port 53 { any; };
  2. allow-query { any; };

3-1、修改主dns服务器(192.168.219.146)的配置/etc/named.rfc1912.zones

vim /etc/named.rfc1912.zones
zone "panyangduola.com" in {
      type master;
      file "data/panyangduola.com.zone";
      allow-transfer {192.168.219.147;};
      notify yes;
      also-notify {192.168.219.147;};
};
zone "219.168.192.in-addr.arpa" in {
      type master;
      file "data/219.168.192.zone";
      allow-transfer {192.168.219.147;}; 
      notify yes;   
      also-notify {192.168.219.147;};  
};

3-2、配置从dns服务器(192.168.219.147)正向解析

编辑文件/etc/named.rfc1912.zones,在末尾添加需要解析的域

vim /etc/named.rfc1912.zones
zone "panyangduola.com" in {
  type slave;
  file "data/panyangduola.com.zone";
  masters { 192.168.219.146; };
};

创建panyangduola.com.zone空文件

touch /var/named/data/panyangduola.com.zone 

设置所有者  

cd /var/named/data
chown named:named panyangduola.com.zone

3-3、配置从dns服务器(192.168.219.147)反向解析

在文件/etc/named.rfc1912.zones中添加

vim etc/named.rfc1912.zones
zone "219.168.192.in-addr.arpa" in {
    type slave;
    file "data/219.168.192.zone";
    masters { 192.168.219.146; };   
};

创建空文件219.168.192.zone

touch /var/named/data/219.168.192.zone

设置所有者

cd /var/named/data
chown named:named 219.168.192.zone

3-4、对dns配置文件进行一下语法检查:

cd /etc
named-checkconf named.conf
named-checkconf named.rfc1912.zones

3-5、编辑/etc/resolv.conf,添加

vim /etc/resolv.conf
search localdomain
nameserver 192.168.219.147

3-6、如果3-4步骤没有错误发生的话,启动named服务

重启named

systemctl restart named

查看状态

systemctl status named

3-7、查看文件/var/named/data/panyangduola.com.zone和/var/named/data/219.168.192.zone是否有二进制数据

cat /var/named/data/panyangduola.com.zone
cat /var/named/data/219.168.192.zone

3-8、检查从dns服务器解析是否成功

ping命令验证

ping -c 4 www.panyangduola.com

nslookup命令验证

nslookup
>192.168.219.147