Nhanho 1: Kuisirwa kwemapaketi anodiwa
Usati watanga kufunga nezvemirairo inotevera, tinoda kucherechedza kuti pane yedu saiti ikoko yatove neyakajaira gwara rekugadzira kune yakajairika DNS muLinux. Isu tinokurudzira kushandisa chaizvo zvinyorwa kana iwe uchifanira kuisa marongero ekushanyira nguva dzose kune internet nzvimbo. Tevere, isu tinoratidza kuti iyo huru yemunharaunda DNS server ine mutengi chikamu chakaiswa.Pakupera kwemaitiro aya, iwe uchaziviswa kuti mapakeji ese akabudirira kuwedzerwa kuhurongwa. Mushure meizvozvo, enda kunzvimbo inotevera.
Nhanho yechipiri: Global DNS Server Setup
Zvino isu tinoda kuratidza kuti iyo huru yekugadzirisa faira inogadziriswa, pamwe nemitsara inowedzerwa ikoko. Hatizogara pamutsetse wega wega, sezvo zvichatora nguva yakawanda, zvakare, ruzivo rwese rwunodiwa rwunowanikwa muzvinyorwa.
- Iwe unogona kushandisa chero mavara ezvinyorwa kugadzirisa zvinhu zvekugadzirisa. Isu tinopa kuisirwa nano nyore nano nekupinda sudo yum kuisa nano mune console.
- Zvese zvakaringana mapakeji zvichawanikwa, uye kana vatove varipo mukugoverwa, uchagamuchira chiziviso "chichaita chinhu."
- Isu tichaenderera kugadzirisa iyo faira pachayo. Vhura iyo kuburikidza sudo nano /etc/ned.conf. Kana zvichidikanwa, dzorera iyo yaunoda mavara ezvinyorwa, saka tambo ichave inotevera: Sudo vi /etc/nam.conf.
- Pazasi tinopa zvirimo izvo iwe zvaunoda kuisa mufaira yakavhurwa kana kuisarudzira iyo yatove iripo nekuwedzera mitsara yakarasika.
- Mushure meizvozvo, tinya Ctrl + o kunyora shanduko.
- Iwe haufanire kuchinja zita refaira, ingo tinya pane pinda.
- Siya mupepeti ezvinyorwa kuburikidza neCTRL + X.
Sezvazviri kare kutaurwa kare, iyo faira yekugadzirisa ichave inoda kuisa mamwe mitsara inotsanangudza iwo maumbirwo emagetsi eDNS server maitiro.
//
// inonzi.conf.
//
// yakapihwa nehwenzi tsvuku inosunga package kuti ugadzirise iyo isc bind inonzi (8) DNS
// server secaking caching inameserver (seyakagadziriswa madhiri esarudzo chete).
//
// Ona / USR / Share / Doc / Bind / / Sampuli / semuenzaniso inonzi mafaera ekugadzirisa.
//
Sarudzo {
Teerera-paPort 53 {127.0.0.1; 192.168.1.101;}; # # # Tenzi DNS IP # # 1
# Teerera-On-v6 Port 53 {:::; 1; };
Directory "/ var / anonzi";
Dhiza-faira "/var/named/data /cache /cusump.db";
Statistics-Faira "/Var/named/data/named_stats.txt";
Memsstatistics-faira "/var/named/data/named_mem_Sats.txt";
Bvumira-query {Munharaunda; 192.168.1.0/24;}; # # # # IP Range # #
Bvumira-kuendesa {Akaisa pasi; 192.168.1.102; }; # # # Muranda DNS IP # #
/*
- Kana iwe urikuvaka ane masertitative dns server, usaite kuti udzorere.
- Kana iwe uri kuvaka kudzokorora (caching) DNS server, iwe unofanirwa kugonesa
Kudzokorora.
- Kana yako kudzokorora DNS server ine yeruzhinji IP kero, iwe unofanirwa kugonesa kuwana
Kutonga kudzikisira mibvunzo kune vashandisi vako vechokwadi. Kukundikana kuita kudaro kuda
Kukonzera yako sevha kuti ive chikamu chehuremu hukuru DNS kuwedzera
Kurwiswa. Kushandisa BCP38 mukati mevaneti yako
Kuderedza zvakadaro kurwiswa
*/
Kudzokorora Ehe;
DNSSEC-Gonesa Hungu;
DNSSec-Validation Hongu;
DNSSEC-lookide auto;
/ * Nzira yeIsc DLV kiyi * /
Bindkeys-Faira "/etc/nam.iscdlv.key";
Yakachengetedzwa-kiyi-dhairekitori "/ var / anonzi / dynamic";
PID-faira "/ @named / Instagram Photo.Pid";
Session-kiyi "/ @named/sedy.key";
};
Logging {
Channel default_debug {
Faira "data / inonzi.run";
Kuomesa simba;
};
};
"Zone". " Mu {
Nyora zano;
Faira "anonzi.
};
Zone "Unixmen.nlical" mu {
Nyora Tenzi;
Faira "kumberi.unixmen";
Bvumira-gadzirisa {hapana; };
};
Zone "1.168.192.In-addr.arpa" mu {
Nyora Tenzi;
Faira "inodzokorora.unixmen";
Bvumira-gadzirisa {hapana; };
};
Sanganisira "/etc/namc1912.zonones";
Sanganisira "/etc/nedda.root.key";
Ita shuwa kuti zvese zvinoburitswa chaizvo sezvakaratidzwa pamusoro, uye woenda kune inotevera nhanho.
Nhanho 3: Kugadzira yakananga uye reverse nzvimbo
Kuti uwane ruzivo nezve sosi, iyo DNS server inoshandisa zvakananga uye zvakashata nzvimbo. Iyo yakananga inobvumidza iwe kuti ugamuchire kero ye IP nezita rekutambira, uye kudzoka kuburikidza neIP kunopa zita rezita. Iko kushanda kwayo kwenzvimbo imwe neimwe kunofanirwa kupihwa nemitemo yakakosha, kusikwa kwatinoita kuti tiite zvakare.
- Yenzvimbo yakatwasuka, isu tichagadzira iyo faira yakaparadzana kuburikidza neiyo yakafanana mavara ezvinyorwa. Ipapo tambo icharatidzika seiyi: Sudo nano /var/named/forwr.unixmen.
- Iwe uchaziviswa kuti chinhu chisina chinhu. Namatira zvinotevera zvirimo ipapo:
$ Ttl 86400.
@ In soa myddns.unixmen.LOLOLOL. nto.unikmen.LOLOLOL. (
2011071001; Serial
3600; zorodza.
1800; dzokorora.
604800; kupera
86400; shoma ttl
)
@ In ns masterdns.unixmen.LOLOLOL.
@ Mu ns yekondari.unixmen.LOLOLOL.
@ In a 192.168.1.101
@ In a 192.168.1.102
@ In a 192.168.1.103
Masterdns in a 192.168.1.101
Yechipiri muna 192.168.1.102
Mutengi mune 192.168.1.103
- Sevha shanduko uye kuvhara mupepeti ezvinyorwa.
- Isu tachinjisa kunzvimbo inodzosera nzvimbo. Zvinoda a /var/named/revereter.unixmen faira.
- Izvi zvichave zvakare faira idzva risina chinhu. Isa ipapo:
$ Ttl 86400.
@ In soa myddns.unixmen.LOLOLOL. nto.unikmen.LOLOLOL. (
2011071001; Serial
3600; zorodza.
1800; dzokorora.
604800; kupera
86400; shoma ttl
)
@ In ns masterdns.unixmen.LOLOLOL.
@ Mu ns yekondari.unixmen.LOLOLOL.
@ MuPTR UNIXmen.LOLOLOL.
Masterdns in a 192.168.1.101
Yechipiri muna 192.168.1.102
Mutengi mune 192.168.1.103
101 muPTR Masterns.unixmen.LOLOLOL.
102 muPTR yeChikamu cheMidanho.Uuniymn.local.
103 muPTR Mutengi.UNixmen.LOLOLOL.
- Kana uchengetedza, usachinja zita rechinhu, asi ingo dzvanya kiyi yekupinda.
Iye zvino mafaera akataurwa achashandiswa kune zvakananga uye reverse nzvimbo. Kana zvichidikanwa, iwe unofanirwa kuvapa kuitira kuti vachinje mamwe ma parameter. Iwe unogona zvakare kuverenga nezvazvo mugwaro repamutemo.
Nhanho 4: Kutanga DNS Server
Mushure mekupedza zvese zvakapfuura mirayiridzo, iwe unogona kutotanga iyo DNS server kuitira kuti mune ramangwana zviri nyore kutarisa mashandiro aro uye kuramba uchiisa zvikonzero zvakakosha. Basa racho rinoitwa seinotevera:
- Mune console, pinda Sudo Systemctl inoita kuti uwedzere server yeDNS kuti autoload ye otomatiki kutanga kana kutanga iyo inoshanda system.
- Simbisa chiitiko ichi nekupinda password superuser.
- Iwe unozoziviswa nezvechisikwa chehurukuro yekufananidzira, zvinoreva kuti kuita kwave kubudirira.
- Mhanya iyo yekushandisa kuburikidza nehurongwa takatanga zita. Iwe unogona kumisa nenzira imwechete, kungotsiva sarudzo yekutanga pane mira.
- Kana iyo yechokwadi pop-up hwindo inoratidzwa, isa password kubva kumidzi.
Sezvauri kuona, manejimendi ebasa rakatsanangurwa rinoitwa maererano nemhedzisiro yakafanana neyakaitwa mamwe mabasa ese, saka, hapazovi nematambudziko neiyi kunyangwe kune vashandisi vepamhepo.
Nhanho 5: Kuchinja paramita yeiyo firewall
Kune iyo chaiyo kushanda kweDNS server, iwe uchafanirwa kuvhura chiteshi 53, chinoitwa kuburikidza neiyo firewald standard firewall. Mune terminal, iwe uchazoda kuunza chete mirairo mitatu yakapusa:
- Iyo yekutanga inoratidzira maonero eFirewall-Cmd - Cmd - Portmanent - Port-Port = 53 / TCP uye ine mutoro wekuvhura tcp protocol chiteshi protocol. Isa iyo mune console uye tinya pane pinda.
- Iwe unofanirwa kugamuchira "kubudirira" ziviso, izvo zvinoratidza kushandiswa kwakabudirira kwemutemo. Mushure meizvozvo, isa iyo firewall-cmd - cmd - permanent --d-port = 53 / udp tambo kuvhura iyo UDP protocol port.
- Shanduko dzese dzichashandiswa chete mushure mekuremekedza iyo firewall, inoitwa kuburikidza neiyo firewall-cmd - cmd - command.
Hapasisina shanduko ne mfollwall kuti ubudise. Chengetedze nguva dzose muHurumende, kuti varege matambudziko ekuwana.
Nhanho 6: Gadzirisa kodzero dzekuwana
Izvozvi zvichave zvakakodzera kuisa iyo huru mvumo uye yekuwana kodzero dzekuchengetedza iyo DNS server basa uye chengetedza vashandisi vanowanzoita kubva mukukwanisa kuchinja ma parmeter. Tichazviita nenzira yakajairika kuburikidza selinux.
- Mirairo yese inotevera inofanira kuiswa panzvimbo yeiyo superuser. Kuti ugare uchiisa password, tinokurayira kuti ugone kugonesa midzi yechigomo yekuwana kwechirongwa chazvino. Kuti uite izvi, pinda svina mune console.
- Taura password yekuwana.
- Mushure meizvozvo, pamwe chete pinda iyo inotevera mirairo yekugadzira yakakwana yekukonzeresa kugadzirisa:
Chrn anonzi -r / var / anonzi
Chown -v midzi: anonzi /etc //ned.conf
Kudzvinyirira -RV / var / anonzi
Kudzoreredza /etc/named.conf.
Pane izvi, iyo gadziriro general yeiyo huru DNS server yapera. Iyo inoramba ichingorongedza mafaera anoverengeka ekugadzirisa uye ekuedza zvikanganiso. Isu tinopa zvese izvi kuti tifunge nezve chinhanho chinotevera.
Nhanho 7: Kuongororwa kwezvikanganiso uye kupedzisa kuiswa
Isu tinokurudzira kutanga nekukanganisa kwezvinhu zvekuti mune ramangwana hazvifanirwe kuchinja mafaira ekugadzirisa akasara. Ndokusaka tichizokurangarira zvese mukati meimwe nhanho, uye isu tinopa samples dzekubuda kwemirairo chaiyo yekuedza.
- Pinda iyo inonzi-Checkconf /etc/named.conf mune terminal. Izvi zvinokutendera kuti utarise ma parameter epasi rose. Kana, semhedzisiro, hapana chinobuda chakateverwa, zvinoreva kuti zvese zvakagadzirirwa nemazvo. Zvikasadaro, dzidza mharidzo uye, kusundira kubva mariri, gadzirisa dambudziko.
- Tevere iwe unofanirwa kutarisa nzvimbo yakatwasuka nekuisa zita rekuti-Checkzone unixmen.narl /var/named/untiward.UNIXT tambo.
- Output sampuli iri seyinotevera: Zone UNIXmen.LOLOLPAL
- Zvinenge zvakafanana uye nenzvimbo dzakatenderwa kuburikidza neiyo inonzi-Checkzone unixmen.LOLOLEN /Var/namned/reating.Uunikamini.
- Iyo chaiyo yekubuda inofanirwa kunge iri: Zone UNIXmen.LOLOLICAL / IN: Yakatakura Serial 2011071 OK.
- Isu zvino tava kuenderera mberi kune iyo marongero eiyo main network interface. Izvo zvinoda kuwedzera data yeiyo yazvino DNS server. Kuti uite izvi, vhura iyo / etc / sssconfig / network-script / ifcf-enpg-enp0s3 faira.
- Tarisa uone kuti zvirimo zviri sezvaratidzwa pazasi. Kana zvichidikanwa, isa iyo dns parameter.
Type = "Ethernet"
BootProTo = "Hapana"
Defroute = "Ehe"
IPv4_Failure_Fatal = "Kwete"
IPv6init = "Ehe"
IPv6_Aautoconf = "Hongu"
IPv6_Defroute = "Ehe"
IPv6_Failure_Fatal = "Kwete"
Zita = "enp0s3"
Uuid = 50D0428b3-6af2-4f6b-9fe3f3-4250cd839efa "
Onboot = "Ehe"
HWaddr = 08: 00: 27: 19: 68: 73 "
IPaddr0 = "192.168.1.101"
Prefix0 = "24"
Gedharo0 = "192.168.1.1"
DNS = 192.168.1.101 "
IPv6_peerdns = "Ehe"
IPv6_Peerrutes = "Ehe"
- Mushure mekuchinja shanduko, enda ku /etc/resolv.conf faira.
- Pano iwe unofanirwa kuwedzera imwe chete mutsara: nameserver 192.168.1.101.
- Kana wapedza, zvinongogara kungodzosera network kana komputa kuti ugadzirise iyo gadziriro. Iyo network inotangwazve kuburikidza nehurongwa hwekutangisa netiweki yekuraira.
Nhanho 8: Kuongorora iyo yakaiswa DNS server
Pakupera kwekugadziriswa, iyo inosara chete kuti iongorore mashandiro eiyo iripo DNS server mushure mekuwedzera kune iyo Global Network Service. Uku kuvhiyiwa kunoitwawo uchishandisa mirairo yakakosha. Yekutanga yavo ine fomu yekuchera masterdds.unixmen.LOLOLOL.
Nekuda kweizvozvo, kubudiswa kunofanirwa kuoneka pachiratidziro, icho chine chiratidzo chakafanana nezviri zvakataurwa pazasi.
; Chera 9.9.4-Redhat-9.9.4-14.EL7 Masterd.Nuntional
;; ZVESE ZVESE ZVOKUSVIKI: + CMD
;; Ndapera Mhinduro:
;; - >> Musoro.
;; Mireza: QR AA Rd Ra; Query: 1, Mhinduro: 1, Chiremera: 2, Kuwedzera: 2
;; Opt pseudosection:
; EDN: Shanduro: 0, Mireza:; UDP: 4096.
;; Chikamu Mubvunzo:
; agords.unixmen.LOLOLOL. Muna A.
;; Pindura Chikamu:
Manyodd.unixmen.LOLOLOLOL. 86400 MUNA 192.168.1.101
;; Chiremera Chikamu:
unixmen.LOLOLOL. 86400 muNS yechipiri.Uunikamini.ROLCAL.
unixmen.LOLOLOL. 86400 muNS STADYDDDS.UNIXProm.LOLOLOL.
;; Chimwe chikamu:
YechipiriDdns.unixmen.LOLOLOL. 86400 MUNA 192.168.1.102
;; Query Nguva: 0 Msec
;; Server: 192.168.1.101 # 53 (192.168.1.101)
;; Wakati: Wed Aug 20 16: 20:46 IST 2014
;; Msg size RVC: 125
Murairo wekuwedzera uchakubvumidza iwe kuti udzidze nezve chimiro cheiyo yemunharaunda DNS server. Kuti uite izvi, isa nslookup uxixmen.LOLOLEN kune console uye tinya paPinda.
Nekuda kweizvozvo, zvikamu zvitatu zvakasiyana zveIP kero uye mazita mazita anofanira kuratidzwa.
Server: 192.168.1.101
Kero: 192.168.1.101 # 53
Zita: Unixmen.LOLOLOL
Kero: 192.168.1.103
Zita: Unixmen.LOLOLOL
Kero: 192.168.1.101
Zita: Unixmen.LOLOLOL
Kero: 192.168.1.102
Kana iyo yakabuda ichienderana neye yatiratidza, zvinoreva kuti iyo yekugadzirisa inopedzwa zvinobudirira uye iwe unogona kuenda kubasa neiyo mutengi chikamu cheDNS server.
Kumisikidza chikamu chemutengi cheDNS server
Hatizopatsanure maitiro aya pane imwe nhanho, sezvo inoitwa nekugadzirisa chete faira rimwe chete rekugadzirisa. Izvo zvinodikanwa kuti uwedzere ruzivo nezvevatengi vese izvo zvichabatana kune server, uye muenzaniso weseti yakadaro inotaridzika seiyi:
- Vhura iyo /etc/resolv.conf faira kuburikidza neipi yakanakira mavara ezvinyorwa.
- Wedzera tambo kuti utsvaki unixmen.LOLOLACAL nameserver 192.168.1.101 uye namesterver 192.168.1012, kutsiva kero dzevatengi vanodiwa.
- Kana uchichengetedza, usachinja zita refaira, asi ingo dzvanya kiyi yekupinda.
- Mushure mekusiya mupepeti ezvinyorwa, restart iyo Global network kuburikidza nehurongwa hweSystem restart network command.
Idzi ndidzo pfungwa huru dzechikamu chemutengi cheDNS server, izvo zvataida kuudza. ZVESE ZVESE ZVESE ZVESE ZVINOGONESWA KUDZIDZA Nekuverenga Zvinyorwa Zvepamutemo Kana zvichidikanwa.
DNS Server Kuedza
Chikamu chekupedzisira chezvinhu zvedu zvemazuva ano ndiko kwekupedzisira kuongororwa kweDNS server. Pazasi iwe unoona akati wandei mirairo, uchikubvumira kuti utsungirire nebasa racho. Shandisa imwe yacho nekuvandudza kuburikidza ne "terminal". Kana pasina zvikanganiso zvichonekwa mune kubuda, saka, maitiro ese anoitwa nenzira kwayo.
Cheraydns.unixmen.LOLOLOL
Chera chechipiriDdn.unixmen.LOLOLOCAL
Dig Cliant.unixmen.LOLOLOL
Nslookup udiximen.local
Nhasi wakadzidza zvese nezvekumisikidza iyo huru DNS server mune iyo centos kugoverwa. Sezvauri kuona, iko kushanda kwose kwakatarisana nekupinda mumirairo yeTerminal uye kugadzirisa mafaira ekugadzirisa, ayo anogona kukonzera mamwe matambudziko kubva kune vashandisi vepacheki. Nekudaro, iwe unongoda kutevera chaizvo iyi mirayiridzo uye uverenge mhinduro dzechechi kuitira kuti zvese zvive zvisina kana zvikanganiso.