Kumisikidza DNS mumakore

Anonim

Kumisikidza DNS mumakore

Nhanho 1: Kuisirwa kwemapaketi anodiwa

Usati watanga kufunga nezvemirairo inotevera, tinoda kucherechedza kuti pane yedu saiti ikoko yatove neyakajaira gwara rekugadzira kune yakajairika DNS muLinux. Isu tinokurudzira kushandisa chaizvo zvinyorwa kana iwe uchifanira kuisa marongero ekushanyira nguva dzose kune internet nzvimbo. Tevere, isu tinoratidza kuti iyo huru yemunharaunda DNS server ine mutengi chikamu chakaiswa.

Pakupera kwemaitiro aya, iwe uchaziviswa kuti mapakeji ese akabudirira kuwedzerwa kuhurongwa. Mushure meizvozvo, enda kunzvimbo inotevera.

Nhanho yechipiri: Global DNS Server Setup

Zvino isu tinoda kuratidza kuti iyo huru yekugadzirisa faira inogadziriswa, pamwe nemitsara inowedzerwa ikoko. Hatizogara pamutsetse wega wega, sezvo zvichatora nguva yakawanda, zvakare, ruzivo rwese rwunodiwa rwunowanikwa muzvinyorwa.

  1. Iwe unogona kushandisa chero mavara ezvinyorwa kugadzirisa zvinhu zvekugadzirisa. Isu tinopa kuisirwa nano nyore nano nekupinda sudo yum kuisa nano mune console.
  2. Murairo wekuisa mupepeti ezvinyorwa usati wagadzirisa mafaira eDNS kune centos

  3. Zvese zvakaringana mapakeji zvichawanikwa, uye kana vatove varipo mukugoverwa, uchagamuchira chiziviso "chichaita chinhu."
  4. Yakabudirira kuisirwa yemutungamiriri ezvinyorwa usati wagadzirisa maDNS mafaera kune centos

  5. Isu tichaenderera kugadzirisa iyo faira pachayo. Vhura iyo kuburikidza sudo nano /etc/ned.conf. Kana zvichidikanwa, dzorera iyo yaunoda mavara ezvinyorwa, saka tambo ichave inotevera: Sudo vi /etc/nam.conf.
  6. Kutanga iyo huru DNS inogadziriswa faira mumasangano ekuwedzera kugadziriswa

  7. Pazasi tinopa zvirimo izvo iwe zvaunoda kuisa mufaira yakavhurwa kana kuisarudzira iyo yatove iripo nekuwedzera mitsara yakarasika.
  8. Kumisikidza iyo huru DNS yekugadziriswa faira muCentos

  9. Mushure meizvozvo, tinya Ctrl + o kunyora shanduko.
  10. Kuchengetedza shanduko mushure mekumisikidza iyo huru DNS yekugadziriswa faira muCentos

  11. Iwe haufanire kuchinja zita refaira, ingo tinya pane pinda.
  12. Kanzura Kudaidza zita reiyo DNS DEFITION faira mune centos

  13. Siya mupepeti ezvinyorwa kuburikidza neCTRL + X.
  14. Buda mupepeti ezvinyorwa mushure mekuchinja main dns ekugadziriswa faira muCentos

Sezvazviri kare kutaurwa kare, iyo faira yekugadzirisa ichave inoda kuisa mamwe mitsara inotsanangudza iwo maumbirwo emagetsi eDNS server maitiro.

//

// inonzi.conf.

//

// yakapihwa nehwenzi tsvuku inosunga package kuti ugadzirise iyo isc bind inonzi (8) DNS

// server secaking caching inameserver (seyakagadziriswa madhiri esarudzo chete).

//

// Ona / USR / Share / Doc / Bind / / Sampuli / semuenzaniso inonzi mafaera ekugadzirisa.

//

Sarudzo {

Teerera-paPort 53 {127.0.0.1; 192.168.1.101;}; # # # Tenzi DNS IP # # 1

# Teerera-On-v6 Port 53 {:::; 1; };

Directory "/ var / anonzi";

Dhiza-faira "/var/named/data /cache /cusump.db";

Statistics-Faira "/Var/named/data/named_stats.txt";

Memsstatistics-faira "/var/named/data/named_mem_Sats.txt";

Bvumira-query {Munharaunda; 192.168.1.0/24;}; # # # # IP Range # #

Bvumira-kuendesa {Akaisa pasi; 192.168.1.102; }; # # # Muranda DNS IP # #

/*

- Kana iwe urikuvaka ane masertitative dns server, usaite kuti udzorere.

- Kana iwe uri kuvaka kudzokorora (caching) DNS server, iwe unofanirwa kugonesa

Kudzokorora.

- Kana yako kudzokorora DNS server ine yeruzhinji IP kero, iwe unofanirwa kugonesa kuwana

Kutonga kudzikisira mibvunzo kune vashandisi vako vechokwadi. Kukundikana kuita kudaro kuda

Kukonzera yako sevha kuti ive chikamu chehuremu hukuru DNS kuwedzera

Kurwiswa. Kushandisa BCP38 mukati mevaneti yako

Kuderedza zvakadaro kurwiswa

*/

Kudzokorora Ehe;

DNSSEC-Gonesa Hungu;

DNSSec-Validation Hongu;

DNSSEC-lookide auto;

/ * Nzira yeIsc DLV kiyi * /

Bindkeys-Faira "/etc/nam.iscdlv.key";

Yakachengetedzwa-kiyi-dhairekitori "/ var / anonzi / dynamic";

PID-faira "/ @named / Instagram Photo.Pid";

Session-kiyi "/ @named/sedy.key";

};

Logging {

Channel default_debug {

Faira "data / inonzi.run";

Kuomesa simba;

};

};

"Zone". " Mu {

Nyora zano;

Faira "anonzi.

};

Zone "Unixmen.nlical" mu {

Nyora Tenzi;

Faira "kumberi.unixmen";

Bvumira-gadzirisa {hapana; };

};

Zone "1.168.192.In-addr.arpa" mu {

Nyora Tenzi;

Faira "inodzokorora.unixmen";

Bvumira-gadzirisa {hapana; };

};

Sanganisira "/etc/namc1912.zonones";

Sanganisira "/etc/nedda.root.key";

Ita shuwa kuti zvese zvinoburitswa chaizvo sezvakaratidzwa pamusoro, uye woenda kune inotevera nhanho.

Nhanho 3: Kugadzira yakananga uye reverse nzvimbo

Kuti uwane ruzivo nezve sosi, iyo DNS server inoshandisa zvakananga uye zvakashata nzvimbo. Iyo yakananga inobvumidza iwe kuti ugamuchire kero ye IP nezita rekutambira, uye kudzoka kuburikidza neIP kunopa zita rezita. Iko kushanda kwayo kwenzvimbo imwe neimwe kunofanirwa kupihwa nemitemo yakakosha, kusikwa kwatinoita kuti tiite zvakare.

  1. Yenzvimbo yakatwasuka, isu tichagadzira iyo faira yakaparadzana kuburikidza neiyo yakafanana mavara ezvinyorwa. Ipapo tambo icharatidzika seiyi: Sudo nano /var/named/forwr.unixmen.
  2. Enda kunogadzira iyo yakananga zone faira kana uchiisa dns mumakore

  3. Iwe uchaziviswa kuti chinhu chisina chinhu. Namatira zvinotevera zvirimo ipapo:

    $ Ttl 86400.

    @ In soa myddns.unixmen.LOLOLOL. nto.unikmen.LOLOLOL. (

    2011071001; Serial

    3600; zorodza.

    1800; dzokorora.

    604800; kupera

    86400; shoma ttl

    )

    @ In ns masterdns.unixmen.LOLOLOL.

    @ Mu ns yekondari.unixmen.LOLOLOL.

    @ In a 192.168.1.101

    @ In a 192.168.1.102

    @ In a 192.168.1.103

    Masterdns in a 192.168.1.101

    Yechipiri muna 192.168.1.102

    Mutengi mune 192.168.1.103

  4. Kuwedzera kurongeka kweDNS Direct Zone faira muCentos

  5. Sevha shanduko uye kuvhara mupepeti ezvinyorwa.
  6. Buda mupepeti ezvinyorwa mushure mekugadzira DNS Direct zone faira muCentos

  7. Isu tachinjisa kunzvimbo inodzosera nzvimbo. Zvinoda a /var/named/revereter.unixmen faira.
  8. Kugadzira iyo Reverse Zone faira kuti ugadzirise DNS muCentos

  9. Izvi zvichave zvakare faira idzva risina chinhu. Isa ipapo:

    $ Ttl 86400.

    @ In soa myddns.unixmen.LOLOLOL. nto.unikmen.LOLOLOL. (

    2011071001; Serial

    3600; zorodza.

    1800; dzokorora.

    604800; kupera

    86400; shoma ttl

    )

    @ In ns masterdns.unixmen.LOLOLOL.

    @ Mu ns yekondari.unixmen.LOLOLOL.

    @ MuPTR UNIXmen.LOLOLOL.

    Masterdns in a 192.168.1.101

    Yechipiri muna 192.168.1.102

    Mutengi mune 192.168.1.103

    101 muPTR Masterns.unixmen.LOLOLOL.

    102 muPTR yeChikamu cheMidanho.Uuniymn.local.

    103 muPTR Mutengi.UNixmen.LOLOLOL.

  10. Kuwedzera zvirimo kunzvimbo inodzosera kumashure kana ichimisa dns mumasangano

  11. Kana uchengetedza, usachinja zita rechinhu, asi ingo dzvanya kiyi yekupinda.
  12. Kanzura ichichinja zita refaira apo uchengetedza reverse dns zone mumasangano

Iye zvino mafaera akataurwa achashandiswa kune zvakananga uye reverse nzvimbo. Kana zvichidikanwa, iwe unofanirwa kuvapa kuitira kuti vachinje mamwe ma parameter. Iwe unogona zvakare kuverenga nezvazvo mugwaro repamutemo.

Nhanho 4: Kutanga DNS Server

Mushure mekupedza zvese zvakapfuura mirayiridzo, iwe unogona kutotanga iyo DNS server kuitira kuti mune ramangwana zviri nyore kutarisa mashandiro aro uye kuramba uchiisa zvikonzero zvakakosha. Basa racho rinoitwa seinotevera:

  1. Mune console, pinda Sudo Systemctl inoita kuti uwedzere server yeDNS kuti autoload ye otomatiki kutanga kana kutanga iyo inoshanda system.
  2. Kuwedzera iyo DNS service kune centos kune iyo yekushandisa system autoload

  3. Simbisa chiitiko ichi nekupinda password superuser.
  4. Kusimbiswa kwekuwedzera DNS service mumasangano kune autoload

  5. Iwe unozoziviswa nezvechisikwa chehurukuro yekufananidzira, zvinoreva kuti kuita kwave kubudirira.
  6. Kusikwa kwakabudirira kwekufananidzira zvinongedzo zvekutakura otomatiki ekuisa yeDNS service mumasangano

  7. Mhanya iyo yekushandisa kuburikidza nehurongwa takatanga zita. Iwe unogona kumisa nenzira imwechete, kungotsiva sarudzo yekutanga pane mira.
  8. Timu kuti iite DNS service mumasangano

  9. Kana iyo yechokwadi pop-up hwindo inoratidzwa, isa password kubva kumidzi.
  10. Kusimbiswa kweDNS DNS Service Command mumasangano nekupinda password

Sezvauri kuona, manejimendi ebasa rakatsanangurwa rinoitwa maererano nemhedzisiro yakafanana neyakaitwa mamwe mabasa ese, saka, hapazovi nematambudziko neiyi kunyangwe kune vashandisi vepamhepo.

Nhanho 5: Kuchinja paramita yeiyo firewall

Kune iyo chaiyo kushanda kweDNS server, iwe uchafanirwa kuvhura chiteshi 53, chinoitwa kuburikidza neiyo firewald standard firewall. Mune terminal, iwe uchazoda kuunza chete mirairo mitatu yakapusa:

  1. Iyo yekutanga inoratidzira maonero eFirewall-Cmd - Cmd - Portmanent - Port-Port = 53 / TCP uye ine mutoro wekuvhura tcp protocol chiteshi protocol. Isa iyo mune console uye tinya pane pinda.
  2. Kuvhura DNS PORT MU Centos kuburikidza standard firewall

  3. Iwe unofanirwa kugamuchira "kubudirira" ziviso, izvo zvinoratidza kushandiswa kwakabudirira kwemutemo. Mushure meizvozvo, isa iyo firewall-cmd - cmd - permanent --d-port = 53 / udp tambo kuvhura iyo UDP protocol port.
  4. Kuvhura yechipiri DNS mugari mune muzana kuburikidza neakajairwa firewall

  5. Shanduko dzese dzichashandiswa chete mushure mekuremekedza iyo firewall, inoitwa kuburikidza neiyo firewall-cmd - cmd - command.
  6. Kudzoreredza iyo firewall mushure mekuita shanduko kune iyo DNS kugadziriswa mumasangano

Hapasisina shanduko ne mfollwall kuti ubudise. Chengetedze nguva dzose muHurumende, kuti varege matambudziko ekuwana.

Nhanho 6: Gadzirisa kodzero dzekuwana

Izvozvi zvichave zvakakodzera kuisa iyo huru mvumo uye yekuwana kodzero dzekuchengetedza iyo DNS server basa uye chengetedza vashandisi vanowanzoita kubva mukukwanisa kuchinja ma parmeter. Tichazviita nenzira yakajairika kuburikidza selinux.

  1. Mirairo yese inotevera inofanira kuiswa panzvimbo yeiyo superuser. Kuti ugare uchiisa password, tinokurayira kuti ugone kugonesa midzi yechigomo yekuwana kwechirongwa chazvino. Kuti uite izvi, pinda svina mune console.
  2. Kugadziriswa kwekodzero dzepamusoro kuti uwedzere kugadzirisa DNS kuwana kune centos

  3. Taura password yekuwana.
  4. Pinda password kuti udzore midzi yechigarire kana uchiisa dns mumakore

  5. Mushure meizvozvo, pamwe chete pinda iyo inotevera mirairo yekugadzira yakakwana yekukonzeresa kugadzirisa:

    Chrn anonzi -r / var / anonzi

    Chown -v midzi: anonzi /etc //ned.conf

    Kudzvinyirira -RV / var / anonzi

    Kudzoreredza /etc/named.conf.

  6. Isa mirairo yekuisa mukana wekuwana maDNS mune centos

Pane izvi, iyo gadziriro general yeiyo huru DNS server yapera. Iyo inoramba ichingorongedza mafaera anoverengeka ekugadzirisa uye ekuedza zvikanganiso. Isu tinopa zvese izvi kuti tifunge nezve chinhanho chinotevera.

Nhanho 7: Kuongororwa kwezvikanganiso uye kupedzisa kuiswa

Isu tinokurudzira kutanga nekukanganisa kwezvinhu zvekuti mune ramangwana hazvifanirwe kuchinja mafaira ekugadzirisa akasara. Ndokusaka tichizokurangarira zvese mukati meimwe nhanho, uye isu tinopa samples dzekubuda kwemirairo chaiyo yekuedza.

  1. Pinda iyo inonzi-Checkconf /etc/named.conf mune terminal. Izvi zvinokutendera kuti utarise ma parameter epasi rose. Kana, semhedzisiro, hapana chinobuda chakateverwa, zvinoreva kuti zvese zvakagadzirirwa nemazvo. Zvikasadaro, dzidza mharidzo uye, kusundira kubva mariri, gadzirisa dambudziko.
  2. Tevere iwe unofanirwa kutarisa nzvimbo yakatwasuka nekuisa zita rekuti-Checkzone unixmen.narl /var/named/untiward.UNIXT tambo.
  3. Output sampuli iri seyinotevera: Zone UNIXmen.LOLOLPAL
  4. Mhedziso yebvunzo bvunzo dzeTrayed Dns Dns zone mumakore

  5. Zvinenge zvakafanana uye nenzvimbo dzakatenderwa kuburikidza neiyo inonzi-Checkzone unixmen.LOLOLEN /Var/namned/reating.Uunikamini.
  6. Murayiro wekutarisa nzvimbo dzekudzosera kumashure apo kuongorora DNS muCentos

  7. Iyo chaiyo yekubuda inofanirwa kunge iri: Zone UNIXmen.LOLOLICAL / IN: Yakatakura Serial 2011071 OK.
  8. Kubuda kwemhedzisiro yekuyedza iyo reverse dns zone mumasangano

  9. Isu zvino tava kuenderera mberi kune iyo marongero eiyo main network interface. Izvo zvinoda kuwedzera data yeiyo yazvino DNS server. Kuti uite izvi, vhura iyo / etc / sssconfig / network-script / ifcf-enpg-enp0s3 faira.
  10. Enda kuOditing iyo Global Network faira kana uchiisa DNS mune Centos

  11. Tarisa uone kuti zvirimo zviri sezvaratidzwa pazasi. Kana zvichidikanwa, isa iyo dns parameter.

    Type = "Ethernet"

    BootProTo = "Hapana"

    Defroute = "Ehe"

    IPv4_Failure_Fatal = "Kwete"

    IPv6init = "Ehe"

    IPv6_Aautoconf = "Hongu"

    IPv6_Defroute = "Ehe"

    IPv6_Failure_Fatal = "Kwete"

    Zita = "enp0s3"

    Uuid = 50D0428b3-6af2-4f6b-9fe3f3-4250cd839efa "

    Onboot = "Ehe"

    HWaddr = 08: 00: 27: 19: 68: 73 "

    IPaddr0 = "192.168.1.101"

    Prefix0 = "24"

    Gedharo0 = "192.168.1.1"

    DNS = 192.168.1.101 "

    IPv6_peerdns = "Ehe"

    IPv6_Peerrutes = "Ehe"

  12. Kurongedza global network faira kana uchiisa dns mumakore

  13. Mushure mekuchinja shanduko, enda ku /etc/resolv.conf faira.
  14. Enda kune Editing Interfaces kana uchiisa DNS muCentos

  15. Pano iwe unofanirwa kuwedzera imwe chete mutsara: nameserver 192.168.1.101.
  16. Kurongedza iyo Global network internet kana kumisikidza DNS muCentos

  17. Kana wapedza, zvinongogara kungodzosera network kana komputa kuti ugadzirise iyo gadziriro. Iyo network inotangwazve kuburikidza nehurongwa hwekutangisa netiweki yekuraira.
  18. Kutangazve iyo Global Network mushure mekubudirira DNS kugadziriswa mumasangano

Nhanho 8: Kuongorora iyo yakaiswa DNS server

Pakupera kwekugadziriswa, iyo inosara chete kuti iongorore mashandiro eiyo iripo DNS server mushure mekuwedzera kune iyo Global Network Service. Uku kuvhiyiwa kunoitwawo uchishandisa mirairo yakakosha. Yekutanga yavo ine fomu yekuchera masterdds.unixmen.LOLOLOL.

Timu kuti muedze kuita kweDNS mune centos

Nekuda kweizvozvo, kubudiswa kunofanirwa kuoneka pachiratidziro, icho chine chiratidzo chakafanana nezviri zvakataurwa pazasi.

Mhedziso yeDNS DNS Performance test timu mune centos

; Chera 9.9.4-Redhat-9.9.4-14.EL7 Masterd.Nuntional

;; ZVESE ZVESE ZVOKUSVIKI: + CMD

;; Ndapera Mhinduro:

;; - >> Musoro.

;; Mireza: QR AA Rd Ra; Query: 1, Mhinduro: 1, Chiremera: 2, Kuwedzera: 2

;; Opt pseudosection:

; EDN: Shanduro: 0, Mireza:; UDP: 4096.

;; Chikamu Mubvunzo:

; agords.unixmen.LOLOLOL. Muna A.

;; Pindura Chikamu:

Manyodd.unixmen.LOLOLOLOL. 86400 MUNA 192.168.1.101

;; Chiremera Chikamu:

unixmen.LOLOLOL. 86400 muNS yechipiri.Uunikamini.ROLCAL.

unixmen.LOLOLOL. 86400 muNS STADYDDDS.UNIXProm.LOLOLOL.

;; Chimwe chikamu:

YechipiriDdns.unixmen.LOLOLOL. 86400 MUNA 192.168.1.102

;; Query Nguva: 0 Msec

;; Server: 192.168.1.101 # 53 (192.168.1.101)

;; Wakati: Wed Aug 20 16: 20:46 IST 2014

;; Msg size RVC: 125

Murairo wekuwedzera uchakubvumidza iwe kuti udzidze nezve chimiro cheiyo yemunharaunda DNS server. Kuti uite izvi, isa nslookup uxixmen.LOLOLEN kune console uye tinya paPinda.

Murairo wekutarisa kurongeka kweiyo DNS nzvimbo mumakore

Nekuda kweizvozvo, zvikamu zvitatu zvakasiyana zveIP kero uye mazita mazita anofanira kuratidzwa.

Server: 192.168.1.101

Kero: 192.168.1.101 # 53

Zita: Unixmen.LOLOLOL

Kero: 192.168.1.103

Zita: Unixmen.LOLOLOL

Kero: 192.168.1.101

Zita: Unixmen.LOLOLOL

Kero: 192.168.1.102

Mirayiridzo yekubuda yekutarisa kurongeka kweiyo DNS nzvimbo muCentos

Kana iyo yakabuda ichienderana neye yatiratidza, zvinoreva kuti iyo yekugadzirisa inopedzwa zvinobudirira uye iwe unogona kuenda kubasa neiyo mutengi chikamu cheDNS server.

Kumisikidza chikamu chemutengi cheDNS server

Hatizopatsanure maitiro aya pane imwe nhanho, sezvo inoitwa nekugadzirisa chete faira rimwe chete rekugadzirisa. Izvo zvinodikanwa kuti uwedzere ruzivo nezvevatengi vese izvo zvichabatana kune server, uye muenzaniso weseti yakadaro inotaridzika seiyi:

  1. Vhura iyo /etc/resolv.conf faira kuburikidza neipi yakanakira mavara ezvinyorwa.
  2. Shanduko yekugadziriswa kwemutengi chikamu DNS muCentos

  3. Wedzera tambo kuti utsvaki unixmen.LOLOLACAL nameserver 192.168.1.101 uye namesterver 192.168.1012, kutsiva kero dzevatengi vanodiwa.
  4. Kugadziriswa kweiyo mutengi chikamu cheDNS mumakore kana akagadziriswa

  5. Kana uchichengetedza, usachinja zita refaira, asi ingo dzvanya kiyi yekupinda.
  6. Kuchengetedza shanduko mushure mekumisikidza chikamu chemutengi DNS muCentos

  7. Mushure mekusiya mupepeti ezvinyorwa, restart iyo Global network kuburikidza nehurongwa hweSystem restart network command.
  8. Kutangazve network mushure mekumisikidza iyo mutengi chikamu dns muCentos

Idzi ndidzo pfungwa huru dzechikamu chemutengi cheDNS server, izvo zvataida kuudza. ZVESE ZVESE ZVESE ZVESE ZVINOGONESWA KUDZIDZA Nekuverenga Zvinyorwa Zvepamutemo Kana zvichidikanwa.

DNS Server Kuedza

Chikamu chekupedzisira chezvinhu zvedu zvemazuva ano ndiko kwekupedzisira kuongororwa kweDNS server. Pazasi iwe unoona akati wandei mirairo, uchikubvumira kuti utsungirire nebasa racho. Shandisa imwe yacho nekuvandudza kuburikidza ne "terminal". Kana pasina zvikanganiso zvichonekwa mune kubuda, saka, maitiro ese anoitwa nenzira kwayo.

Cheraydns.unixmen.LOLOLOL

Chera chechipiriDdn.unixmen.LOLOLOCAL

Dig Cliant.unixmen.LOLOLOL

Nslookup udiximen.local

Global DNS Performance Tarisa muCentos

Nhasi wakadzidza zvese nezvekumisikidza iyo huru DNS server mune iyo centos kugoverwa. Sezvauri kuona, iko kushanda kwose kwakatarisana nekupinda mumirairo yeTerminal uye kugadzirisa mafaira ekugadzirisa, ayo anogona kukonzera mamwe matambudziko kubva kune vashandisi vepacheki. Nekudaro, iwe unongoda kutevera chaizvo iyi mirayiridzo uye uverenge mhinduro dzechechi kuitira kuti zvese zvive zvisina kana zvikanganiso.

Verenga zvimwe