Tallaabada 1: Rakibaadda xirmooyinka lagama maarmaanka ah
Kahor intaadan bilaabin tixgelinta tilmaamaha soo socda, waxaan rabnaa inaan ogaano in bartayada ay durba tahay hage guud ahaan qaabeynta guud ee loo yaqaan 'DNUX' ee Linux. Waxaan kugula talineynaa inaad si sax ah u isticmaasho maaddada haddii ay tahay inaad dejiso dejimaha booqashada caadiga ah ee bogagga internetka. Marka xigta, waxaan ku tusi doonaa sida ugu weyn ee serverka ugu weyn ee loo yaqaan 'DNS-ka ugu weyn ee loo yaqaan' Macaamiisha 'la rakibay.Dhamaadka hanaankan, waa lagu soo ogeysiin doonaa in dhammaan baakadaha si guul leh loogu daray nidaamka. Taas ka dib, tag tallaabada xigta.
Tilaabada 2: Dejinta Global DNS Server
Hadda waxaan rabnaa inaan muujino sida faylka loo habeeyo ugu weyn ee loo tafatiray, iyo sidoo kale sacabbada halkaas lagu daray. Si gooni ah uma wada joogi doonno qadxan kasta, maadaama ay qaadanayso waqti badan, oo intaa ka badan dhammaan macluumaadka loo baahan yahay waxaa laga heli karaa dukumiinti rasmi ah.
- Waad u adeegsan kartaa wixii tafatiraha qoraalka ah si aad u tafatirto waxyaabaha qaabeynta ah. Waxaan u bandhignaa inaan ku rakibno Nano ku habboon ee Nano oo aan galeyno sudo yum ku rakib nano ee Nano.
- Dhammaan xirmooyinka lagama maarmaanka ah waa la soo dejisan doonaa, oo haddii ay hadda joogaan qaybinta, waxaad heli doontaa ogeysiis "wax aan waxba qaban."
- Waxaan u sii wadaynaa inaan tafatirno faylka laftiisa. Fur fur sudo Nano'/etc/ned.conf. Haddii loo baahdo, beddel tifaftiraha qoraalka ee la doonayo, ka dib xarig ayaa noqon doona sidan soo socota: sudo vi oetc/ned.conf.
- Hoos waxaan soo bandhigaynaa waxa ku jira ee aad u baahan tahay inaad geliso faylka la furay ama aad ku xaqiijiso inay hore u jirtay adigoo ku daraya xariiqyo ka maqan.
- Intaa ka dib, riix Ctrl + o si aad u duubto isbeddelada.
- Uma baahnid inaad beddesho magaca faylka, kaliya dhagsii Gali.
- Uga tag tafatiraha qoraalka ee Ctrl + X.
Maaddaama mar hore la sheegay, faylka qaabeynta ayaa loo baahan doonaa gelin doonaa khadadka qaarkood ee qeexaya xeerarka guud ee dabeecadda server-ka DNS.
//
// la magacaabay.conf.
//
// oo ay bixiso koofiyadaha casaanka ee xirmada si loo habeeyo xirashada ISC ee la magacaabay (8) DNS
// server ahaan sida loo yaqaan 'Xere' oo keliya magac-bixiye (sida gorgor-ka-dns xalka maxalliga ah oo keliya).
//
// arag / USR / Waleon / Doc / Dind * / Muunad / tusaale ahaan faylasha qaabeynta.
//
Xulasho {
Dhagayso dekeda 53 {127.0.0.1; 192.16.1.1.101;}; ### Master Dns IP ###
# Dhagayso dekeda-v6 dekeda 53 {:: 1; ;;;
Tilmaanta "/ var / loo magacaabay";
Disp-faylka "/Var/nad/nata/data/kata/cache_dump.db";
tirakoobka-faylka "/Var/nad/nata/data/dat_stats.txt";
Memstatistics-faylka "/Var/nad/nata/data/dat_mem_stats.txt";
U oggolow-weydiinta {maxalliga; 192.168.16.1.0/24;}; ### IP FAT ###
Ogolaanshaha-wareejinta {maxalliga; 192.16.1.1.102; ;;; ### addoonsiga DNS IP ###
/*
- Haddii aad dhisaneyso server-ka DNS ee sharci darada ah, ha suuragal ahayn soo jeedinta.
- Haddii aad dhisaneyso server-ka dib-u-soo-nooleynta (kaydinta) server-ka DNS, waxaad u baahan tahay inaad karti u yeelatid
Dib-u-celin.
- Haddii server-ka 'DNS server-ka' DNS server-ka 'Cinwaanka IP-ga dadweynaha leeyahay, waa inaad u oggolaataa gelitaanka
Xakamee si loo xaddido weydiimaha isticmaaleyaashaada sharciga ah. Ku guuldareysiga in sidaas la sameeyo
Sababi in server-kaaga inuu noqdo qayb ka mid ah cod-weyneynta ballaaran ee DNS
Weerarada. Hirgalinta BCP38 ee shabakadaada si weyn ayey u tahay
Yaree dusha weerarka noocaas ah
*/
Dib u soo noqoshada Haa;
DNSSECE-Key karti Haa;
Ansixinta DNSSECE-;
Dnsssec-soosaside auto;
/ * Wadada loo maro ISC DLV furaha * /
Xaraashka '' faylka 'redketc/neddlv.key ";
Maareynta-furayaasha-buugga "/ var / la magacaabay / firfircoon";
Pid-faylka "/qunta/ned/ned/ned.pid";
kal-fadhiga-Keyfile "/qunta/ned/sission.key";
};
Galitaanka {
Kanaalka deface_debug {
Faylka "Xogta / La Magacaabay.Run";
Darnaanta dhaqdhaqaaqa;
};
};
aagga "." In {
Nooca tilmaanta;
Faylka "la magacaabay.ca";
};
Aagga "Unixmen.local" ee {
Nooca Masterka;
Fayl "hore.unixmen";
U oggolow-cusboonaysiinta {ma jiro; ;;;
};
Aagga "1.168.192.in-1rpa" ee {
Nooca Masterka;
Faylka "Reparch.Unixmenmen";
U oggolow-cusboonaysiinta {ma jiro; ;;;
};
Ku dar "ottc/ned.rfc1912.Zones";
Ku dar "oetc/ned.root.key";
Hubso in wax walba ay qaataan si sax ah sida kor lagu soo sheegay, ka dibna u tag tallaabada xigta.
Tallaabada 3: Abuuritaanka aag toos ah oo gadaal u rogaya
Wixii macluumaad ah ee ku saabsan isha, server-ka DNS waxay isticmaashaa aagado toos ah oo aan kala go 'lahayn. Tooska ayaa kuu oggolaanaya inaad ka hesho Cinwaanka IP-ga magaca martida loo yahay, iyo soo laabashada IP-ga waxay siisaa magac domain. Qalliinka saxda ah ee aag kasta waa in la siiyaa qawaaniin gaar ah, abuurista aan bixinno si aan wax uga sii wadno.
- Aag toos ah, waxaan u abuuri doonnaa fayl gaar ah isla isla qoraalkaas. Markaas xariggu wuxuu u ekaan doonaa tan: sudo Nano /var/Named/Forward.unixmen.
- Waxaa lagu soo ogeysiin doonaa inay tahay shay madhan. Ku dhaji waxa ku jira soo socda halkaas:
$ TTL 86400.
@ In Soa Masterdns.unixmen.local. xididka.unixmen.local. (
2011071001; serial
3600; dib u cusbooneysii.
1800; isku day.
604800;
86400; ugu yaraan ttl
)
@ Ns Masterdns.unixmen.local.
@ NS SIT SISTDNS.UNXMEN.LOCAL.
@ A 1922.168.1.101
@ A 1922.168.1.102
@ A 1922.168.1.103
Masterdns sanadkii 192.168.1.101
SITETDNS EE 192.168.102
Macmiil ahaan 192.168.1.103
- Badbaadi isbeddelada oo xir qoraalka tifatiraha qoraalka.
- Waxaan hadda u leexaneynaa aag soonaha. Waxay u baahan tahay a /var/Named/Refisemes.unixment faylka.
- Tani waxay sidoo kale noqon doontaa fayl cusub oo madhan. Gali halkaas:
$ TTL 86400.
@ In Soa Masterdns.unixmen.local. xididka.unixmen.local. (
2011071001; serial
3600; dib u cusbooneysii.
1800; isku day.
604800;
86400; ugu yaraan ttl
)
@ Ns Masterdns.unixmen.local.
@ NS SIT SISTDNS.UNXMEN.LOCAL.
@ PTR Unixmen.local.
Masterdns sanadkii 192.168.1.101
SITETDNS EE 192.168.102
Macmiil ahaan 192.168.1.103
101 PTR Masterdns.unixmen.local.
102 PTR SIT SIT SISTDNS.UNXMEN.LOCAL.
103 Ptt macmiilka.unixmen.local.
- Markaad badbaadineyso, ha beddelin magaca sheyga, laakiin si fudud u riix furaha ENTER.
Hadda feylasha la cayimay waxaa loo isticmaali doonaa aag toos ah oo soo noqda. Haddii loo baahdo, waa inaad tafatirtaa si aad u beddesho halbeegyada qaarkood. Waxa kale oo aad ka akhriyi kartaa wax ku saabsan dukumiintiyada rasmiga ah.
Tallaabo 4: Bilow server DNS
Kadib markay dhammeeyaan dhammaan tilmaamaha hore, waxaad durba bilaabi kartaa server-ka DNS si mustaqbalka ay u fududahay in la hubiyo wax qabadkiisa oo sii wadida dejinta cabbirrada muhiimka ah. Hawsha waxaa loo fuliyaa sida soo socota:
- Qalabka Console, Gali Nidaamka Sudo ee Sudotctl wuxuu awood u siinayaa in lagu magacaabay in lagu daro server DNS ah oo ku saabsan autoload loogu talagalay bilowga otomaatiga marka la bilaabayo nidaamka hawlgalka.
- Xaqiiji ficilkan adoo soo galay furaha sirta ah.
- Waxaa lagu ogeysiin doonaa abuurista tixraac astaan, taas oo macnaheedu yahay in ficilku guuleystay.
- U adeegso utility iyada oo loo marayo nidaamka la yiraahdo. Waad u joojin kartaa si la mid ah, kaliya bedelida ikhtiyaarka bilowga ee joogsiga.
- Marka xaqiijinta daaqadda xaqiijinta la soo bandhigo, geli lambarka sirta ah xididka.
Sidaad arki karto, maaraynta adeegga la cayimay waxaa loo fuliyaa iyada oo loo eegayo isla mabda'a qiyaasta kale ee caadiga ah, sidaa darteed, ma jiraan wax dhibaatooyin ah oo tan ka jira xitaa isticmaaleyaasha Lavice.
Tallaabo 5: Bedelka xuduudaha dabada galka
Howlgalka saxda ah ee server-ka DNS, waxaad u baahan doontaa inaad furato dekeda 53, kaas oo lagu fulinayo dabka dabka ee dab-damiska. Terminalka, waxaad u baahan doontaa inaad soo bandhigto kaliya seddex amarro fudud:
- Astaamaha ugu horreeya ee aragtida galka-cmd - cmd --permanent --dd-deked = 53 / TCP oo mas'uul ka ah furitaanka dekedaha 'TCP'. Gali qalabka ku dheji oo guji Gal.
- Waa inaad heshaa ogeysiiska "guusha", taasoo muujineysa adeegsiga guuleysta ee qaanuunka. Intaa ka dib, geliso galka-cmd - cmd --permant --dd-deked = 53 / UDP xarig si loo furo dekeda borotokoolka UDP.
- Dhammaan isbeddelada ayaa la dabaqi doonaa oo keliya ka dib markii dib loo soo celiyo galka, kaas oo lagu sameeyo amarka dabka-cmd --reload.
Ma jiraan wax isbadal ah oo ku saabsan galka galka si loo soo saaro. Si joogto ah uga dhig gobolka, si aysan jirin dhibaatooyin marin u helitaan.
Tallaabo 6: Hagaaji xuquuqda marinka
Hadda waxaa lagama maarmaan ah in la dejiyo rukhsadaha ugu waaweyn iyo helitaanka xuquuqaha lagu ilaalinayo server-ka DNS-ka oo ay ka ilaaliso isticmaaleyaasha caadiga ah awooda ay ku beddelaan xuduudaha. Waxaan ku sameyn doonnaa hab caadi ah oo loo maro Sellinux.
- Dhammaan amarrada xigta waa in lagu hawlgeliyaa iyagoo ku hadlaya magaca super-ka. Si aan had iyo jeer u soo galin erayga sirta ah, waxaan kugula talineynaa inaad awood u yeelato helitaanka xididdada asalka u ah kal-fadhiga Terminalka. Si tan loo sameeyo, ku qor Su scle.
- Sheeg furaha sirta ah.
- Intaa ka dib, si kale u gal amarrada soo socda si loo abuuro qaabeynta marin u helka ugu habboon:
Chgrp waxaa loo magacaabay -r / var / la magacaabay
Xididdada Chan -v -V: loo magacaabay othetc/ned.conf
Resoorcon -RV / var / la magacaabay
ResoorEcon otcc/ned.conf.
Tan, qaabeynta guud ee ku saabsan server-ka DNS ee ugu weyn ayaa la dhammaystiray. Kaliya waxay tafatiri kartaa dhowr faylal qaabeyn ah iyo khaladaad tijaabo ah. Waxaan ku siineynaa waxaas oo dhan si loo ogaado tallaabada xigta.
Tallaabo 7: Imtixaanka Khaladaadka iyo Dhameystirka Goobta
Waxaan kugula talineynaa bilaabida hubinta qaladka si mustaqbalka ay tahay in aysan u baahnayn in la beddelo faylalka haray ee harsan. Taasi waa sababta aan u tixgelinno dhammaantood hal talaabo gudahood, iyo sidoo kale waxaan ku siinaynaa tusaalooyin wax soo saar sax ah oo amarro ah oo lagu baaro.
- Gali magaca-soo-jeedinta-ka-eegska /ETC/ETC.CONF ee Terminalka. Tani waxay kuu oggolaaneysaa inaad hubiso cabirrada adduunka. Haddii, natiijo ahaan, wax soo saar ah lama raaco, waxay la micno tahay in wax walba si sax ah loo habeeyo. Haddii kale, baro fariinta iyo, ka soo riixeysa, xallinta dhibaatada.
- Marka xigta waxaad u baahan tahay inaad fiiriso aagga tooska ah adigoo galaya-checkzone UnixMen.Local /Var/Named/Fork/form.Uxmen String.
- Muunad wax soo saarka ah waa sida soo socota: aag Unixmen.local / Gudaha: Serial-ka: Serial-ka ee 2011071001 ok.
- Qiyaastii isku mid ah iyo goorta la soo rogay oo loo maro 'Checkzone UnixMen.local /Var/Named/Refisen.unix.
- Wax soo saarka saxda ah waa inuu ahaadaa: aag Unixmen.local / Gudaha: Sarisa 2011071001 ok.
- Waxaan hadda u gudubnaa dejimaha is-dhexgalka shabakadda weyn. Waxay u baahan doontaa ku darista xogta server-ka DNS ee hadda jira. Si tan loo sameeyo, fur fur / etm / sysconfig / shabakadda-qoraal-sheekooyinka / IFCFG-ENP0S3.
- Hubi in waxyaabaha ku jira ay yihiin sida hoose. Haddii loo baahdo, geli digsiyada DNS.
Nooca = "Ethernet"
Bootproto = "midna"
Defroute = "haa"
IPV4_Failulure_fatal = "Maya"
Ipv6init = "haa"
Ipv6_autoconf = "haa"
Ipv6_defroute = "haa"
IPV6_Failulure_fatal = "Maya"
Magaca = "Enp0s3"
Uuid = "5D0428B3-6AF2-4B6B-9FE3-4250CD839EFA"
Onboot = "haa"
Hiwalddr = "08: 00: 27: 19: 68: 73"
Ipaddr0 = "192.168.101"
Horgaalada0 = "24"
Gateway0 = "192.168.1.1"
DNS = "192.168.1.101"
IPV6_PERDNS = "HAA"
IPV6_PEERROUTES = "HAA"
- Kadib badbaadinta isbeddelka, u tag faylka 'otresolv.conf'.
- Halkan waxaad u baahan tahay inaad kudarto hal sadar oo keliya: Feejignaan 192.168.101.101.
- Marka la dhameeyo, waxa wali aan kaliya ku guuleysatey in network ama computer si loo casriyeeyo habka qaabeynta. network waxaa bilaabmay iyada oo amarka SystemCTL Guuleysatey NETWORK.
Tallaabo 8: Hubinta server DNS rakibay
Dhamaadka qaabeynta, waxaa hadhay oo keliya si loo xaqiijiyo howlaha server DNS diyaar ah ka dib waxaa lagu daray in adeega caalamiga ah ee network. hawlgalka waxaa sidoo kale lagu sameeyaa iyadoo la isticmaalayo amarrada gaarka ah. The ugu horeysay oo ka mid ah waxay leedahay qaab dalooli Masterdns.Unixmen.local.
Sidaas darteed, wax soo saarka ah waa in u muuqan shaashadda, taas oo uu leeyahay wakiil la mid ah la content hoos ku qeexan.
; Dalooli 9.9.4-Redhat-9.9.4-14.EL7 MasterDns.Unixmen.local
;; Global Options: + Lauch
;; Jawaab helay:
;; - >> Header.
;; Calanka: QR AA RD RA, Su'aal: 1, Jawaab: 1, AWOODDA: 2, DHEERAAD AH: 2
;; Gaabsadeen Pseudosection:
; EDNS: Version: 0, Calanka :; UDP: 4096.
;; Su'aasha Section:
, Masterdns.unixmen.local. In A.
;; JAWAAB QAYBTA:
Masterdns.Unixmen.local. 86400 IN A 192.168.1.101
;; Maamulka Section:
unixmen.local. 86400 ee NS secondarydns.unixmen.local.
unixmen.local. 86400 ee NS masterdns.unixmen.local.
;; QAYBTA DHEERAAD AH:
Secondarydns.unixmen.local. 86400 IN A 192.168.1.102
;; Su'aal Time: 0 msec
;; Server: 192.168.1.101 # 53 (192.168.1.101)
;; GOORMA: ONS Aug 20 16:20:46 2014 IST
;; MSG Size RCVD: 125
Amarka dheeraad ah u ogolaan doonaa inaad barato oo ku saabsan xaaladda server DNS maxaliga ah. Si arrintan loo sameeyo, insert nslookup unixmen.local in ay Console iyo riix ENTER.
Sidaas darteed, saddex Wakiilada kala duwan ee cinwaanada IP iyo magacyada domain waa in la soo bandhigay.
Server: 192.168.1.101
Cinwaanka: 192.168.1.101 # 53
Name: unixmen.local
ADDRESS: 192.168.1.103
Name: unixmen.local
Cinwaanka: 192.168.1.101
Name: unixmen.local
ADDRESS: 192.168.1.102
Haddii wax soo saarka kulan ka mid ah in aan ku tilmaamay, waxa ay ka dhigan tahay in qaabeynta waa guul u soo dhammaystay iyo waxaad tagi kartaa shaqo la qayb macmiilka ah server DNS ah.
Aasaasidda qayb macmiilka ah server DNS ah
Waxaan ma kala sooci doonaa nidaamka this on tallaabo shakhsi, tan iyo markii ay la sameeyaa by sixiddiisa kaliya hal file qaabeynta. Waxaa lagama maarmaan ah in aad ku darto macluumaad ku saabsan dhammaan macaamiisha in la xiri doonaa server ka, iyo tusaale ah ee looks Mudanayaasha sida sidan oo kale:
- Fur file /etc/resolv.conf ku dhex editor kasta oo qoraalka ku haboon.
- Ku dar string ah si aad u raadiso nameserver unixmen.local 192.168.1.101 iyo NameServer 192.168.1012, bedelida cinwaanada macmiilka loo baahan yahay.
- Marka lagu badbaadinayo, ha la badalo magaca file ah, laakiin si fudud riix ATAR muhiimka ah.
- Markii uu ka tagay editor qoraalka, guuleysatey shabakadda caalamiga ah ee iyada oo amarka SystemCTL Guuleysatey NETWORK.
Kuwaani waxay ahaayeen qodobbada ugu muhiimsan ee macmiilka ka qeyb qaata adeegaha DNS, oo aan dooneynay inaan sheegno. Dhammaan nuxurka kale waxaa la siiyaa si wax lagu barto iyadoo la akhriyo dukumiintiyada rasmiga ah haddii loo baahdo.
Tijaabada Server ee DNS
Marxaladda ugu dambeysa ee sheydeena maanta waa tijaabada ugu dambeysa ee server-ka DNS. Hoos waxaad ku aragtaa dhowr amarro, oo kuu oggolaanaya inaad laqabsato hawsha. U adeegso mid ka mid ah adoo ku hawlan "Terminalka". Haddii aan khaladaad lahayn wax soo saarka, sidaa darteed, howsha oo dhan si sax ah ayaa loo sameeyaa.
Qodista MasterDns.unixmen.local
DIIWAANKA SISTDNS.UNXMEN.LOCAL
Gunt.unixmen.local
nskelfup Unixmen.local
Maanta waxaad ka baratay sidii loo diyaarin lahaa server-ka ugu weyn ee DNS ee qaybinta 'cneros'. Sidaad arki karto, qalliinka oo dhami wuxuu diiradda saarayaa galitaanka amarrada Terminalka iyo tafatirka feylasha qaabeynta, kaas oo sababi kara dhibaatooyin gaar ah oo ka soo baxa isticmaaleyaasha khatarta ah. Si kastaba ha noqotee, waxaad u baahan tahay oo keliya inaad si sax ah u raacdo tilmaamahan oo aad aqriso natiijooyinka jeegagga si wax walbana ay u socdaan wax qalad ah.