1. 程式人生 > 實用技巧 >centos7.x 部署主、從DNS伺服器問題

centos7.x 部署主、從DNS伺服器問題

1、準備

例:兩臺192.168.219.146(主), 192.168.219.147(從), 域名www.panyangduola.com

主、從DNS伺服器均需要安裝bind、bind-chroot、bind-utils

yum -y install bind bind-utils bind-chroot

如果防火牆開啟,配置防火牆,新增服務(防火牆已禁用則忽略)

firewall-cmd --permanent --add-service=dns
firewall-cmd --reload

2、主DNS伺服器(192.168.219.146)配置

編輯配置檔案

vim /etc/named.conf

找到其中兩行

listen-on port 53 { 127.0.0.1; };
allow-query { localhost; };

修改為

listen-on port 53 { any; };
allow-query { any; };

2-1、配置正向解析

編輯檔案/etc/named.rfc1912.zones,在末尾新增需要解析的域

vim /etc/named.rfc1912.zones
zone "panyangduola.com" IN {
  type master;
  file "data/panyangduola.com.zone";
};

建立panyangduola.com.zone解析域

vim /var/named/data/panyangduola.com.zone
$TTL 3600
$ORIGIN panyangduola.com.
@  IN  SOA panyangduola.com. admin.panyangduola.com. (
  2018042101
  1D
  1H
  1W
  3H
)
@  IN  NS  ns1.panyangduola.com.
@  IN  NS  ns2.panyangduola.com.
ns1  IN  A  192.168.219.146
ns2  IN  A  192.168.219.147
www  IN  A  192.168.219.146
web  IN  CNAME www

2-2、配置反向解析

編輯檔案/etc/named.rfc1912.zones,在末尾新增需要解析的域

vim /etc/named.rfc1912.zones
zone "219.168.192.in-addr.arpa" IN {
   type master;
   file "data/219.168.192.zone"; 
};

建立219.168.192.zone解析域

vim /var/named/data/219.168.192.zone
$TTL 3600
$ORIGIN 219.168.192.in-addr.arpa.
@  IN  SOA panyangduola.com. admin.panyangduola.com. (
  2018042101
  1D
  1H
  1W
  3H
)
@  IN  NS  ns1.panyangduola.com.
@  IN  NS  ns2.panyangduola.com.
146  IN  PTR  ns1.panyangduola.com.
147  IN  PTR  ns2.panyangduola.com.
146  IN  PTR  www.panyangduola.com.

2-3、對DNS配置檔案進行一下語法檢查:

cd /etc
named-checkconf named.conf
named-checkconf named.rfc1912.zones
cd /var/named/data
named-checkzone panyangduola.com panyangduola.com.zone
named-checkzone 219.168.192.in-addr.arpa 219.168.192.zone

2-4、編輯/etc/resolv.conf,新增

vim /etc/resolv.conf
search localdomain
nameserver 192.168.219.146

2-5、如果2-3步驟沒有錯誤發生的話,啟動named服務

重啟named

systemctl restart named

檢視狀態

systemctl status named

2-6、檢查主DNS伺服器解析是否成功

ping命令驗證

ping -c 4 www.panyangduola.com
nslookup命令驗證
nslookup
>www.panyangduola.com
nslookup
>192.168.219.146

3、從DNS伺服器(192.168.219.147)配置

編輯named.conf檔案

vim /etc/named.conf

找到其中兩行  

listen-on port 53 { 127.0.0.1; };   
allow-query { localhost; };

修改為

listen-on port 53 { any; };
allow-query { any; };

3-1、修改主DNS伺服器(192.168.219.146)的配置/etc/named.rfc1912.zones

vim /etc/named.rfc1912.zones
zone "panyangduola.com" IN {
  type master;
  file "data/panyangduola.com.zone";
  allow-transfer {192.168.219.147;};
  notify yes;
  also-notify {192.168.219.147;};
};
zone "219.168.192.in-addr.arpa" IN {
  type master;
  file "data/219.168.192.zone";
  allow-transfer {192.168.219.147;}; 
  notify yes; 
  also-notify {192.168.219.147;}; 
};

3-2、配置從DNS伺服器(192.168.219.147)正向解析

編輯檔案/etc/named.rfc1912.zones,在末尾新增需要解析的域

vim /etc/named.rfc1912.zones
zone "panyangduola.com" IN {
  type slave;
  file "data/panyangduola.com.zone";
  masters { 192.168.219.146; };
};

建立panyangduola.com.zone空檔案

touch /var/named/data/panyangduola.com.zone

設定所有者  

cd /var/named/data
chown named:named panyangduola.com.zone

3-3、配置從DNS伺服器(192.168.219.147)反向解析

在檔案/etc/named.rfc1912.zones中新增

vim etc/named.rfc1912.zones
zone "219.168.192.in-addr.arpa" IN {
 type slave;
 file "data/219.168.192.zone";
 masters { 192.168.219.146; };   
};

建立空檔案219.168.192.zone

touch /var/named/data/219.168.192.zone

設定所有者

cd /var/named/data
chown named:named 219.168.192.zone

3-4、對DNS配置檔案進行一下語法檢查:

cd /etc
named-checkconf named.conf
named-checkconf named.rfc1912.zones

3-5、編輯/etc/resolv.conf,新增

vim /etc/resolv.conf
search localdomain
nameserver 192.168.219.147

3-6、如果3-4步驟沒有錯誤發生的話,啟動named服務

重啟named

systemctl restart named

檢視狀態

systemctl status named

3-7、檢視檔案/var/named/data/panyangduola.com.zone和/var/named/data/219.168.192.zone是否有二進位制資料

cat /var/named/data/panyangduola.com.zone
cat /var/named/data/219.168.192.zone

3-8、檢查從DNS伺服器解析是否成功

ping命令驗證
ping -c 4 www.panyangduola.com
nslookup命令驗證
nslookup
>192.168.219.147

總結

以上所述是小編給大家介紹的centos7.x 部署主、從DNS伺服器問題,希望對大家有所幫助,如果大家有任何疑問請給我留言,小編會及時回覆大家的。在此也非常感謝大家對碼農教程網站的支援!
如果你覺得本文對你有幫助,歡迎轉載,煩請註明出處,謝謝!