父域和子域配置實現
阿新 • • 發佈:2021-01-10
- 父域配置 10.0.0.101
[root@localhost ~]# vim /etc/named.conf options { // listen-on port 53 { 127.0.0.1; }; // allow-query { localhost; }; allow-transfer {10.0.0.102;}; #只允許從伺服器(子域)進行區域傳輸 } dnssec-enable no; #關閉加密驗證 dnssec第二步:修改主配置檔案/etc/named.rfc1912.zones,建立區域資訊-validation no;
[root@localhost ~]# vim /etc/named.rfc1912.zones zone "magedu.org" IN { type master; file "magedu.org.zone"; };第三步:建立區域資料庫檔案,並修改許可權、所屬組
[root@localhost ~]# vim /var/named/magedu.org.zone $TTL 1D @ IN SOA master admin.magedu.org. (第四步:重啟伺服器20201231 1H 10M 3D 12H ) NS ns1 shanghai NS ns2 #建立一個NS記錄shanghai.magedu.org. ns1 A 10.0.0.101 ns2 A 10.0.0.102 #將子域shanghai.magedu.org.指向10.0.0.102 www A10.0.0.103 [root@localhost named]# chmod 640 magedu.org.zone [root@localhost named]# chown .named magedu.org.zone
systemctl restart named
- 子域配置 10.0.0.102
options { // listen-on port 53 { 127.0.0.1; }; // allow-query { localhost; }; allow-transfer {none;}; }第二步:修改主配置檔案/etc/named.rfc1912.zones,建立區域資訊
[root@localhost ~]# vim /etc/named.rfc1912.zones zone "shanghai.magedu.org" IN { type master; file "shanghai.magedu.org.zone"; };第三步:建立區域資料庫檔案,並修改許可權、所屬組
[root@localhost named]# vim shanghai.magedu.org.zone $TTL 1D @ IN SOA master admin.magedu.org. ( 20201231 1H 10M 3D 12H ) NS ns1 ns1 A 10.0.0.102 k8s A 10.0.0.200 www A 10.0.0.201 [root@localhost named]# chmod 640 shanghai.magedu.org.zone [root@localhost named]# chown .named shanghai.magedu.org.zone第四步:重啟伺服器
systemctl restart named
- 客戶端測試
dig k8s.shanghai.magedu.org @10.0.0.101 dig www.shanghai.magedu.org @10.0.0.101