Différences
Ci-dessous, les différences entre deux révisions de la page.
Prochaine révision | Révision précédente | ||
linuxedconfdns [2013/01/26 10:12] – créée madko | linuxedconfdns [2013/01/26 10:29] (Version actuelle) – [Tests DNS] madko | ||
---|---|---|---|
Ligne 1: | Ligne 1: | ||
====== Configuration DNS ====== | ====== Configuration DNS ====== | ||
- | Configuration du service DNS. | + | Configuration du service DNS sur RHEL/CentOS 6. |
===== Installation ===== | ===== Installation ===== | ||
Ligne 10: | Ligne 10: | ||
* bind-libs | * bind-libs | ||
* bind-chroot | * bind-chroot | ||
+ | |||
+ | ===== Configuration ===== | ||
+ | |||
+ | Les fichiers de configuration avec bind chrooté se trouvent dans /// | ||
+ | |||
+ | ===== Fichier de configuration named.conf ===== | ||
+ | |||
+ | Il s'agit du fichier principal de configuration, | ||
+ | |||
+ | < | ||
+ | // | ||
+ | // named.conf | ||
+ | // | ||
+ | // Provided by Red Hat bind package to configure the ISC BIND named(8) DNS | ||
+ | // server as a caching only nameserver (as a localhost DNS resolver only). | ||
+ | // | ||
+ | // See / | ||
+ | // | ||
+ | |||
+ | options { | ||
+ | listen-on port 53 { 91.121.61.20; | ||
+ | // | ||
+ | directory "/ | ||
+ | dump-file "/ | ||
+ | statistics-file "/ | ||
+ | memstatistics-file "/ | ||
+ | // | ||
+ | // | ||
+ | |||
+ | allow-recursion { mes_dns; 127.0.0.1; 94.23.42.209; | ||
+ | allow-notify { mes_dns; }; | ||
+ | version none; | ||
+ | |||
+ | dnssec-enable yes; | ||
+ | dnssec-validation yes; | ||
+ | dnssec-lookaside auto; | ||
+ | |||
+ | /* Path to ISC DLV key */ | ||
+ | bindkeys-file "/ | ||
+ | }; | ||
+ | |||
+ | logging { | ||
+ | channel default_debug { | ||
+ | file " | ||
+ | severity dynamic; | ||
+ | }; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type hint; | ||
+ | file " | ||
+ | }; | ||
+ | |||
+ | include "/ | ||
+ | </ | ||
+ | |||
+ | ===== Fichier de configuration des zones ===== | ||
+ | |||
+ | < | ||
+ | // named.rfc1912.zones: | ||
+ | // | ||
+ | // Provided by Red Hat caching-nameserver package | ||
+ | // | ||
+ | // ISC BIND named zone configuration for zones recommended by | ||
+ | // RFC 1912 section 4.1 : localhost TLDs and address zones | ||
+ | // and http:// | ||
+ | // (c)2007 R W Franks | ||
+ | // | ||
+ | // See / | ||
+ | // | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-update { none; }; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-update { none; }; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-update { none; }; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-update { none; }; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-update { none; }; | ||
+ | }; | ||
+ | |||
+ | acl dns_secondaires { | ||
+ | 89.80.161.232; | ||
+ | 87.89.143.135; | ||
+ | 217.70.177.40; | ||
+ | 94.23.42.209; | ||
+ | }; | ||
+ | |||
+ | acl dns_bookmyname { | ||
+ | 88.191.249.0/ | ||
+ | }; | ||
+ | |||
+ | acl mes_dns { | ||
+ | 89.80.161.232; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-update { none; }; | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-update { none; }; | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-update { none; }; | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type slave; | ||
+ | file " | ||
+ | masters { 82.234.6.243; | ||
+ | }; | ||
+ | |||
+ | //zone " | ||
+ | // type slave; | ||
+ | // file " | ||
+ | // masters { 82.234.6.243; | ||
+ | //}; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-update { none; }; | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | |||
+ | zone " | ||
+ | type master; | ||
+ | file " | ||
+ | allow-update { none; }; | ||
+ | allow-transfer { dns_secondaires; | ||
+ | }; | ||
+ | </ | ||
+ | |||
+ | ====== Tests DNS ====== | ||
+ | |||
+ | Pour tester une résolution: | ||
+ | dig @ip_serveur nom_a_resoudre | ||
+ | | ||
+ | Avec plus d' | ||
+ | dig @ip_serveur nom_a_resoudre +trace | ||
+ | | ||
+ | Ou pour un champ spécifique: | ||
+ | dig @ip_serveur zone NS | ||
+ | dig @ip_serveur zone MX |