【问题标题】:Very simple bind9 DNS server非常简单的bind9 DNS服务器
【发布时间】:2021-03-24 06:01:14
【问题描述】:

我正在使用 Debian server 10 和 bind9 作为我的 DNS 服务器网络,我想非常简单地使用 DNS 服务器,我的拓扑如下所示:

client <-> DNS <-> voip.example.com

client IP: 172.17.106.9
client DNS primary: 172.17.106.15
client DNS secondary: 8.8.8.8

DNS IP: 172.17.106.15

voip.example.com IP: 172.17.106.12

我想在收到客户端的每个请求时检查DNS记录,如果不匹配,就去客户端的二级DNS(8.8.8.8)中存储的二级DNS

我在客户端 cmd 上收到此错误:

C:\Users\Farhad>nslookup voip.example.com
Server:  ns1.example.com
Address:  172.17.106.15

*** ns1.example.com can't find voip.example.com: Server failed

我的 bind9 配置在这里:

/etc/bind/named.conf.local

zone "example.com" {
    type master;
    file "/etc/bind/db.example.com";            # zone file path
};

zone "17.172.in-addr.arpa" {
    type master;
    file "/etc/bind/db.172.17";                 # 172.17.0.0/16 subnet
};

/etc/bind/named.conf.options

acl "trusted" {
        172.17.106.15;  # ns1
        172.17.106.9;   # client
        172.17.106.12;  # VoIP
};

options {
        directory "/var/cache/bind";

        recursion yes;                 # enables resursive queries
        allow-recursion { trusted; };  # allows recursive queries from "trusted" clients
        listen-on { 172.17.106.15; };   # ns1 private IP address - listen on private network only
        allow-transfer { none; };      # disable zone transfers by default

        forwarders {
                8.8.8.8;
                8.8.4.4;
        };

};

/etc/bind/db.example.com

$TTL    604800
@                               IN      SOA     ns1.example.com.    f.example.com. (
                                3               ; Serial
                                604800          ; Refresh
                                86400           ; Retry
                                2419200         ; Expire
                                604800 )        ; Negative Cache TTL
;

; name servers - NS records
                                IN      NS      ns1.example.com.

; name servers - A records
ns1.example.com.            IN      A       172.17.106.15

; 172.16.0.0/16 - A records
voip.example.com.           IN      A       172.17.106.12

/etc/bind/db.172.17

$TTL    604800
@               IN      SOA     ns1.example.com.    f.example.com. (
                3               ; Serial
                604800          ; Refresh
                86400           ; Retry
                2419200         ; Expire
                604800 )        ; Negative Cache TTL
;

; name servers
            IN      NS      ns1.example.com.

; PTR Records
15.106      IN      PTR     ns1.example.com.        ; 172.17.106.15
12.106      IN      PTR     voip.example.com.       ; 172.17.106.12

【问题讨论】:

  • 您没有主机 farhad.example.com 的 A 记录。这解释了can't find 消息,但服务器不应因否定结果而失败,因此存在一些错误配置。您是否尝试过像www.google.com 这样的现有主机来检查转发是否有效?你看过绑定日志文件吗?
  • 抱歉,我更改了我的 nslookup 命令
  • 所以它无法解析example.com中的主机。检查 ns1 上的命名日志并运行命令 named-checkzone example.com &lt;path-to-zone-file&gt;
  • 谢谢@YuriGinsburg 这可以正确解析我的IP

标签: dns bind bind9


【解决方案1】:

现在它可以正常使用更改的 db.example.com 并删除 ns2 记录并准确解析 voip.example.com 的 IP 地址

但我的主要问题仍然存在: 我想在收到客户端的每个请求时检查DNS记录,如果不匹配,则转到存储在客户端辅助DNS(8.8.8.8)中的辅助DNS

例如一些客户端请求到达 test.com ,客户端有主 dns 172.17.106.15 和辅助 dns 8.8.8.8

查询已从客户端修改到我的 dns 服务器 172.17.106.15,但没有转到 8.8.8.8

【讨论】:

    猜你喜欢
    • 2012-06-17
    • 2022-01-05
    • 2016-02-05
    • 1970-01-01
    • 2014-12-20
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2014-12-31
    相关资源
    最近更新 更多