域名系统(Domain Name System缩写DNS,Domain Name被译为域名)是因特网的一项核心服务,它作为可以将域名和IP地址相互映射的一个分布式数据库,能够使人更方便的访问互联网,而不用去记住能够被机器直接读取的IP数串。
(1)高速缓存设置
服务器:
yum install bing 下载dns服务器
vim /etc/resolv.conf 配置linux系统DNS服务器的配置文件
nameserver 114.114.114.114 设置DNS服务器的ip地址
systemctl restart network 重启网络
vim /etc/named.conf dns配置文件的设置
11 listen-on port 53 { any; }; 设置任何用户都可以访问53接口
17 allow-query { any; };
18 forwarders { 114.114.114.114; };
32 dnssec-validation no;
systemctl restart named
ping www.baidu.com (出错,查询网关设置)
客户机:
vim /etc/resolv.conf
nameserver 172.25.254.109
验证:
dig www.baidu.com(第二次查询速度更快)
vim /etc/resolv.conf
nameserver 172.25.254.109
vim /etc/named.conf
删除forwarders
systemctl restart named
cp -p /var/named/named.localhost westos.com.zone
vim /etc/named.rfc1912.zones
编辑如下:
zone "westos.com" IN {
type master;
file "westos.com.zone";
allow-update {none;};
};
vim /var/named/westos.com.zone
dig www.westos.com 一个域名对应多个ip
vim /etc/named.rfc1912.zones
zone "1.0.0.127.in-addr.arpa" IN {
type master;
file "named.loopback";
allow-update { none; };
};
zone "0.in-addr.arpa" IN {
type master;
file "named.empty";
allow-update { none; };
};
zone "254.25.172.in-addr.arpa" IN {
type master;
file "westos.com.ptr";
allow-update { none; };
};
cd /var/named ls
cp -p named.loopback westos.com.ptr ls
vim westos.com.ptr
NS dns.westos.com.
dns A 172.25.254.109
111 PTR www.westos.com.
222 PTR linux.wetos.com.
systemctl restart named(重启不了的排错查看/var/log/messages)
验证
dig -x 172.25.254.111
dig -x 172.25.254.222
(4)不同网段的dns解析,双向解析
服务器
cd /var/named
cp -p westos.com.zone westos.com.inter
vim westos.com.inter
改变ip
cp -p /etc/named.rfc1912.zones /etc/named.rfc1912.inter
vim /etc/named.rfc1912.inter
vim /etc/named.conf
systemctl restart named
测试
客户机
vim /etc/resolv.conf
nameserver 172.25.88.56
验证:
dig www.westos.com 出现改正后的ip
服务器
vim /etc/named.rfc1912.zones
辅助服务器
vim /etc/resolv.conf
nameserver 172.25.254.109
dig www.westos.com
vim /etc/named.rfc1912.zones
systemctl restart named
systemctl stop firewalld
dig www.westos.com
(6) dns的更新
主dns服务器
cp -p /var/named/westos.com.zone /mnt/
ll -d /var/named
chmod 770 /var/named 赋予目录下的文件有写的权限
vim /etc/named.rfc1912.zones
getenforce查询selinux状态是否为disabled状态
systemctl restart named
测试机
vim /etc/resolv.conf
检查nameserver 172.25.254.109
主dns服务器
systemctl restart named
vim /var/named/westos.com.zone 查看,test.westos.com 172.25.254.231已更新
cd /var/named
rm -fr westos.com.zone*
cp -p /mnt/westos.com.zone . 进行实验还原
(6)dns解析加密
vim /etc/rndc.key
dnssec-keygen -a HMAC-MD5 -b 128 -n HOST westos
ls
cat Kwestos.+157+50214.key
cat Kwestos.+157+50214.private
cp /etc/rndc.key /etc/westos.key -p
vim /etc/westos.key
vim /etc/named.conf
vim /etc/named.rfc1912.zones
服务器
scp Kwestos.+157+50214.* root@172.25.254.9:/mnt 传送钥匙给客户端
客户端
测试
cd /mnt
ls
服务器端验证
systemctl restart named
vim /var/named/westos.com.zone
7)
动态域名解析(花生壳)
主dns服务器
yum install dhcp
cp /usr/share/doc/dhcp-4.2.5/dhcpd.conf.example /etc/dhcp/dhcpd.conf
vim /etc/dhcp/dhcpd.conf
systemctl restart network
systemctl start dhcpd
测试机
vim /etc/sysconfig/network-scripts/ifcfg-eth0
测试机
systemctl restart network
hostnamectl set-hostname linux.westos.com
dig linux.westos.com
systemctl retsrat network
systemctl restart named
测试机
systemctl restart network
dig wn.westos.com