- dig –t axfr doubao.com //完全区域传送
- dig –t IXFR=2013040201 doubao.com //查看增量信息
- [root@localhost ~]# rpm -ql bind
- package bind is not installed //老版本已经卸载
- [root@localhost ~]# rpm -ql bind97
- /etc/NetworkManager/dispatcher.d/13-named
- /etc/logrotate.d/named
- /etc/named
- /etc/named.conf
- /etc/named.iscdlv.key
- /etc/named.rfc1912.zones
- /etc/named.root.key
- /etc/rc.d/init.d/named
- /etc/rndc.conf
- /etc/rndc.key
- /etc/sysconfig/named //bind97已经安装
- [root@localhost ~]# cd /etc/yum.repos.d/
- [root@localhost yum.repos.d]# ls
- redhat.repo rhel-debuginfo.repo server.repo yumsever.repo
- [root@localhost yum.repos.d]# cd
- [root@localhost ~]# ls -ld /var/named/
- drwxr-x--- 5 root named 4096 Apr 1 18:01 /var/named/ //由于named这里没有写权限,所以我们重新选择一个别的
- [root@localhost ~]# ls -ld /var/named/
- drwxr-x--- 5 root named 4096 Apr 1 18:01 /var/named/
- [root@localhost ~]# ls -l /var/named/
- total 72
- -rw-r----- 1 root named 231 Apr 1 18:01 172.16.111.zone
- drwxrwx--- 2 named named 4096 Nov 17 2011 data
- -rw-r----- 1 root named 282 Apr 1 17:41 doubao.com.zone
- drwxrwx--- 2 named named 4096 Nov 17 2011 dynamic
- -rw-r----- 1 root named 1892 Feb 18 2008 named.ca
- -rw-r----- 1 root named 152 Dec 15 2009 named.empty
- -rw-r----- 1 root named 152 Jun 21 2007 named.localhost
- -rw-r----- 1 root named 168 Dec 15 2009 named.loopback
- drwxrwx--- 2 named named 4096 Nov 17 2011 slaves //对,就是这里这个文件
- [root@localhost ~]# setenforce 0
- vim /etc/named.conf
- options {
- directory "/var/named";
- };
- zone "." IN {
- type hint;
- file "named.ca";
- };
- zone "localhost" IN {
- type master;
- file "named.localhost";
- };
- zone "0.0.127.in-addr.arpa" IN {
- type master;
- file "named.loopback";
- };
- zone "doubao.com" IN { //配置从服务器
- type slave;
- file "slave/doubao.com.zone"; //保存位置
- masters { 172.16.111.1; }; //配置主服务器路径
- allow-transfer { none; }; //不允许传送
- };
- zone "111.16.172.in-addr.arpa" IN {
- type slave;
- file "slave/172.16.111.zone";
- masters { 172.16.111.1; };
- allow-transfer { none; };
- };
- [root@localhost etc]# ls -l named.conf
- -rw-r----- 1 root named 493 Apr 4 12:00 named.conf //权限named组是读取不到的
- [root@localhost etc]# chgrp named /etc/named.conf
- tail /var/log/messages //查看下是否进行了区域传送。
- service named reload //重读
- tail /var/log/messages
- tail /var/log/messages
- rndc的用法
- -c 指定配置文件
- -s 指定远程服务器是谁
- -p 指定以哪个端口进行连接
- -k 以哪个key文件进行发送文件
- 注意:因为rndc是远程控制,所以为了防止外人通过其来进行攻击,我们首先要为其提供key