1. 程式人生 > 實用技巧 >從零開始部署bind9伺服器之二:部署快取伺服器

從零開始部署bind9伺服器之二:部署快取伺服器

所有操作均在192.168.1.104上進行

一、安裝bind9:

yum install -y bind

二、修改配置檔案:

cp /etc/named.conf{,.back} //先做備份

vim /etc/named.conf

wKiom1hqOj2CHUEcAAIIvK9tNW0151.png

三、啟動服務:

chkconfig --level 35 named on //設定開機啟動

service named start

驗證:

wKioL1hqOm3Do_r3AADYj5LmZ5s755.png

dig -t A www.souhu.com @192.168.1.104 //在192.168.1.0/24主機上操作

wKiom1hqOoOTnHVQAABcK98PPUw645.png

dig -t A www.sina.com @192.168.1.104 //在非192.168.1.0/24主機上操作

wKioL1hqOpyxr35WAAC2iMdEH2s621.png

附:

/etc/named.conf

//
//named.conf
//
//ProvidedbyRedHatbindpackagetoconfiguretheISCBINDnamed(8)DNS
//serverasacachingonlynameserver(asalocalhostDNSresolveronly).
//
//See/usr/share/doc/bind*/sample/forexamplenamedconfigurationfiles.
//

//自定義acl
aclmyNet{
192.168.1.0/24;
};

options{
listen-onport53{192.168.1.104;127.0.0.1;};
//listen-on-v6port53{::1;};
directory"/var/named";
dump-file"/var/named/data/cache_dump.db";
statistics-file"/var/named/data/named_stats.txt";
memstatistics-file"/var/named/data/named_mem_stats.txt";
allow-query{any;};//允許任何主機查詢
recursionyes;//開啟遞迴查詢功能
allow-recursion{myNet;};//只允許指定的客戶端進行遞迴查詢
dnssec-enableno;//關閉dnssec
dnssec-validationno;//關閉dnssec

/*PathtoISCDLVkey*/
//bindkeys-file"/etc/named.iscdlv.key";

//managed-keys-directory"/var/named/dynamic";
};

logging{
channeldefault_debug{
file"data/named.run";
severitydynamic;
};
};

zone"."IN{
typehint;
file"named.ca";
};

include"/etc/named.rfc1912.zones";
include"/etc/named.root.key";



轉載於:https://blog.51cto.com/362475097/1888377