###selinux的初级管理###
1.什么时selinux
selinux,内核级加强型防火墙
2.如何管理selinux级别
selinux开启或者关闭)
vim /etc/sysconfig/selinux
selinux=disabled ##关闭状态
selinux=Enforcing ##强制状态
selinux=Permissive ##警告状态
getenforce ##查看状态
当selinux开启时
setenforce 0|1 ##更改selinux运行级别
3.如何更改文件安全上下文
临时更改)
chcon -t 安全上下文 文件
chcon -t public_content_t /publicftp -R
永久更改)
semanage fcontext -l ##列出内核安全上下文列表内容
semanage fcontext -a -t public_content_t '/publicftp(/.*)?'
restorecon -FvvR /publicftp/
4.如何控制selinux对服务功能的开关
getsebool -a | grep 服务名称
getsebool -a | grep ftp
setsebool -P 功能bool值 on|off
setsebool -P ftpd_anon_write on
5.监控selinux的错误信息
setroubleshoot-server
###系统恢复###
1.系统启动流程
通电
||
bios(主板上的只读存储中,basic input or output system)
作用,硬件检测,激活硬件
||
grub系统引导(grub引导分为两个阶段)
1)阶段1 mbr(主引导记录)主引导记录在硬盘上的0磁道,一扇区,446个字节
*)dd if=/dev/zero of=/dev/vda bs=446 count=1 可以清空mbr
*)进入到挽救模式,执行chroot /mnt/sysimage切换到真实/环境,
并执行grub2-install /dev/vda
2)阶段2 grub文件引导阶段
找到/boot分区
读取/boot/grub2/grub.cfg
文件丢失,grub2-mkconfig >/boot/grub2/grub.cfg
||
启动内核,只读挂载/设备
检测设备
对设备驱动进行初始化
进入系统初始化阶段
内核丢失,从新安装内核安装包就可以解决
rpm -ivh kernel-xxxxx.rpm --force
||
系统初始化阶段
系统初始化阶段加载initrd镜像
开启初始化进程systemd
开始selinux
加载内核参数
初始化系统时钟,键盘,主机名称
重新读写挂载/设备
激活raid,lvm
激活配额
启动multi-user.target.wants中的所有服务
开启虚拟控制台
启动图形
initramfs-`uname -r`.img丢失用:
mkinitrd initramfs-`uname -r`.img `uname -r`
恢复
改密码
###dns高速缓存###
第一步(服务配置):
修改server主机ip为172.25.254.118 (作为dns服务器端)
修改server主机ip为172.25.254.218 (作为dns客户端)
两台主机同时做:
修改yum源为http://172.25.254.250/rhel7
yum install bind -y
systemctl status named
systemctl start named
systemctl enable named
server主机:
firewall-cmd --permanent --add-service=dns
firewall-cmd --reload
vim /etc/named.conf
修改内容为:
行数 内容
11 listen-on port 53 { any; }; ##设定端口开放,any表示所有interface都开
17 allow-query { any; }; ##回答所有人的问题
18 forwarders { 172.25.254.250; }; ##缓存谁的答案
32 dnssec-validation no; ##表示不发布dns表
desktop主机:
vim /etc/resolv.conf
添加内容为:
nameserver 172.25.254.118 ##在第三行添加
然后进行测试,如:
dig www.xxx.com
示例:
[root@client-dns ~]# dig www.qq.com
; <<>> DiG 9.9.4-RedHat-9.9.4-14.el7 <<>> www.qq.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 26942
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 4, ADDITIONAL: 4
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;www.qq.com. IN A
;; ANSWER SECTION:
www.qq.com. 300 IN A 113.142.21.81
;; AUTHORITY SECTION:
www.qq.com. 83653 IN NS ns-cnc1.qq.com.
www.qq.com. 83653 IN NS ns-tel1.qq.com.
www.qq.com. 83653 IN NS ns-os1.qq.com.
www.qq.com. 83653 IN NS ns-cmn1.qq.com.
;; ADDITIONAL SECTION:
ns-cmn1.qq.com. 2939 IN A 183.232.120.59
ns-cmn1.qq.com. 2939 IN A 182.254.16.102
ns-cmn1.qq.com. 2939 IN A 182.254.111.100
;; Query time: 53 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 01:53:10 EST 2016
;; MSG SIZE rcvd: 190
第二步(正向解析,规范名称-CNAME):
配置(server主机):
修改/etc/named.conf文件的内容:
删除第18行,即,删除 forwarders { 172.25.254.250; };
退出保存
vim /etc/named.rfc1912.zones
修改内容为:
在第25行添加内容为:
25 zone "westos.com" IN {
26 type master;
27 file "westos.com.zone";
28 allow-update { none; };
29 };
30
退出保存,然后执行:
cd /var/named
cp -p named.localhost westos.com.zone ##一定要加-p,-p的作用是权限
vim /var/named/westos.com.zone
修改文件/var/named/westos.com.zone内容为:
(!!!@@@注意:修改此文件时一定要注意“.”的存在,若不带"."则系统自动往后面添加.westos.com)
1 $TTL 1D
2 @ IN SOA dns.westos.com. root.westos.com. (注意“.”) (
3 0 ; serial
4 1D ; refresh
5 1H ; retry
6 1W ; expire
7 3H ) ; minimum
8 NS dns.westos.com.(注意“.”)
9 dns A 172.25.254.118
10 www A 172.25.254.18
11 AAAA ::1
12 bbs CNAME www.westos.com.
13 westos.com. MX 1 172.25.254.118. ##发送邮件的地址
退出保存后,执行:
systemctl restart named
测试(desktop主机):
[root@client-dns ~]# dig www.westos.com
;www.westos.com. IN A
;; ANSWER SECTION:
www.westos.com. 86400 IN A 172.25.254.18
;; AUTHORITY SECTION:
westos.com. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 2 msec
;; SERVER: 172.25.254.107#53(172.25.254.107)
;; WHEN: Sun Nov 20 02:26:03 EST 2016
;; MSG SIZE rcvd: 93
[root@client-dns ~]# dig bbs.westos.com
;bbs.westos.com. IN A
;; ANSWER SECTION:
bbs.westos.com. 86400 IN CNAME www.westos.com.
www.westos.com. 86400 IN A 172.25.254.18
;; AUTHORITY SECTION:
westos.com. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 2 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 02:54:42 EST 2016
;; MSG SIZE rcvd: 111
第三步(反向解析):
vim /etc/named.rfc1912.zones
编写/etc/named.rfc1912.zones文件内容:
在第43行添加:
43 zone "254.25.172.in-addr.arpa" IN {
44 type master;
45 file "westos.com.ptr";
46 allow-update { none; };
47 };
退出保存后
cd /var/named
cp -p named.loopback westos.com.ptr
vim westos.com.ptr
内容为:
1 $TTL 1D
2 @ IN SOA dns.westos.com. root.westos.com. (
3 0 ; serial
4 1D ; refresh
5 1H ; retry
6 1W ; expire
7 3H ) ; minimum
8 NS dns.westos.com.
9 A 172.25.254.118
10 AAAA ::1
11 111 PTR www.westos.com.
12 110 PTR www.lover.com.
退出保存后,执行:
systemctl restart named
测试(desktop主机):
使用命令: dig -x 172.25.254.110 (ip值)
[root@client-dns ~]# dig -x 172.25.254.110
;110.254.25.172.in-addr.arpa. IN PTR
;; ANSWER SECTION:
110.254.25.172.in-addr.arpa. 86400 IN PTR www.lover.com.
;; AUTHORITY SECTION:
254.25.172.in-addr.arpa. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 2 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 03:09:51 EST 2016
;; MSG SIZE rcvd: 124
[root@client-dns ~]# dig -x 172.25.254.111
;111.254.25.172.in-addr.arpa. IN PTR
;; ANSWER SECTION:
111.254.25.172.in-addr.arpa. 86400 IN PTR www.westos.com.
;; AUTHORITY SECTION:
254.25.172.in-addr.arpa. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 2 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 03:09:57 EST 2016
;; MSG SIZE rcvd: 118
第四步(双向解析):
配置/etc/named.conf文件,如下:
50 /*zone "." IN {
51 type hint;
52 file "named.ca";
53 };
54
55 include "/etc/named.rfc1912.zones";
56 include "/etc/named.root.key";
57 */
58 view localnet {
59 match-clients { 172.25.254.118; };
60 zone "." IN {
61 type hint;
62 file "named.ca";
63 };
64 include "/etc/named.rfc1912.zones";
65 };
66
67
68 view internet {
69 match-clients { any; };
70 zone "." IN {
71 type hint;
72 file "named.ca";
73 };
74 include "/etc/named.rfc1912.zones.inter";
75 };
退出保存
cp -p /etc/named.rfc1912.zones /etc/named.rfc1912.zones.inter
vim /etc/named.rfc1912.zones.inter
内容为:
25 zone "westos.com" IN {
26 type master;
27 file "westos.com.inter";
28 allow-update { none; };
29 };
30
43 zone "254.25.172.in-addr.arpa" IN {
44 type master;
45 file "westos.com.ptr.inter";
46 allow-update { none; };
退出保存
cp -p /var/named/westos.com.zone /var/named/westos.com.inter
vim /etc/named/westos.com.inter
修改内容为:
8 NS dns.westos.com.
9 dns A 172.25.0.118
10 www A 172.25.0.18
11 AAAA ::1
12 bbs CNAME www.westos.com.
13 westos.com. MX 1 172.25.0.218.
退出保存
cp -p /var/named/westos.com.ptr /var/named/westos.com.ptr.inter
vim /var/named/westos.com.ptr.inter
修改内容为:
8 NS dns.westos.com.
9 A 172.25.254.118
10 AAAA ::1
11 111 PTR www.force.com.
12 110 PTR www.250.com.
退出保存
然后执行:
systemctl restart named
按照上述顺序,在此处重启服务正常,若想在配置完/etc/named.conf文件后,立即restart服务,则需要把上述顺序颠倒
测试一(server主机):
@@@注意:若出现不匹配现象,则需要修改/etc/resolv.conf 文件,文件内容修改为:
nameserver 172.25.254.118 ##在第三行添加
[root@dns-server named]# dig -x 172.25.254.110
;110.254.25.172.in-addr.arpa. IN PTR
;; ANSWER SECTION:
110.254.25.172.in-addr.arpa. 86400 IN PTR www.lover.com.
;; AUTHORITY SECTION:
254.25.172.in-addr.arpa. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 2 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 04:04:21 EST 2016
;; MSG SIZE rcvd: 124
[root@dns-server ~]# dig www.westos.com
;www.westos.com. IN A
;; ANSWER SECTION:
www.westos.com. 86400 IN A 172.25.254.18
;; AUTHORITY SECTION:
westos.com. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 1 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 04:00:23 EST 2016
;; MSG SIZE rcvd: 93
测试二(desktop主机):
[root@client-dns ~]# dig www.westos.com
;www.westos.com. IN A
;; ANSWER SECTION:
www.westos.com. 86400 IN A 172.25.0.18
;; AUTHORITY SECTION:
westos.com. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.0.118
;; Query time: 2 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 04:00:02 EST 2016
;; MSG SIZE rcvd: 93
[root@client-dns ~]# dig -x 172.25.254.110
;110.254.25.172.in-addr.arpa. IN PTR
;; ANSWER SECTION:
110.254.25.172.in-addr.arpa. 86400 IN PTR www.250.com.
;; AUTHORITY SECTION:
254.25.172.in-addr.arpa. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.0.118
;; Query time: 1 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 04:04:38 EST 2016
;; MSG SIZE rcvd: 122
1.什么时selinux
selinux,内核级加强型防火墙
2.如何管理selinux级别
selinux开启或者关闭)
vim /etc/sysconfig/selinux
selinux=disabled ##关闭状态
selinux=Enforcing ##强制状态
selinux=Permissive ##警告状态
getenforce ##查看状态
当selinux开启时
setenforce 0|1 ##更改selinux运行级别
3.如何更改文件安全上下文
临时更改)
chcon -t 安全上下文 文件
chcon -t public_content_t /publicftp -R
永久更改)
semanage fcontext -l ##列出内核安全上下文列表内容
semanage fcontext -a -t public_content_t '/publicftp(/.*)?'
restorecon -FvvR /publicftp/
4.如何控制selinux对服务功能的开关
getsebool -a | grep 服务名称
getsebool -a | grep ftp
setsebool -P 功能bool值 on|off
setsebool -P ftpd_anon_write on
5.监控selinux的错误信息
setroubleshoot-server
###系统恢复###
1.系统启动流程
通电
||
bios(主板上的只读存储中,basic input or output system)
作用,硬件检测,激活硬件
||
grub系统引导(grub引导分为两个阶段)
1)阶段1 mbr(主引导记录)主引导记录在硬盘上的0磁道,一扇区,446个字节
*)dd if=/dev/zero of=/dev/vda bs=446 count=1 可以清空mbr
*)进入到挽救模式,执行chroot /mnt/sysimage切换到真实/环境,
并执行grub2-install /dev/vda
2)阶段2 grub文件引导阶段
找到/boot分区
读取/boot/grub2/grub.cfg
文件丢失,grub2-mkconfig >/boot/grub2/grub.cfg
||
启动内核,只读挂载/设备
检测设备
对设备驱动进行初始化
进入系统初始化阶段
内核丢失,从新安装内核安装包就可以解决
rpm -ivh kernel-xxxxx.rpm --force
||
系统初始化阶段
系统初始化阶段加载initrd镜像
开启初始化进程systemd
开始selinux
加载内核参数
初始化系统时钟,键盘,主机名称
重新读写挂载/设备
激活raid,lvm
激活配额
启动multi-user.target.wants中的所有服务
开启虚拟控制台
启动图形
initramfs-`uname -r`.img丢失用:
mkinitrd initramfs-`uname -r`.img `uname -r`
恢复
改密码
###dns高速缓存###
第一步(服务配置):
修改server主机ip为172.25.254.118 (作为dns服务器端)
修改server主机ip为172.25.254.218 (作为dns客户端)
两台主机同时做:
修改yum源为http://172.25.254.250/rhel7
yum install bind -y
systemctl status named
systemctl start named
systemctl enable named
server主机:
firewall-cmd --permanent --add-service=dns
firewall-cmd --reload
vim /etc/named.conf
修改内容为:
行数 内容
11 listen-on port 53 { any; }; ##设定端口开放,any表示所有interface都开
17 allow-query { any; }; ##回答所有人的问题
18 forwarders { 172.25.254.250; }; ##缓存谁的答案
32 dnssec-validation no; ##表示不发布dns表
desktop主机:
vim /etc/resolv.conf
添加内容为:
nameserver 172.25.254.118 ##在第三行添加
然后进行测试,如:
dig www.xxx.com
示例:
[root@client-dns ~]# dig www.qq.com
; <<>> DiG 9.9.4-RedHat-9.9.4-14.el7 <<>> www.qq.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 26942
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 4, ADDITIONAL: 4
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;www.qq.com. IN A
;; ANSWER SECTION:
www.qq.com. 300 IN A 113.142.21.81
;; AUTHORITY SECTION:
www.qq.com. 83653 IN NS ns-cnc1.qq.com.
www.qq.com. 83653 IN NS ns-tel1.qq.com.
www.qq.com. 83653 IN NS ns-os1.qq.com.
www.qq.com. 83653 IN NS ns-cmn1.qq.com.
;; ADDITIONAL SECTION:
ns-cmn1.qq.com. 2939 IN A 183.232.120.59
ns-cmn1.qq.com. 2939 IN A 182.254.16.102
ns-cmn1.qq.com. 2939 IN A 182.254.111.100
;; Query time: 53 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 01:53:10 EST 2016
;; MSG SIZE rcvd: 190
第二步(正向解析,规范名称-CNAME):
配置(server主机):
修改/etc/named.conf文件的内容:
删除第18行,即,删除 forwarders { 172.25.254.250; };
退出保存
vim /etc/named.rfc1912.zones
修改内容为:
在第25行添加内容为:
25 zone "westos.com" IN {
26 type master;
27 file "westos.com.zone";
28 allow-update { none; };
29 };
30
退出保存,然后执行:
cd /var/named
cp -p named.localhost westos.com.zone ##一定要加-p,-p的作用是权限
vim /var/named/westos.com.zone
修改文件/var/named/westos.com.zone内容为:
(!!!@@@注意:修改此文件时一定要注意“.”的存在,若不带"."则系统自动往后面添加.westos.com)
1 $TTL 1D
2 @ IN SOA dns.westos.com. root.westos.com. (注意“.”) (
3 0 ; serial
4 1D ; refresh
5 1H ; retry
6 1W ; expire
7 3H ) ; minimum
8 NS dns.westos.com.(注意“.”)
9 dns A 172.25.254.118
10 www A 172.25.254.18
11 AAAA ::1
12 bbs CNAME www.westos.com.
13 westos.com. MX 1 172.25.254.118. ##发送邮件的地址
退出保存后,执行:
systemctl restart named
测试(desktop主机):
[root@client-dns ~]# dig www.westos.com
;www.westos.com. IN A
;; ANSWER SECTION:
www.westos.com. 86400 IN A 172.25.254.18
;; AUTHORITY SECTION:
westos.com. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 2 msec
;; SERVER: 172.25.254.107#53(172.25.254.107)
;; WHEN: Sun Nov 20 02:26:03 EST 2016
;; MSG SIZE rcvd: 93
[root@client-dns ~]# dig bbs.westos.com
;bbs.westos.com. IN A
;; ANSWER SECTION:
bbs.westos.com. 86400 IN CNAME www.westos.com.
www.westos.com. 86400 IN A 172.25.254.18
;; AUTHORITY SECTION:
westos.com. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 2 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 02:54:42 EST 2016
;; MSG SIZE rcvd: 111
第三步(反向解析):
vim /etc/named.rfc1912.zones
编写/etc/named.rfc1912.zones文件内容:
在第43行添加:
43 zone "254.25.172.in-addr.arpa" IN {
44 type master;
45 file "westos.com.ptr";
46 allow-update { none; };
47 };
退出保存后
cd /var/named
cp -p named.loopback westos.com.ptr
vim westos.com.ptr
内容为:
1 $TTL 1D
2 @ IN SOA dns.westos.com. root.westos.com. (
3 0 ; serial
4 1D ; refresh
5 1H ; retry
6 1W ; expire
7 3H ) ; minimum
8 NS dns.westos.com.
9 A 172.25.254.118
10 AAAA ::1
11 111 PTR www.westos.com.
12 110 PTR www.lover.com.
退出保存后,执行:
systemctl restart named
测试(desktop主机):
使用命令: dig -x 172.25.254.110 (ip值)
[root@client-dns ~]# dig -x 172.25.254.110
;110.254.25.172.in-addr.arpa. IN PTR
;; ANSWER SECTION:
110.254.25.172.in-addr.arpa. 86400 IN PTR www.lover.com.
;; AUTHORITY SECTION:
254.25.172.in-addr.arpa. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 2 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 03:09:51 EST 2016
;; MSG SIZE rcvd: 124
[root@client-dns ~]# dig -x 172.25.254.111
;111.254.25.172.in-addr.arpa. IN PTR
;; ANSWER SECTION:
111.254.25.172.in-addr.arpa. 86400 IN PTR www.westos.com.
;; AUTHORITY SECTION:
254.25.172.in-addr.arpa. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 2 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 03:09:57 EST 2016
;; MSG SIZE rcvd: 118
第四步(双向解析):
配置/etc/named.conf文件,如下:
50 /*zone "." IN {
51 type hint;
52 file "named.ca";
53 };
54
55 include "/etc/named.rfc1912.zones";
56 include "/etc/named.root.key";
57 */
58 view localnet {
59 match-clients { 172.25.254.118; };
60 zone "." IN {
61 type hint;
62 file "named.ca";
63 };
64 include "/etc/named.rfc1912.zones";
65 };
66
67
68 view internet {
69 match-clients { any; };
70 zone "." IN {
71 type hint;
72 file "named.ca";
73 };
74 include "/etc/named.rfc1912.zones.inter";
75 };
退出保存
cp -p /etc/named.rfc1912.zones /etc/named.rfc1912.zones.inter
vim /etc/named.rfc1912.zones.inter
内容为:
25 zone "westos.com" IN {
26 type master;
27 file "westos.com.inter";
28 allow-update { none; };
29 };
30
43 zone "254.25.172.in-addr.arpa" IN {
44 type master;
45 file "westos.com.ptr.inter";
46 allow-update { none; };
退出保存
cp -p /var/named/westos.com.zone /var/named/westos.com.inter
vim /etc/named/westos.com.inter
修改内容为:
8 NS dns.westos.com.
9 dns A 172.25.0.118
10 www A 172.25.0.18
11 AAAA ::1
12 bbs CNAME www.westos.com.
13 westos.com. MX 1 172.25.0.218.
退出保存
cp -p /var/named/westos.com.ptr /var/named/westos.com.ptr.inter
vim /var/named/westos.com.ptr.inter
修改内容为:
8 NS dns.westos.com.
9 A 172.25.254.118
10 AAAA ::1
11 111 PTR www.force.com.
12 110 PTR www.250.com.
退出保存
然后执行:
systemctl restart named
按照上述顺序,在此处重启服务正常,若想在配置完/etc/named.conf文件后,立即restart服务,则需要把上述顺序颠倒
测试一(server主机):
@@@注意:若出现不匹配现象,则需要修改/etc/resolv.conf 文件,文件内容修改为:
nameserver 172.25.254.118 ##在第三行添加
[root@dns-server named]# dig -x 172.25.254.110
;110.254.25.172.in-addr.arpa. IN PTR
;; ANSWER SECTION:
110.254.25.172.in-addr.arpa. 86400 IN PTR www.lover.com.
;; AUTHORITY SECTION:
254.25.172.in-addr.arpa. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 2 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 04:04:21 EST 2016
;; MSG SIZE rcvd: 124
[root@dns-server ~]# dig www.westos.com
;www.westos.com. IN A
;; ANSWER SECTION:
www.westos.com. 86400 IN A 172.25.254.18
;; AUTHORITY SECTION:
westos.com. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.254.118
;; Query time: 1 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 04:00:23 EST 2016
;; MSG SIZE rcvd: 93
测试二(desktop主机):
[root@client-dns ~]# dig www.westos.com
;www.westos.com. IN A
;; ANSWER SECTION:
www.westos.com. 86400 IN A 172.25.0.18
;; AUTHORITY SECTION:
westos.com. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.0.118
;; Query time: 2 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 04:00:02 EST 2016
;; MSG SIZE rcvd: 93
[root@client-dns ~]# dig -x 172.25.254.110
;110.254.25.172.in-addr.arpa. IN PTR
;; ANSWER SECTION:
110.254.25.172.in-addr.arpa. 86400 IN PTR www.250.com.
;; AUTHORITY SECTION:
254.25.172.in-addr.arpa. 86400 IN NS dns.westos.com.
;; ADDITIONAL SECTION:
dns.westos.com. 86400 IN A 172.25.0.118
;; Query time: 1 msec
;; SERVER: 172.25.254.118#53(172.25.254.118)
;; WHEN: Sun Nov 20 04:04:38 EST 2016
;; MSG SIZE rcvd: 122