linux dns递归功能,linux – bind9正确的递归设置

如果我删除递归,那么我无法解析外部域,但仍然可以解析DNS服务器上的域.

正确设置递归的正确方法是什么,这样可以在不让DNS服务器打开的情况下解析外部域?

named.conf.options

options {

version "One does not simply get my version";

directory "/var/cache/bind";

// If there is a firewall between you and nameservers you want

// to talk to,you may need to fix the firewall to allow multiple

// ports to talk. See http://www.kb.cert.org/vuls/id/800113

// If your ISP provided one or more IP addresses for stable

// nameservers,you probably want to use them as forwarders.

// Uncomment the following block,and insert the addresses replacing

// the all-0's placeholder.

// forwarders {

// 0.0.0.0;

// };

//========================================================================

// If BIND logs error messages about the root key being expired,// you will need to update your keys. See https://www.isc.org/bind-keys

//========================================================================

dnssec-validation yes;

auth-nxdomain no;

listen-on-v6 { any; };

allow-recursion { any; };

allow-query {

any;

};

allow-query-cache { any; };

notify yes;

dnssec-enable yes;

dnssec-lookaside . trust-anchor dlv.isc.org.;

also-notify {

};

};

我还在内部子网中添加了允许递归{subnet / xx; };但仍无法解析外部域名.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值