bind配置内网解析部分子域名,其它子域名转发。以下以m.xxx.com和admin.xxx.com由内网dns解析,其它*.xxx.com转发给外网dns解析为例配置。
文件/etc/named.conf:
options {
# listen-on port 53 { 127.0.0.1; }; #注释表示监听所有端口
# listen-on-v6 port 53 { ::1; };
directory "/var/named";
dump-file "/var/named/data/cache_dump.db";
statistics-file "/var/named/data/named_stats.txt";
memstatistics-file "/var/named/data/named_mem_stats.txt";
recursing-file "/var/named/data/named.recursing";
secroots-file "/var/named/data/named.secroots";
allow-query { any; };
forwarders { 202.96.134.133;8.8.8.8; };#这里指定本地找不到解析转发的服务器列表
recursion yes;
dnssec-enable yes;
dnssec-validation yes;
/* Path to ISC DLV key */