linux+dns的acl,ACL DNS

[root@localhost ~]# rpm -qa | grep bind

bind-libs-9.3.6-4.P1.el5_4.2

bind-utils-9.3.6-4.P1.el5_4.2

ypbind-1.19-12.el5

[root@localhost ~]# mount /dev/cdrom /mnt

mount: block device /dev/cdrom is write-protected, mounting read-only

[root@localhost ~]# yum install bind-* -y

[root@localhost ~]# cd /var/named/chroot/etc

[root@localhost etc]# vim named.conf

options {

directory "/var/named";

};

include "/etc/ipbase";

view CNC {

match-clients { cnc;};

zone "baidu.com" IN {

type master;

file "baidu.com.zone.cnc";

};

};

view DX {

match-clients { dx;};

zone "baidu.com" IN {

type master;

file "baidu.com.zone.dx";

};

};

view other {

match-clients { any;};

zone "baidu.com" IN {

type master;

file "baidu.com.zone.any";

};

};

[root@localhost etc]# vim ipbase

acl cnc {

172.17.17.1;

172.17.17.2;

};

acl dx {

172.17.17.5;

172.17.17.4;

};

[root@localhost etc]# ls

ipbase  localtime  named.conf  rndc.key

[root@localhost etc]#

[root@localhost etc]# rpm -ivh /mnt/Server/caching-nameserver-9.3.6-4.P1.el5_4.2.i386.rpm

将localhost.zone复制到baidu.com.zone.cnc,并配置:

[root@localhost etc]# cd ..

You have new mail in /var/spool/mail/root

[root@localhost chroot]# cd ..

[root@localhost named]# ls

chroot  localdomain.zone  named.broadcast  named.ip6.local  named.zero

data    localhost.zone    named.ca         named.local      slaves

[root@localhost named]# cp localhost.zone baidu.com.zone.cnc

[root@localhost named]# vim baidu.com.zone.cnc

$TTL    86400

@               IN SOA  baidu.com.       root (

42              ; serial (d. adams)

3H              ; refresh

15M             ; retry

1W              ; expiry

1D )            ; minimum

IN NS           www.baidu.com.

www             IN A            127.0.0.1

IN AAAA         ::1

[root@localhost named]# cp baidu.com.zone.cnc baidu.com.zone.dx

[root@localhost named]# cp baidu.com.zone.cnc baidu.com.zone.any

[root@localhost named]# vim baidu.com.zone.dx

$TTL    86400

@               IN SOA  baidu.com.       root (

42              ; serial (d. adams)

3H              ; refresh

15M             ; retry

1W              ; expiry

1D )            ; minimum

IN NS           www.baidu.com.

www             IN A            127.0.0.2

IN AAAA         ::1

[root@localhost named]# vim baidu.com.zone.any

$TTL    86400

@               IN SOA  baidu.com.       root (

42              ; serial (d. adams)

3H              ; refresh

15M             ; retry

1W              ; expiry

1D )            ; minimum

IN NS           www.baidu.com.

www             IN A            127.0.0.3

IN AAAA         ::1

重启named:

[root@localhost named]# service named restart

停止 named:                                               [确定]

启动 named:                                               [确定]

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值