DNS域名解析服务(正反向解析)

一、正向解析

1、修改服务端、客户端的IP为静态IP,安装软件

服务端:
[root@node1 ~]# setenforce 0  #关闭SELinux
setenforce: SELinux is disabled 
[root@node1 ~]# systemctl stop firewalld   #关闭防火墙
[root@node1 ~]# nmcli connection modify ens160 ipv4.address '192.168.16.130/24' ipv4.gateway '192.168.16.2' ipv4.dns '114.114.114.114'
[root@node1 ~]# nmcli connection reload #关闭
[root@node1 ~]# nmcli connection up ens160 #打开网卡
连接已成功激活(D-Bus 活动路径:/org/freedesktop/NetworkManager/ActiveConnection/2)
[root@node1 ~]# yum install bind -y


客户端:
[root@node1 ~]# setenforce 0
setenforce: SELinux is disabled
[root@node1 ~]# systemctl stop firewalld
[root@node1 ~]# nmcli connection modify ens160 ipv4.addresses '192.168.16.135/24' ipv4.gateway '192.168.16.2' ipv4.dns '114.114.114.114'
[root@node1 ~]# nmcli connection reload 
[root@node1 ~]# nmcli connection up ens160 
连接已成功激活(D-Bus 活动路径:/org/freedesktop/NetworkManager/ActiveConnection/2)
[root@node1 ~]# yum install bind -y

2、 服务端配置编辑主配置文件

[root@node1 ~]# vim /etc/named.conf
修改如下内容:
options {
 11       listen-on port 53 { any; }; #any 允许所有主机
          listen-on-v6 port 53 { ::1; };
          directory       "/var/named";
          dump-file       "/var/named/data/cache_dump.db";
          statistics-file "/var/named/data/named_stats.txt";
          memstatistics-file "/var/named/data/named_mem_stats.txt";
          secroots-file   "/var/named/data/named.secroots";
          recursing-file  "/var/named/data/named.recursing";
  19      allow-query     { any; }; #修改{}内的内容为any 

 3、编辑区域配置文件,可以清空完,复制一个模板局部修改

[root@node1 ~]# vim /etc/named.rfc1912.zones 
修改如下配置:

zone "openlab.com" IN {
        type master;
        file "openlab.com.zone";
        allow-update { none; }
  

4、编辑数据配置文件,使用copy命令将正向文件解析,复制一份,然后局部修改

[root@node1 named]# cp -a named.localhost  openlab.com.zone
[root@node1 named]# vim openlab.com.zone
修改如下配置:

$TTL 1D
@       IN SOA  @ rname.invalid. (
                                        0       ; serial
                                        1D      ; refresh
                                        1H      ; retry
                                        1W      ; expire
                                        3H )    ; minimum
                IN      NS      openlab.comm
        ns      IN      A       192.168.16.130
        www     IN      A       192.168.16.130
        ftp     IN      A       192.168.16.130
        bbs     IN      A       192.168.16.130

5、关闭防火墙,重启服务

[root@node1 named]# systemctl stop firewalld
[root@node1 named]# systemctl restart named

6、测试。在客户端机上操作

[root@node1 ~]# host -a www.openlab.com
Trying "www.openlab.com"
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 58597
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;www.openlab.com.		IN	ANY

;; ANSWER SECTION:
www.openlab.com.	3600	IN	CNAME	openlab.com.

Received 47 bytes from 114.114.114.114#53 in 636 ms

二、反向解析

1、服务端,客户端操作 

服务端:
[root@node1 ~]# setenforce 0  #关闭SELinux
setenforce: SELinux is disabled 
[root@node1 ~]# systemctl stop firewalld   #关闭防火墙
[root@node1 ~]# nmcli connection modify ens160 ipv4.address '192.168.16.130/24' ipv4.gateway '192.168.16.2' ipv4.dns '114.114.114.114'
[root@node1 ~]# nmcli connection reload #关闭
[root@node1 ~]# nmcli connection up ens160 #打开网卡
连接已成功激活(D-Bus 活动路径:/org/freedesktop/NetworkManager/ActiveConnection/2)
[root@node1 ~]# yum install bind -y


客户端:
[root@node1 ~]# setenforce 0
setenforce: SELinux is disabled
[root@node1 ~]# systemctl stop firewalld
[root@node1 ~]# nmcli connection modify ens160 ipv4.addresses '192.168.16.135/24' ipv4.gateway '192.168.16.2' ipv4.dns '114.114.114.114'
[root@node1 ~]# nmcli connection reload 
[root@node1 ~]# nmcli connection up ens160 
连接已成功激活(D-Bus 活动路径:/org/freedesktop/NetworkManager/ActiveConnection/2)
[root@node1 ~]# yum install bind -y

2、编辑区域配置文件,可以清空完,复制一个模板局部修改

zone "16.168.192.in-addr.arpa" IN {
        type master;
        file "192.168.16.arpa";
        allow-update { none; };
};
 

 3、编辑数据配置文件,使用copy命令将反向文件解析,复制一份,然后局部修改

$TTL 1D
@       IN SOA  ns.openlab.com. admin.qq.com. (
                                        0       ; serial
                                        1D      ; refresh
                                        1H      ; retry
                                        1W      ; expire
                                        3H )    ; minimum
        NS      ns.openlab.com.
130     IN      PTR     ns.openlab.com.
130     IN      PTR     mail.openlab.com.
130     IN      PTR     bbs.openlab.com.
130     IN      PTR     www.openlab.com.
~

4、重启服务

[root@node1 named]# systemctl restart named

5、客户端测试

[root@node1 ~]# nslookup 192.168.16.130
130.38.168.192.in-addr.arpa	name = www.openlab.com.
130.38.168.192.in-addr.arpa	name = mail.openlab.com.
130.38.168.192.in-addr.arpa	name = ns.openlab.com.
130.38.168.192.in-addr.arpa	name = bbs.openlab.com.
 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值