一、准备工作
[ root@server ~ ] # setenforce 0
[ root@server ~ ] # systemctl stop firewalld #关闭防火墙
[ root@server ~ ] # yum install bind -y #下载bind
二、正向解析
1. 配置服务端和客户端静态ip
#服务端
[ root@server ~ ] # nmcli c modify ens32 ipv4.method manual ipv4.addresses 192.168.132.129/24 ipv4.gateway 192,168.132.2 ipv4.dns 114.114.114.114
[ root@server ~ ] # nmcli c reload
[ root@server ~ ] # nmcli c up ens32
#客户端 #记得修改ip
[root@node1 ~] # nmcli c modify ens32 ipv4.method manual ipv4.addresses 192.168.132.130/24 ipv4.gateway 192.168.132.2 ipv4.dns 114.114.114.114
[root@node1 ~] # nmcli c reload
[root@node1 ~] # nmcli c up ens32
2. 在服务器端修改listen-on port 53 和allow-query的{ }中为any;
[root@server ~] # vim /etc/named.conf
# 需改2行
listen-on port 53 { any; }; # any为允许所有主机... #此处不做修改
allow-query { any; };
3. 服务端操作,编辑区域配置文件
[root@server ~] # vim /etc/named.rfc1912.zones
zone "openlab.com" IN {
type master;
file "openlab.com.zone"; # 注意:不写路径
allow-update { none; };
};
4. 拷贝模版文件
[root@server ~] # cd /var/named
[root@server named] # cp -a named.localhost openlab.com.zone # -a 完整拷贝
[root@server named] # vim openlab.com.zone # 完整格式修改如下
$TTL 1D
openlab.com. IN SOA ns.opeblab.com. admin.openlab.com. (
0 ; serial
1D ; refresh
1H ; retry
1W ; expire
3H ) ; minimum
openlab.com. IN NS ns.openlab.com.
ns.openlab.com. IN A 192.168.132.129
www.openlab.com. IN A 192.168.132.129
ftp.openlab.com. IN A 192.168.132.129
bbs.openlab.com. IN A 192.168.132.129
www1.openlab.com. IN CNAME www.openlab.com.
5. 服务端重启服务
[root@server named] # systemctl restart named
6. 客户端测试,编辑客户端网卡配置文件,修改dns为服务端
# 编辑客户端网卡配置文件
[root@node1 ~] # vim /etc/sysconfig/network-scripts/ifcfg-ens32
dns=192.168.132.130; # dns改为服务端的IP地址# 重启
[root@node1 ~]# nmcli c reload
[root@node1 ~]# nmcli c up ens32#客户端测试
[root@node1 ~]# nslookup www.openlab.com
Server: 192.168.132.130
Address: 192.168.132.130#53Name: www.openlab.com
Address: 192.168.132.130
三 、反向解析
1. 同上检查安全软件,下载bind,配置两边静态ip
2. 服务端操作,编辑区域配置文件,添加反向解析记录
[root@server named]# vim /etc/named.rfc1912.zones
zone "132.168.192.in-addr.arpa" IN {
type master;
file "192.168.132.arpa";
allow-update { none; };
};
3. 服务端操作,编辑数据配置文件,复制反向解析模版
[root@server ~] # cd /var/named
[root@server named] # cp -a named.loopback 192.168.132.arpa
[root@server named] # vim 192.168.132.arpa$TTL 1D
@ IN SOA ns.openlab.com. jenny.qq.com. (
0 ; serial
1D ; refresh
1H ; retry
1W ; expire
3H ) ; minimum
IN NS ns.openlab.com.
ns.openlab.com. IN A 192.168.132.129
130 IN PTR ns.openlab.com.
130 IN PTR www.openlab.com.
130 IN PTR ftp.openlab.com.
4. 重启服务
[root@server named]# systemctl restart named
5. 客户端测试
[root@node1 ~]# nslookup 192.168.132.129
129.132.168.192.in-addr.arpa name = www.openlab.com.
129.132.168.192.in-addr.arpa name = ftp.openlab.com.
129.132.168.192.in-addr.arpa name = ns.openlab.com.