Portál AbcLinuxu, 15. prosince 2025 03:04
.. grrrr
local:
1-192.168.1/24
2-172.32.1/24
na rozsahu 1 bezi bind9(dns-server) a resolvuje v pohode, ale jen pro subnet 1 .... ze subnetu 2 funguje dig a ping na dns-server, ale tento neprelozi "internetovy dotaz" - vsechny acl sem zrusil kvuli testum, stejne bezvysledne ... ostudou (pro me) je, ze na subnetu 1 bezi starej wokenni dns-server, pri prepnuti na nej vse v pohode
predem diky za kopance, neco ze syslogu, jinak vic muzu dodat po nastaveni logovani (na to uz ted ale nemam)
Feb 9 16:30:03 samba1 named[4014]: client 172.32.1.15#47676: query (cache) 'google.com/A/IN' denied Feb 9 16:30:08 samba1 named[4014]: client 172.32.1.15#58638: query (cache) 'google.com/A/IN' denied
root@samba1:/etc/bind# cat named.conf
// This is the primary configuration file for the BIND DNS server named.
//
// Please read /usr/share/doc/bind9/README.Debian.gz for information on the
// structure of BIND configuration files in Debian, *BEFORE* you customize
// this configuration file.
//
// If you are just adding zones, please do that in /etc/bind/named.conf.local
include "/etc/bind/named.conf.options";
// prime the server with knowledge of the root servers
zone "." {
type hint;
file "/etc/bind/db.root";
};
// be authoritative for the localhost forward and reverse zones, and for
// broadcast zones as per RFC 1912
zone "localhost" {
type master;
file "/etc/bind/db.local";
};
zone "127.in-addr.arpa" {
type master;
file "/etc/bind/db.127";
};
zone "0.in-addr.arpa" {
type master;
file "/etc/bind/db.0";
};
zone "255.in-addr.arpa" {
type master;
file "/etc/bind/db.255";
};
//because of dnssec
key "TRANSFER" {
algorithm hmac-md5;
secret "XXXXXXXXXXXXXXXXXXx";
};
server 192.168.1.242 {
keys {
TRANSFERS;
};
};
include "/etc/bind/named.conf.local";
################################################################
root@samba1:/etc/bind# cat named.conf.options
options {
directory "/var/cache/bind";
// If there is a firewall between you and nameservers you want
// to talk to, you might need to uncomment the query-source
// directive below. Previous versions of BIND always asked
// questions using port 53, but BIND 8.1 and later use an unprivileged
// port by default.
// query-source address * port 53;
// If your ISP provided one or more IP addresses for stable
// nameservers, you probably want to use them as forwarders.
// Uncomment the following block, and insert the addresses replacing
// the all-0's placeholder.
forwarders {
62.128.242.20;
62.128.242.18;
};
auth-nxdomain no; # conform to RFC1035
listen-on-v6 { any; };
dnssec-enable yes;
};
//acl mynet {
// 192.168.1.0/24;
// 127.0.0.1;
//};
#############################################################################
root@samba1:/etc/bind# cat named.conf.local
//
// Do any local configuration here
//
// Consider adding the 1918 zones here, if they are not used in your
// organization
//include "/etc/bind/zones.rfc1918";
zone "hk.no" {
type master;
file "/etc/bind/db.hk.no";
allow-query {
mynet;
};
allow-transfer {
key TRANSFER;
};
allow-update {
mynet;
};
};
zone "hattfjelldal-kommune.no" {
type master;
file "/etc/bind/db.hattfjelldal-kommune.no";
allow-query {
mynet;
};
allow-transfer {
key TRANSFER;
};
// allow-update {
// mynet;
// };
};
zone "1.168.192.in-addr.arpa" {
type master;
file "/etc/bind/db.192.168.1.rev";
allow-query {
mynet;
};
allow-transfer {
key TRANSFER;
};
allow-update {
mynet;
};
};
zone "1.32.172.in-addr.arpa" {
type master;
file "/etc/bind/db.172.32.1.rev";
allow-query {
mynet;
};
allow-transfer {
key TRANSFER;
};
};
acl mynet {
192.168.1.0/24;
172.32.1.0/24;
127.0.0.1;
};
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.