Zrobiłem mały test a mianowicie mam teraz domenę cyfrowyzasieg.eu
postawiłem dwa serwery DNS na debianie jeezy, master i slave
oba na publicznych numerach IP 91.231.20.206 i 91.231.20.207
deleguje domenę z home.pl na ns1.cyfrowyzasieg.eu oraz ns2.cyfrowyzasieg.eu podając dodatkowo numery ip ponieważ te dns-y nie mają żadnej domeny i będą przypisanej do domeny cyfrowyzasieg.eu.
konfig dla ns1.cyfrowyzasieg.eu
options {
directory "/var/cache/bind";
// forwarders {
// 0.0.0.0;
// };
dnssec-validation auto;
auth-nxdomain no; # conform to RFC1035
listen-on-v6 { none; };
allow-query {any;};
allow-transfer { 91.231.20.207;};
allow-recursion { any; };
allow-recursion-on { any; };
};
zone "cyfrowyzasieg.eu" {
type master;
allow-transfer {91.231.20.207;};
file "/etc/bind/pri.cyfrowyzasieg.eu";
};
$TTL 3600
@ IN SOA ns1.cyfrowyzasieg.eu. dawid.potel.pl. (
2016072311 ; serial, todays date + todays serial #
3600 ; refresh, seconds
600 ; retry, seconds
1209600 ; expire, seconds
86400 ) ; minimum, seconds
;
@ 86400 TXT "v=spf1 a mx ~all"
@ 3600 MX 10 mail.cyfrowyzasieg.eu.
@ 3600 A 91.231.20.206
@ 3600 NS ns1.cyfrowyzasieg.eu.
@ 3600 NS ns2.cyfrowyzasieg.eu.
ns1 86400 A 91.231.20.206
ns2 86400 A 91.231.20.207
mail 3600 A 91.231.20.206
www 3600 A 91.231.20.206
Log restartu bind na ns1
Jul 23 18:00:02 hosting named[28566]: starting BIND 9.9.5-9+deb8u6-Debian -4 -f -u bind
Jul 23 18:00:02 hosting named[28566]: built with '--prefix=/usr' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--sysconfdir=/etc/bind' '--localstate
Jul 23 18:00:02 hosting named[28566]: ----------------------------------------------------
Jul 23 18:00:02 hosting named[28566]: BIND 9 is maintained by Internet Systems Consortium,
Jul 23 18:00:02 hosting named[28566]: Inc. (ISC), a non-profit 501(c)(3) public-benefit
Jul 23 18:00:02 hosting named[28566]: corporation. Support and training for BIND 9 are
Jul 23 18:00:02 hosting named[28566]: available at https://www.isc.org/support
Jul 23 18:00:02 hosting named[28566]: ----------------------------------------------------
Jul 23 18:00:02 hosting named[28566]: adjusted limit on open files from 4096 to 1048576
Jul 23 18:00:02 hosting named[28566]: found 1 CPU, using 1 worker thread
Jul 23 18:00:02 hosting named[28566]: using 1 UDP listener per interface
Jul 23 18:00:02 hosting named[28566]: using up to 4096 sockets
Jul 23 18:00:02 hosting named[28566]: loading configuration from '/etc/bind/named.conf'
Jul 23 18:00:02 hosting named[28566]: reading built-in trusted keys from file '/etc/bind/bind.keys'
Jul 23 18:00:02 hosting named[28566]: using default UDP/IPv4 port range: [1024, 65535]
Jul 23 18:00:02 hosting named[28566]: using default UDP/IPv6 port range: [1024, 65535]
Jul 23 18:00:02 hosting named[28566]: no IPv6 interfaces found
Jul 23 18:00:02 hosting named[28566]: listening on IPv4 interface lo, 127.0.0.1#53
Jul 23 18:00:02 hosting named[28566]: listening on IPv4 interface eth0, 91.231.20.206#53
Jul 23 18:00:02 hosting named[28566]: generating session key for dynamic DNS
Jul 23 18:00:02 hosting named[28566]: sizing zone task pool based on 8 zones
Jul 23 18:00:02 hosting named[28566]: using built-in root key for view _default
Jul 23 18:00:02 hosting named[28566]: set up managed keys zone for view _default, file 'managed-keys.bind'
Jul 23 18:00:02 hosting named[28566]: automatic empty zone: 10.IN-ADDR.ARPA
Jul 23 18:00:03 hosting named[28566]: automatic empty zone: 113.0.203.IN-ADDR.ARPA
Jul 23 18:00:03 hosting named[28566]: automatic empty zone: 255.255.255.255.IN-ADDR.ARPA
Jul 23 18:00:03 hosting named[28566]: automatic empty zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA
Jul 23 18:00:03 hosting named[28566]: automatic empty zone: 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA
Jul 23 18:00:03 hosting named[28566]: automatic empty zone: D.F.IP6.ARPA
Jul 23 18:00:03 hosting named[28566]: automatic empty zone: 8.E.F.IP6.ARPA
Jul 23 18:00:03 hosting named[28566]: automatic empty zone: 9.E.F.IP6.ARPA
Jul 23 18:00:03 hosting named[28566]: automatic empty zone: A.E.F.IP6.ARPA
Jul 23 18:00:03 hosting named[28566]: automatic empty zone: B.E.F.IP6.ARPA
Jul 23 18:00:03 hosting named[28566]: automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA
Jul 23 18:00:03 hosting named[28566]: command channel listening on 127.0.0.1#953
Jul 23 18:00:03 hosting named[28566]: managed-keys-zone: loaded serial 7
Jul 23 18:00:03 hosting named[28566]: zone 0.in-addr.arpa/IN: loaded serial 1
Jul 23 18:00:03 hosting named[28566]: zone 127.in-addr.arpa/IN: loaded serial 1
Jul 23 18:00:03 hosting named[28566]: zone cyfrowyzasieg.eu/IN: 'cyfrowyzasieg.eu' found SPF/TXT record but no SPF/SPF record found, add matching type SPF re
Jul 23 18:00:03 hosting named[28566]: zone cyfrowyzasieg.eu/IN: loaded serial 2016072311
Jul 23 18:00:03 hosting named[28566]: zone 255.in-addr.arpa/IN: loaded serial 1
Jul 23 18:00:03 hosting named[28566]: zone localhost/IN: loaded serial 2
Jul 23 18:00:03 hosting named[28566]: zone potel.com.pl/IN: loaded serial 2016072003
Jul 23 18:00:03 hosting named[28566]: zone cyfrowyzasieg.pl/IN: loaded serial 2016072002
Jul 23 18:00:03 hosting named[28566]: all zones loaded
Jul 23 18:00:03 hosting named[28566]: running
Jul 23 18:00:03 hosting named[28566]: zone cyfrowyzasieg.eu/IN: sending notifies (serial 2016072311)
Jul 23 18:00:03 hosting named[28566]: zone potel.com.pl/IN: sending notifies (serial 2016072003)
Jul 23 18:00:03 hosting named[28566]: zone cyfrowyzasieg.pl/IN: sending notifies (serial 2016072002)
Jul 23 18:00:03 hosting named[28566]: client 91.231.20.207#37744 (cyfrowyzasieg.eu): transfer of 'cyfrowyzasieg.eu/IN': AXFR-style IXFR started
Jul 23 18:00:03 hosting named[28566]: client 91.231.20.207#37744 (cyfrowyzasieg.eu): transfer of 'cyfrowyzasieg.eu/IN': AXFR-style IXFR ended
konfig dla ns2.cyfrowyzasieg.eu
options {
directory "/var/cache/bind";
// forwarders {
// 0.0.0.0;
// };
dnssec-validation auto;
auth-nxdomain no; # conform to RFC1035
listen-on-v6 { none; };
allow-query {any;};
};
zone "cyfrowyzasieg.eu" {
type slave;
masters {91.231.20.206;};
allow-transfer {91.231.20.206;};
file "/etc/bind/slave/sec.cyfrowyzasieg.eu";
};
po restarcie cała strefa zostaje skopiowana z mastera ponieważ tworzy mi się plik sec.cyfrowyzasieg.eu w katalogu slave
logi restartu bind na ns2
Jul 23 18:07:05 ns2 named[17616]: starting BIND 9.9.5-9+deb8u6-Debian -4 -f -u bindJul 23 18:07:05 ns2 named[17616]: built with '--prefix=/usr' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--sysconfdir=/etc/bind' '--localstatedir=
Jul 23 18:07:05 ns2 named[17616]: ----------------------------------------------------
Jul 23 18:07:05 ns2 named[17616]: BIND 9 is maintained by Internet Systems Consortium,
Jul 23 18:07:05 ns2 named[17616]: Inc. (ISC), a non-profit 501(c)(3) public-benefit
Jul 23 18:07:05 ns2 named[17616]: corporation. Support and training for BIND 9 are
Jul 23 18:07:05 ns2 named[17616]: available at https://www.isc.org/support
Jul 23 18:07:05 ns2 named[17616]: ----------------------------------------------------
Jul 23 18:07:05 ns2 named[17616]: adjusted limit on open files from 4096 to 1048576
Jul 23 18:07:05 ns2 named[17616]: found 1 CPU, using 1 worker thread
Jul 23 18:07:05 ns2 named[17616]: using 1 UDP listener per interface
Jul 23 18:07:05 ns2 named[17616]: using up to 4096 sockets
Jul 23 18:07:05 ns2 named[17616]: loading configuration from '/etc/bind/named.conf'
Jul 23 18:07:05 ns2 named[17616]: reading built-in trusted keys from file '/etc/bind/bind.keys'
Jul 23 18:07:05 ns2 named[17616]: using default UDP/IPv4 port range: [1024, 65535]
Jul 23 18:07:05 ns2 named[17616]: using default UDP/IPv6 port range: [1024, 65535]
Jul 23 18:07:05 ns2 named[17616]: no IPv6 interfaces found
Jul 23 18:07:05 ns2 named[17616]: listening on IPv4 interface lo, 127.0.0.1#53
Jul 23 18:07:05 ns2 named[17616]: listening on IPv4 interface eth0, 91.231.20.207#53
Jul 23 18:07:05 ns2 named[17616]: generating session key for dynamic DNS
Jul 23 18:07:05 ns2 named[17616]: sizing zone task pool based on 6 zones
Jul 23 18:07:05 ns2 named[17616]: using built-in root key for view _default
Jul 23 18:07:05 ns2 named[17616]: set up managed keys zone for view _default, file 'managed-keys.bind'
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: 10.IN-ADDR.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: 16.172.IN-ADDR.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: 100.51.198.IN-ADDR.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: 113.0.203.IN-ADDR.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: 255.255.255.255.IN-ADDR.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: D.F.IP6.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: 8.E.F.IP6.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: 9.E.F.IP6.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: A.E.F.IP6.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: B.E.F.IP6.ARPA
Jul 23 18:07:05 ns2 named[17616]: automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA
Jul 23 18:07:05 ns2 named[17616]: command channel listening on 127.0.0.1#953
Jul 23 18:07:05 ns2 named[17616]: managed-keys-zone: loaded serial 2
Jul 23 18:07:05 ns2 named[17616]: zone 0.in-addr.arpa/IN: loaded serial 1
Jul 23 18:07:05 ns2 named[17616]: zone 127.in-addr.arpa/IN: loaded serial 1
Jul 23 18:07:05 ns2 named[17616]: zone cyfrowyzasieg.eu/IN: loaded serial 2016072311
Jul 23 18:07:05 ns2 named[17616]: zone localhost/IN: loaded serial 2
Jul 23 18:07:05 ns2 named[17616]: zone 255.in-addr.arpa/IN: loaded serial 1
Jul 23 18:07:05 ns2 named[17616]: all zones loaded
Jul 23 18:07:05 ns2 named[17616]: running
Jul 23 18:07:05 ns2 named[17616]: zone cyfrowyzasieg.eu/IN: sending notifies (serial 2016072311)
sprawdzenie pliku zone na ns1
named-checkzone localhost /etc/bind/pri.cyfrowyzasieg.eu
zone localhost/IN: 'localhost' found SPF/TXT record but no SPF/SPF record found, add matching type SPF record
zone localhost/IN: loaded serial 2016072311
OK
do tego na ns1 i ns2
53/tcp open domain
Możecie sprawdzić czy wszystko zrobiłem ok ?