°Ô½Ã¹° 259°Ç
   
[RedHat] Name ¼­¹ö ±¸¼ºÇϱâ
±Û¾´ÀÌ : ÃÖÀå¼· ³¯Â¥ : 2013-09-05 (¸ñ) 11:13 Á¶È¸ : 5467


¼ø¼­´Â ´ÙÀ½À» µû¸¥´Ù

1. ±âÁ¸ ¼³Ä¡µÈ ÆÐÅ°Áö È®ÀÎ -> 2. ¾÷µ¥ÀÌÆ® ¹× ÆÐÅ°Áö ¼³Ä¡ -> 3. DNS¼­¹ö ¼³Á¤ -> 4. ZoneÆÄÀÏ »ý¼º ¹× ¸µÅ© -> 5. ¼­ºñ½º ½ÃÀÛ ¹× È®ÀÎ

1. ±âÁ¸ ¼³Ä¡µÈ ÆÐÅ°Áö È®ÀÎ

[root@localhost ~]# rpm -qa | grep bind  //¼³Ä¡µÈ ¹ÙÀεå È®ÀÎ
bind-9.3.4-10.P1.el5
bind-devel-9.3.4-10.P1.el5
bind-utils-9.3.4-10.P1.el5
bind-chroot-9.3.4-10.P1.el5
bind-libs-9.3.4-10.P1.el5
ypbind-1.19-11.el5
[root@localhost ~]# rpm -qa | grep name  //¼³Ä¡µÈ ³×ÀÓ¼­¹ö È®ÀÎ
caching-nameserver-9.3.4-10.P1.el5

2. ¾÷µ¥ÀÌÆ® ¹× ÆÐÅ°Áö ¼³Ä¡

¸¸¾à À§¿Í °°Àº ¼­ºñ½º°¡ ¾ø´Ù¸é ¼³Ä¡¸¦ ÇØÁØ´Ù.

# yum -y install bind*
# yum -y install caching-nameserver*

3. DNS¼­¹ö ¼³Á¤

¿ì¼±ÀûÀ» IP¼¼ÆÃÀÌ Àß µÇ¾îÀÖ´ÂÁö È®ÀÎÀ» ÇØ¾ß ÇÑ´Ù.
# ifconfig ¸¦ È®ÀÎÇÏ¿© ÀÚ½ÅÀÌ ¿øÇÏ´Â ip¿¡ DNS¼­ºñ½º¸¦ µ¹¸± Áغñ°¡ µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÏ¸ç ¼öÁ¤ÇÏ¿© ÁØ´Ù. IP¼¼ÆÃÀº ¿©±â¸¦ Âü°í Çϵµ·Ï ÇÑ´Ù.
# vi /etc/resolv.conf  //DNS¸¦ ¼öÁ¤ÇÏ¿© ÁØ´Ù.

; generated by /sbin/dhclient-script
search test.net
nameserver 192.168.0.34

# vi /etc/sysconfig/network  //³×Æ®¿÷À» ´ÙÀ½°ú °°ÀÌ ¼³Á¤ÇØ ÁØ´Ù.

NETWORKING=yes
NETWORKING_IPV6=no
HOSTNAME=ns.jiho.net

# vim /etc/named.caching-nameserver.conf //³×ÀÓ¼­¹öÀÇ ±ÇÇÑÀ» ¾Æ·¡¿Í °°ÀÌ ¼öÁ¤ ÇØÁØ´Ù.
        listen-on port 53 { any ; };
           query-source    port 53;
        allow-query     { any ; };
        match-clients      { any ; };
        match-destinations { any ; };

¼³¸íÀ» ´õÇÏÀÚ¸é Æ÷Æ® °³¹æ°ú Äõ¸®ÀÇ Çã¿ë¿¡ ´ëÇÑ ³»¿ëÀÌ´Ù. ÆÄÀÏÀ» ¿­¾îº¸¸é localhost µî Á¦ÇÑÀûÀÎ ¼­ºñ½º¸¦ ÇÏ°Ô µÇ¾î Àִµ¥ ¿©±â¼­ any·Î ¼³Á¤ÇÏ°Ô µÇ¸é ¸ðµç ÁúÀÇ¿¡ ´ëÇØ ÀÀ´äÀ» ÇÏ°Ô µÇ´Â °ÍÀÌ´Ù.

# vim /etc/named.rfc1912.zones //³×ÀÓµ¥¸ó Á¸ÆÄÀÏ ¼öÁ¤

¿©±â¿¡¼­ ¾Æ·¡¿¡ ¸¸µé Á¸ ÆÄÀÏÀ» ¾ð±ÞÇÏ°í ¸µÅ©ÇÏ°Ô µÈ´Ù. ¼ö½Ä¿¡ ¸ÂÃç Àß ÀÛ¼ºÇÏÀÚ. Âü°í·Î ³»¿ëÀ» ¾Æ·¡¿¡ Ãß°¡¸¸ ÇÏ¸é µÈ´Ù.

¼ø¹æÇâ
zone    "test.net" IN {                               // ¿¬°áÇÒ ¼­¹ö ȤÀº DNS ÀÇ ÁÖ¼Ò¸¦ Àû´Â´Ù.
        type master;
        file "test.net.zone";                        // zone ÆÄÀÏ ÁöÁ¤.
        allow-update { none; };             
};

¿ª¹æÇâ
zone    "0.168.192.in-addr.arpa" IN {       //  ¿ª¹æÇâÀº ip.in-addr.arpa Çü½ÄÀ¸·Î ¸¸µç´Ù.
        type master;
        file "0.168.192.zone";                     // zone ÆÄÀÏ ÁöÁ¤
        allow-update { none; };
};

4. ZoneÆÄÀÏ »ý¼º ¹× ¸µÅ©

# cd /var/named/chroot/var/named //À̵¿ÇÑ´Ù.

[root@localhost named]# ls -al
ÇÕ°è 52
drwxr-x--- 4 root  named 4096  6¿ù 18 09:31 .
drwxr-x--- 6 root  named 4096  6¿ù 18 09:08 ..
drwxrwx--- 2 named named 4096  6¿ù 18 09:27 data
-rw-r----- 1 root  named  198 10¿ù 13  2012 localdomain.zone
-rw-r----- 1 root  named  195 10¿ù 13  2012 localhost.zone
-rw-r----- 1 root  named  427 10¿ù 13  2012 named.broadcast
-rw-r----- 1 root  named 1892 10¿ù 13  2012 named.ca
-rw-r----- 1 root  named  424 10¿ù 13  2012 named.ip6.local
-rw-r----- 1 root  named  426 10¿ù 13  2012 named.local
-rw-r----- 1 root  named  427 10¿ù 13  2012 named.zero
drwxrwx--- 2 named named 4096  7¿ù 27  2004 slaves

ÆÄÀÏÀ» º¸¸é localhost.zone ÆÄÀÏÀÌ Àִµ¥ Áö±Ý ÀÌ°Ô ¾ø´Ù¸é caching-nameserver °¡ ¾ø°Å³ª À߸ø ¼³Ä¡µÈ °ÍÀÌ´Ï ¼³Ä¡¸¦ ÇØ¾ß ÇÑ´Ù.


cp¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© zoneÆÄÀÏÀ» ¸¸µé¾î ÁØ´Ù.

#cp localhost.zone test.net.zone     // test.net ÀÇ zone ÆÄÀÏÀ» ¸¸µç´Ù.
#cp localhost.zone 0.168.192.zone   // teet.net ÀÇ ¿ª¹æÇâ zone ÆÄÀÏÀ» ¸¸µç´Ù.

0.168.192.zone ¼­¹öÀÇ ¸Ç ¸¶Áö¸· ³¡ÀÚ¸®¸¦ »« 3ÀÚ¸®¿¡ zoneÀ» ºÙ¿©¼­ ¸¸µé¾î ³½´Ù.

[test.net.zone]
$TTL    86400
@               IN SOA  @       root (
                                        42              ; serial (d. adams)
                                        3H              ; refresh
                                        15M             ; retry
                                        1W              ; expiry
                                        1D )            ; minimum

                IN NS           ns.test.net.
                IN A            127.0.0.1
                IN AAAA         ::1
ns              IN A            192.168.0.34
www             IN A            192.168.0.34
ftp             IN A            192.168.0.34

[0.168.192.zone]
$TTL    86400
@               IN SOA  @       root (
                                        42              ; serial (d. adams)
                                        3H              ; refresh
                                        15M             ; retry
                                        1W              ; expiry
                                        1D )            ; minimum

                IN NS           @
                IN A            127.0.0.1
                IN AAAA         ::1
34              IN PTR         
www.test.net.
34              IN PTR         
ftp.test.net.
34              IN PTR          ns.test.net.

ÀÌÁ¦ ÆÄÀÏ Æ۹̼ÇÀ» ÁÖµµ·Ï ÇÑ´Ù. ÆÄÀÏ Æ۹̼ÇÀ» ÁÖ´Â ÀÌÀ¯´Â chrootÀÇ Á¦ÇÑ ¶§¹®ÀÌ´Ù.
±âÁ¸¿¡´Â chroot »óÀ§¿¡ Á¸ ÆÄÀÏÀ» ¿Ã·È´ÂÁö Áö±ÝÀº ¸µÅ©·Î ´ëü ÇÏ°í ÀÖ´Ù.

# chown named:named /var/named/chroot/var/named/jiho.net.zone
# chown named:named /var/named/chroot/var/named/1.16.172.zone

* ·çÆ® ±ÇÇÑÀ» Á൵ µÇ´Âµ¥...±ÇÀåµÇÁö´Â ¾Ê´Â´Ù.
ex
# chown root:named /var

´ÙÀ½Àº /var/named Æú´õ¿¡ ¸µÅ©ÆÄÀÏÀ» ³ÖÀ» Â÷·ÊÀÌ´Ù. ÇØ´ç Æú´õ·Î À̵¿ÇÏ¿©

# ln -s /var/named/chroot/var/named/jiho.net.zone jiho.net.zone
# ln -s /var/named/chroot/var/named/1.16.172.zone 1.16.172.zone

ÀÌ·¸°Ô ÇÏ¸é ¸µÅ©ÆÄÀÏÀÌ »ý¼ºµÈ´Ù. ÀÌÁ¦´Â ½ÇÇàÇÒ Àϸ¸ ³²¾Ò´Ù.

# service named start ¸¦ ÇÏ¸é ¼­ºñ½º°¡ ½ÇÇàÀÌ µÉ °ÍÀÌ´Ù. ¸¸¾à ¿À·ù°¡ ³­´Ù¸é ÇØ´çÇÏ´Â ÆÄÀÏ·Î °¡¼­ ¼öÁ¤À» ÇÏ¸é µÇ°Ù´Ù.

¶ÇÇÑ Á¸ ÆÄÀÏÀ̳ª ±âŸ ÆÄÀÏÀ» ¼öÁ¤ÇÑ´Ù¸é Àç½ÃÀÛ ÇØÁÖ¾î¾ß ÇÑ´Ù.
# service named restart ¸¦ ÀÌ¿ëÇϵµ·Ï ÇÑ´Ù.

¼­ºñ½º ½ÃÀ۽à ÀÚµ¿½ÇÇà
# chkconfig --list | grep named

named           0:off   1:off   2:on    3:on    4:on    5:on    6:off //ÀÌ »óÅ°¡ µÇ¾î¾ß ÇÑ´Ù.

¼³Á¤¹ý

# chkconfig --level 5 named on
# chkconfig named on

grep Çغ¸¸é À§¿Í °°ÀÌ º¯°æ µÈ °ÍÀ» È®ÀÎ ÇÒ ¼ö ÀÖ´Ù.


2Â÷ ³×ÀÓ ¼­¹ö ±¸¼º ÇÏ´Â ¹æ¹ý

= 1Â÷ ³×ÀÓ ¼­¹öÀÇ ¼³Á¤ =

1. ¡²  rndc.key ¸¦  ÀÌ¿ëÇÑ µ¿±âÈ­ ¹æ¹ý ¡³
 
-  1Â÷ ³×ÀÓ¼­¹öÀÇ /etc/rndc.key °ªÀ»  2Â÷ ³×ÀÓ¼­¹öÀÇ /etc/rndc.key°ªÀ» µ¿ÀÏÇÏ°Ô ¼öÁ¤ÇÑ´Ù.
    [root@backup named¡³# more /etc/rndc.key
 
  key "rndckey" {
      algorithm       hmac-md5;
       secret    "3MueARgOApRyrgACga6jqWZPzFIp83uyns97bMAdz0ylJ8LHQZ8NO";
    };
 
2. ¡² 1Â÷ ³×ÀÓ¼­¹öÀÇ named.conf ¼³Á¤ ¡³
 
- named.confÆÄÀÏ¿¡ "allow-transfer" Ç׸ñ¸¦ Ãß°¡ µî·ÏÇÑ´Ù.................
 
  options {
        directory "/var/named";
        dump-file "/var/named/data/cache_dump.db";
        statistics-file "/var/named/data/named_stats.txt";
         //query-source address * port 53;
         allow-transfer { 192.168.1.2; };   // 2Â÷ DNS IP..
 };
 
3. ¡² /etc/rndc.key  µî·Ï ¡³
 
- ±âº»À¸·Î include "/etc/rndc.key";  ·Î µî·ÏµÇ¾î ÀÖÀ½. ( zone ¼³Á¤ Ç׸ñº¸´Ù »óÀ§¿¡ ¶óÀο¡ µî·Ï)
 
- ¶Ç´Â  rndc.key °ªÀ» Á÷Á¢ µî·ÏÇÑ´Ù.
 
     key "rndckey" {
           algorithm       hmac-md5;
           secret "3MueARgOApRyrgACgalqOZPzFIp83uyns97bMAdz0ylJ8LHQZ8NO";
     };
 
 - µÑÀå Çϳª¸¸ ¼³Á¤ÇÏ¸é µË´Ï´Ù.
 

4. ¡² ZONE ÆÄÀÏ ¼³Á¤¡³
 
- zone ¼³Á¤ ½Ã   allow-update, allow-transfer Ç׸ñ Ãß°¡
    zone "bansong.hs.kr" IN {
             type master;
             file "named.bansong";
             allow-update { key  rndckey; };    
             allow-transfer { key  rndckey; }; 
    };
          ¶Ç´Â rndc.key°ªÀÌ ¾Æ´Ñ IP¸¦ Á÷Á¢µî·ÏÇϴ  ¾Æ·¡ ¹æ½Äµµ ÀÖ´Ù
           allow-update { localhost;  192.168.1.2;  };  
           allow-update { localhost;  192.168.1.2;  };  

= 2Â÷ ³×ÀÓ ¼­¹öÀÇ ¼³Á¤ =
 
5. ¡² named.conf  ¼³Á¤¡³
 
-  named.conf ÆÄÀÏ¿¡ server Ç׸ñ¸¦  µî·ÏÇÑ´Ù.
 
     server 192.168.1.1{                      // 1Â÷³×ÀÓ¼­¹ö IPµî·Ï
                    keys {rndckey;};
     };
 
 
6. ¡² ZONE ÆÄÀÏ ¼³Á¤¡³
 
- zone ¼³Á¤ ½Ã  type , masters Ç׸ñ Ãß°¡
 
   zone "bansong.hs.kr" IN {
       type slave;
       file "named.slave.bansong";
       masters { 192.168.1.1; };           // 1Â÷³×ÀÓ¼­¹ö IPµî·Ï
   };
 
 
7. ¡² named Àç ½ÇÇà ¹× /var/name/chroot/var/named  ¹é¾÷ÆÄÀÏ È®ÀΡ³
 
-  ¼³Á¤ÀÌ ³¡³ª¸é named µ¥¸ó Àç½ÇÇà ÈÄ /var/log/messages ÆÄÀÏ·Î µ¿ÀÛ ¿©ºÎ¸¦ È®ÀÎÇÑ´Ù.
-  2Â÷ ³×ÀÓ¼­¹öÀÇ /var/named/chroot/var/named¿¡  zone ÆÄÀÏ »ý¼º µÇ´ÂÁö È®ÀÎÇÑ´Ù.
-  ¸¶Áö¸·À¸·Î dig ¹× nslookup ¸í·ÉÀ» ÀÌ¿ëÇÏ¿© µ¿ÀÛ¿©ºÎ¸¦ È®ÀÎÇÑ´Ù.


À̸§ Æнº¿öµå
ºñ¹Ð±Û (üũÇÏ¸é ±Û¾´À̸¸ ³»¿ëÀ» È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.)
¿ÞÂÊÀÇ ±ÛÀÚ¸¦ ÀÔ·ÂÇϼ¼¿ä.
   

miwit.com sir.co.kr DNS Powered by DNSEver.com DNS Powered by DNSEver.com