¼ø¼´Â ´ÙÀ½À» µû¸¥´Ù
1. ±âÁ¸ ¼³Ä¡µÈ ÆÐÅ°Áö È®ÀÎ -> 2. ¾÷µ¥ÀÌÆ® ¹× ÆÐÅ°Áö ¼³Ä¡ -> 3. DNS¼¹ö
¼³Á¤ -> 4. ZoneÆÄÀÏ »ý¼º ¹× ¸µÅ© -> 5. ¼ºñ½º ½ÃÀÛ ¹× È®ÀÎ
1. ±âÁ¸ ¼³Ä¡µÈ ÆÐÅ°Áö È®ÀÎ
[root@localhost ~]# rpm -qa | grep bind //¼³Ä¡µÈ ¹ÙÀεå
È®ÀÎ
bind-9.3.4-10.P1.el5
bind-devel-9.3.4-10.P1.el5
bind-utils-9.3.4-10.P1.el5
bind-chroot-9.3.4-10.P1.el5
bind-libs-9.3.4-10.P1.el5
ypbind-1.19-11.el5
[root@localhost
~]# rpm -qa | grep name //¼³Ä¡µÈ ³×ÀÓ¼¹ö
È®ÀÎ
caching-nameserver-9.3.4-10.P1.el5
2. ¾÷µ¥ÀÌÆ® ¹× ÆÐÅ°Áö ¼³Ä¡
¸¸¾à À§¿Í °°Àº ¼ºñ½º°¡ ¾ø´Ù¸é ¼³Ä¡¸¦ ÇØÁØ´Ù.
# yum -y install bind*
# yum -y install
caching-nameserver*
3. DNS¼¹ö ¼³Á¤
¿ì¼±ÀûÀ» IP¼¼ÆÃÀÌ Àß µÇ¾îÀÖ´ÂÁö È®ÀÎÀ» ÇØ¾ß ÇÑ´Ù.
# ifconfig ¸¦ È®ÀÎÇÏ¿© ÀÚ½ÅÀÌ
¿øÇÏ´Â ip¿¡ DNS¼ºñ½º¸¦ µ¹¸± Áغñ°¡ µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÏ¸ç ¼öÁ¤ÇÏ¿© ÁØ´Ù. IP¼¼ÆÃÀº ¿©±â¸¦ Âü°í Çϵµ·Ï ÇÑ´Ù.
# vi /etc/resolv.conf //DNS¸¦ ¼öÁ¤ÇÏ¿© ÁØ´Ù.
; generated by /sbin/dhclient-script
search
test.net
nameserver 192.168.0.34
# vi /etc/sysconfig/network //³×Æ®¿÷À» ´ÙÀ½°ú °°ÀÌ ¼³Á¤ÇØ
ÁØ´Ù.
NETWORKING=yes
NETWORKING_IPV6=no
HOSTNAME=ns.jiho.net
# vim /etc/named.caching-nameserver.conf //³×ÀÓ¼¹öÀÇ ±ÇÇÑÀ»
¾Æ·¡¿Í °°ÀÌ ¼öÁ¤ ÇØÁØ´Ù.
listen-on port 53 { any ;
};
query-source port
53;
allow-query { any ;
};
match-clients {
any ; };
match-destinations { any ; };
¼³¸íÀ» ´õÇÏÀÚ¸é Æ÷Æ® °³¹æ°ú Äõ¸®ÀÇ Çã¿ë¿¡ ´ëÇÑ ³»¿ëÀÌ´Ù. ÆÄÀÏÀ» ¿¾îº¸¸é localhost µî Á¦ÇÑÀûÀÎ ¼ºñ½º¸¦
ÇÏ°Ô µÇ¾î Àִµ¥ ¿©±â¼ any·Î ¼³Á¤ÇÏ°Ô µÇ¸é ¸ðµç ÁúÀÇ¿¡ ´ëÇØ ÀÀ´äÀ» ÇÏ°Ô µÇ´Â °ÍÀÌ´Ù.
# vim /etc/named.rfc1912.zones //³×ÀÓµ¥¸ó Á¸ÆÄÀÏ
¼öÁ¤
¿©±â¿¡¼ ¾Æ·¡¿¡ ¸¸µé Á¸ ÆÄÀÏÀ» ¾ð±ÞÇÏ°í ¸µÅ©ÇÏ°Ô µÈ´Ù. ¼ö½Ä¿¡ ¸ÂÃç Àß ÀÛ¼ºÇÏÀÚ. Âü°í·Î ³»¿ëÀ»
¾Æ·¡¿¡ Ãß°¡¸¸ ÇÏ¸é µÈ´Ù.
¼ø¹æÇâ
zone "test.net" IN
{ // ¿¬°áÇÒ ¼¹ö ȤÀº DNS ÀÇ ÁÖ¼Ò¸¦ Àû´Â´Ù.
type
master;
file "test.net.zone"; // zone ÆÄÀÏ
ÁöÁ¤.
allow-update { none; };
};
¿ª¹æÇâ
zone "0.168.192.in-addr.arpa" IN
{ // ¿ª¹æÇâÀº ip.in-addr.arpa Çü½ÄÀ¸·Î ¸¸µç´Ù.
type master;
file "0.168.192.zone"; // zone ÆÄÀÏ ÁöÁ¤
allow-update
{ none; };
};
4. ZoneÆÄÀÏ »ý¼º ¹× ¸µÅ©
# cd /var/named/chroot/var/named
//À̵¿ÇÑ´Ù.
[root@localhost named]# ls
-al
ÇÕ°è 52
drwxr-x--- 4 root named 4096 6¿ù 18 09:31 .
drwxr-x--- 6
root named 4096 6¿ù 18 09:08 ..
drwxrwx--- 2 named named 4096 6¿ù 18 09:27
data
-rw-r----- 1 root named 198 10¿ù 13 2012
localdomain.zone
-rw-r----- 1 root named 195 10¿ù 13 2012
localhost.zone
-rw-r----- 1 root named 427 10¿ù 13 2012
named.broadcast
-rw-r----- 1 root named 1892 10¿ù 13 2012
named.ca
-rw-r----- 1 root named 424 10¿ù 13 2012
named.ip6.local
-rw-r----- 1 root named 426 10¿ù 13 2012
named.local
-rw-r----- 1 root named 427 10¿ù 13 2012
named.zero
drwxrwx--- 2 named named 4096 7¿ù 27 2004 slaves
ÆÄÀÏÀ» º¸¸é localhost.zone ÆÄÀÏÀÌ Àִµ¥ Áö±Ý
ÀÌ°Ô ¾ø´Ù¸é caching-nameserver °¡ ¾ø°Å³ª À߸ø ¼³Ä¡µÈ °ÍÀÌ´Ï ¼³Ä¡¸¦ Çؾß
ÇÑ´Ù.
cp¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© zoneÆÄÀÏÀ» ¸¸µé¾î ÁØ´Ù.
#cp localhost.zone test.net.zone // test.net ÀÇ zone ÆÄÀÏÀ»
¸¸µç´Ù.
#cp localhost.zone 0.168.192.zone // teet.net ÀÇ ¿ª¹æÇâ zone ÆÄÀÏÀ»
¸¸µç´Ù.
0.168.192.zone ¼¹öÀÇ ¸Ç ¸¶Áö¸· ³¡ÀÚ¸®¸¦ »« 3ÀÚ¸®¿¡ zoneÀ» ºÙ¿©¼ ¸¸µé¾î ³½´Ù.
[test.net.zone]
$TTL 86400
@ IN
SOA @ root (
42 ;
serial (d. adams)
3H ;
refresh
15M ;
retry
1W ;
expiry
1D ) ;
minimum
IN NS
ns.test.net.
IN A 127.0.0.1
IN
AAAA ::1
ns IN A
192.168.0.34
www IN A 192.168.0.34
ftp
IN A 192.168.0.34
[0.168.192.zone]
$TTL 86400
@ IN SOA
@ root (
42 ;
serial (d. adams)
3H ;
refresh
15M ;
retry
1W ;
expiry
1D ) ;
minimum
IN NS @
IN
A 127.0.0.1
IN AAAA ::1
34
IN PTR www.test.net.
34 IN
PTR ftp.test.net.
34 IN
PTR ns.test.net.
ÀÌÁ¦ ÆÄÀÏ Æ۹̼ÇÀ» ÁÖµµ·Ï ÇÑ´Ù. ÆÄÀÏ Æ۹̼ÇÀ» ÁÖ´Â ÀÌÀ¯´Â chrootÀÇ Á¦ÇÑ
¶§¹®ÀÌ´Ù.
±âÁ¸¿¡´Â chroot »óÀ§¿¡ Á¸ ÆÄÀÏÀ» ¿Ã·È´ÂÁö Áö±ÝÀº ¸µÅ©·Î ´ëü ÇÏ°í ÀÖ´Ù.
# chown named:named /var/named/chroot/var/named/jiho.net.zone
# chown named:named /var/named/chroot/var/named/1.16.172.zone
* ·çÆ® ±ÇÇÑÀ» Á൵ µÇ´Âµ¥...±ÇÀåµÇÁö´Â ¾Ê´Â´Ù.
ex #
chown root:named /var
´ÙÀ½Àº /var/named Æú´õ¿¡ ¸µÅ©ÆÄÀÏÀ» ³ÖÀ» Â÷·ÊÀÌ´Ù. ÇØ´ç Æú´õ·Î À̵¿ÇÏ¿©
# ln -s /var/named/chroot/var/named/jiho.net.zone
jiho.net.zone
# ln -s /var/named/chroot/var/named/1.16.172.zone
1.16.172.zone
ÀÌ·¸°Ô ÇÏ¸é ¸µÅ©ÆÄÀÏÀÌ »ý¼ºµÈ´Ù. ÀÌÁ¦´Â ½ÇÇàÇÒ Àϸ¸
³²¾Ò´Ù.
# service named start ¸¦ ÇÏ¸é ¼ºñ½º°¡ ½ÇÇàÀÌ µÉ °ÍÀÌ´Ù. ¸¸¾à ¿À·ù°¡ ³´Ù¸é ÇØ´çÇÏ´Â
ÆÄÀÏ·Î °¡¼ ¼öÁ¤À» ÇÏ¸é µÇ°Ù´Ù.
¶ÇÇÑ Á¸ ÆÄÀÏÀ̳ª ±âŸ ÆÄÀÏÀ» ¼öÁ¤ÇÑ´Ù¸é Àç½ÃÀÛ ÇØÁÖ¾î¾ß ÇÑ´Ù.
# service named restart ¸¦ ÀÌ¿ëÇϵµ·Ï ÇÑ´Ù.
¼ºñ½º ½ÃÀ۽à ÀÚµ¿½ÇÇà
# chkconfig --list |
grep named
named 0:off 1:off 2:on
3:on 4:on 5:on 6:off //ÀÌ »óÅ°¡ µÇ¾î¾ß ÇÑ´Ù.
¼³Á¤¹ý
# chkconfig --level 5 named on
# chkconfig named
on
grep Çغ¸¸é À§¿Í °°ÀÌ º¯°æ µÈ °ÍÀ» È®ÀÎ ÇÒ ¼ö ÀÖ´Ù.
2Â÷ ³×ÀÓ ¼¹ö ±¸¼º ÇÏ´Â ¹æ¹ý
= 1Â÷ ³×ÀÓ ¼¹öÀÇ ¼³Á¤ =
1. ¡² rndc.key ¸¦ ÀÌ¿ëÇÑ µ¿±âÈ ¹æ¹ý
¡³
- 1Â÷ ³×ÀÓ¼¹öÀÇ /etc/rndc.key °ªÀ» 2Â÷ ³×ÀÓ¼¹öÀÇ /etc/rndc.key°ªÀ» µ¿ÀÏÇÏ°Ô
¼öÁ¤ÇÑ´Ù.
[root@backup named¡³# more /etc/rndc.key
key "rndckey"
{
algorithm hmac-md5;
secret
"3MueARgOApRyrgACga6jqWZPzFIp83uyns97bMAdz0ylJ8LHQZ8NO";
};
2. ¡² 1Â÷ ³×ÀÓ¼¹öÀÇ named.conf ¼³Á¤ ¡³
-
named.confÆÄÀÏ¿¡ "allow-transfer" Ç׸ñ¸¦ Ãß°¡ µî·ÏÇÑ´Ù.................
options
{
directory "/var/named";
dump-file
"/var/named/data/cache_dump.db";
statistics-file
"/var/named/data/named_stats.txt";
//query-source address * port
53;
allow-transfer { 192.168.1.2; }; // 2Â÷ DNS
IP..
};
3. ¡² /etc/rndc.key µî·Ï ¡³
- ±âº»À¸·Î
include "/etc/rndc.key"; ·Î µî·ÏµÇ¾î ÀÖÀ½. ( zone ¼³Á¤ Ç׸ñº¸´Ù »óÀ§¿¡ ¶óÀο¡ µî·Ï)
- ¶Ç´Â
rndc.key °ªÀ» Á÷Á¢ µî·ÏÇÑ´Ù.
key "rndckey" {
algorithm
hmac-md5;
secret
"3MueARgOApRyrgACgalqOZPzFIp83uyns97bMAdz0ylJ8LHQZ8NO";
};
- µÑÀå
Çϳª¸¸ ¼³Á¤ÇÏ¸é µË´Ï´Ù.
4. ¡² ZONE ÆÄÀÏ ¼³Á¤¡³
- zone ¼³Á¤
½Ã allow-update, allow-transfer Ç׸ñ Ãß°¡
zone "bansong.hs.kr" IN
{
type master;
file
"named.bansong";
allow-update { key rndckey; };
allow-transfer { key rndckey; };
};
¶Ç´Â
rndc.key°ªÀÌ ¾Æ´Ñ IP¸¦ Á÷Á¢µî·ÏÇÏ´Â ¾Æ·¡ ¹æ½Äµµ ÀÖ´Ù
allow-update { localhost;
192.168.1.2; };
allow-update { localhost; 192.168.1.2;
};
= 2Â÷ ³×ÀÓ ¼¹öÀÇ ¼³Á¤ =
5.
¡² named.conf ¼³Á¤¡³
- named.conf ÆÄÀÏ¿¡ server Ç׸ñ¸¦
µî·ÏÇÑ´Ù.
server 192.168.1.1{ // 1Â÷³×ÀÓ¼¹ö
IPµî·Ï
keys {rndckey;};
};
6.
¡² ZONE ÆÄÀÏ ¼³Á¤¡³
- zone ¼³Á¤ ½Ã type , masters Ç׸ñ Ãß°¡
zone
"bansong.hs.kr" IN {
type slave;
file
"named.slave.bansong";
masters { 192.168.1.1; }; // 1Â÷³×ÀÓ¼¹ö
IPµî·Ï
};
7. ¡² named Àç ½ÇÇà ¹× /var/name/chroot/var/named
¹é¾÷ÆÄÀÏ È®ÀΡ³
- ¼³Á¤ÀÌ ³¡³ª¸é named µ¥¸ó Àç½ÇÇà ÈÄ /var/log/messages ÆÄÀÏ·Î µ¿ÀÛ ¿©ºÎ¸¦
È®ÀÎÇÑ´Ù.
- 2Â÷ ³×ÀÓ¼¹öÀÇ /var/named/chroot/var/named¿¡ zone ÆÄÀÏ »ý¼º µÇ´ÂÁö È®ÀÎÇÑ´Ù.
-
¸¶Áö¸·À¸·Î dig ¹× nslookup ¸í·ÉÀ» ÀÌ¿ëÇÏ¿© µ¿ÀÛ¿©ºÎ¸¦ È®ÀÎÇÑ´Ù.