首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >bind9适当的递归设置

bind9适当的递归设置
EN

Server Fault用户
提问于 2014-10-08 20:13:01
回答 1查看 24.3K关注 0票数 12

如果删除递归,则无法解析外部域,但仍然可以解析DNS服务器上的域。

正确设置递归的正确方法是什么,这样就可以在不打开DNS服务器的情况下解析外部域?

named.conf.options

代码语言:javascript
复制
options {
    version "One does not simply get my version";

    directory "/var/cache/bind";

    // If there is a firewall between you and nameservers you want
    // to talk to, you may need to fix the firewall to allow multiple
    // ports to talk.  See http://www.kb.cert.org/vuls/id/800113

    // If your ISP provided one or more IP addresses for stable
    // nameservers, you probably want to use them as forwarders.
    // Uncomment the following block, and insert the addresses replacing
    // the all-0's placeholder.

    // forwarders {
    //      0.0.0.0;
    // };

    //========================================================================
    // If BIND logs error messages about the root key being expired,
    // you will need to update your keys.  See https://www.isc.org/bind-keys
    //========================================================================
    dnssec-validation yes;

    auth-nxdomain no;
    listen-on-v6 { any; };
    allow-recursion { any; };
    allow-query {
            any;
            };
    allow-query-cache { any; };
    notify yes;
    dnssec-enable yes;
    dnssec-lookaside . trust-anchor dlv.isc.org.;
    also-notify {
            };
};

我还添加了内部子网,以允许-递归{ subnet/xx;};但仍然无法解析外部域。

EN

回答 1

Server Fault用户

回答已采纳

发布于 2014-10-08 21:22:51

筛选谁能够递归地查询DNS,谁不使用ACL。

代码语言:javascript
复制
acl my_net { 
    192.168.1.0/24;
};

acl my_other_net {
    10.0.0.0/8;
};

options {

    [ ... ]


    recursion yes;

    allow-recursion { my_net; };
    blackhole { my_other_net; };

};

此外,在网关中设置入口(BCP 84)/egress筛选,以避免欺骗UDP数据包以到达您的网络,并产生意外的通信量或中毒。黑洞不可信的部分,你当地的基础设施。

票数 8
EN
页面原文内容由Server Fault提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://serverfault.com/questions/634546

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档