02.07.2013 Views

BIND 9

BIND 9

BIND 9

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CHAPTER 4. 高级DNS特征 4.4. 分割DNS<br />

zone "site1.example.com" {<br />

type master;<br />

file "m/site1.example.com";<br />

// do normal iterative resolution (do not forward)<br />

forwarders { };<br />

allow-query { internals; externals; };<br />

allow-transfer { internals; };<br />

};<br />

// sample slave zone<br />

zone "site2.example.com" {<br />

type slave;<br />

file "s/site2.example.com";<br />

masters { 172.16.72.3; };<br />

forwarders { };<br />

allow-query { internals; externals; };<br />

allow-transfer { internals; };<br />

};<br />

zone "site1.internal" {<br />

type master;<br />

file "m/site1.internal";<br />

forwarders { };<br />

allow-query { internals; };<br />

allow-transfer { internals; }<br />

};<br />

zone "site2.internal" {<br />

type slave;<br />

file "s/site2.internal";<br />

masters { 172.16.72.3; };<br />

forwarders { };<br />

allow-query { internals };<br />

allow-transfer { internals; }<br />

};<br />

外部(堡垒主机)DNS服务器配置:<br />

acl internals { 172.16.72.0/24; 192.168.1.0/24; };<br />

acl externals { bastion-ips-go-here; };<br />

options {<br />

...<br />

...<br />

// sample allow-transfer (no one)<br />

allow-transfer { none; };<br />

// default query access<br />

allow-query { any; };<br />

// restrict cache access<br />

allow-query-cache { internals; externals; };<br />

// restrict recursion<br />

allow-recursion { internals; externals; };<br />

...<br />

...<br />

};<br />

// sample slave zone<br />

24

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!