BIND 9
BIND 9
BIND 9
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
CHAPTER 4. 高级DNS特征 4.4. 分割DNS<br />
zone "site1.example.com" {<br />
type master;<br />
file "m/site1.example.com";<br />
// do normal iterative resolution (do not forward)<br />
forwarders { };<br />
allow-query { internals; externals; };<br />
allow-transfer { internals; };<br />
};<br />
// sample slave zone<br />
zone "site2.example.com" {<br />
type slave;<br />
file "s/site2.example.com";<br />
masters { 172.16.72.3; };<br />
forwarders { };<br />
allow-query { internals; externals; };<br />
allow-transfer { internals; };<br />
};<br />
zone "site1.internal" {<br />
type master;<br />
file "m/site1.internal";<br />
forwarders { };<br />
allow-query { internals; };<br />
allow-transfer { internals; }<br />
};<br />
zone "site2.internal" {<br />
type slave;<br />
file "s/site2.internal";<br />
masters { 172.16.72.3; };<br />
forwarders { };<br />
allow-query { internals };<br />
allow-transfer { internals; }<br />
};<br />
外部(堡垒主机)DNS服务器配置:<br />
acl internals { 172.16.72.0/24; 192.168.1.0/24; };<br />
acl externals { bastion-ips-go-here; };<br />
options {<br />
...<br />
...<br />
// sample allow-transfer (no one)<br />
allow-transfer { none; };<br />
// default query access<br />
allow-query { any; };<br />
// restrict cache access<br />
allow-query-cache { internals; externals; };<br />
// restrict recursion<br />
allow-recursion { internals; externals; };<br />
...<br />
...<br />
};<br />
// sample slave zone<br />
24