BIND 9快速安装实例[笔记]
发表于:2007-06-09来源:作者:点击数:
标签:
这是一个 服务器 安装的一部分; 由于论坛吃空格,准备了txt文件在这里: http://www.hackerbay.com/doc/bind9.txt [code:1:3f69c81bf9]########################BIND9############### #简单的bind9安装 #配置为转发+master### 阿土AborigenYin http//www.ha
这是一个
服务器安装的一部分;
由于论坛吃空格,准备了txt文件在这里:
http://www.hackerbay.com/doc/bind9.txt
[code:1:3f69c81bf9]######################## BIND 9 ###############
# 简单的bind 9 安装
# 配置为 转发 + master ###
阿土 Aborigen Yin
http://www.hackerbay.com
2003.06.27
###################### modules bind 9 #############33
7.安装bind 9.2.2
7.1.获得源码并安装
mkdir -p /usr/local/src/distfiles
cd /usr/local/src/distfiles
#wget ftp://ftp.isc.org/isc/bind9/9.2.2/bind-9.2.2.tar.gz
wget ftp://172.16.100.245/pub/distfiles/bind-9.2.2.tar.gz
tar xfz bind-9.2.2.tar.gz -C ..
cd ../bind-9.2.2/
./configure --prefix=/usr/local/modules/named --disable-ipv6
make && make install
7.2.add user and group for named
pw groupadd named
mkdir -p /usr/local/modules/named/etc
mkdir -p /usr/local/modules/named/var/log
mkdir -p /usr/local/modules/named/var/run
pw useradd named -g named -d /usr/local/modules/named -s /sbin/nologin
chown -R named:named /usr/local/modules/named
chmod 700 /usr/local/modules/named
chmod 777 /usr/local/modules/named/var/run
7.3.配置DNS服务器
cd /usr/local/modules/named/etc
#vi named.conf
//begin of named.conf
acl "trust-lan" { 127.0.0.1/8; 192.168.0.0/16; 172.16.0.0/16; };
options {
directory "/usr/local/modules/named/etc";
datasize 80M;
allow-transfer {
"trust-lan";
};
forward first;
forwarders {
202.96.134.133;
202.96.128.110;
};
//recursion no;
recursion yes;
allow-notify {
"trust-lan";
};
allow-recursion {
"trust-lan";
};
//auth-nxdomain yes;
auth-nxdomain no;
#不报告自己的版本号
version "[secured]";
};
// How to log
logging {
channel warning
{
file "/usr/local/modules/named/var/log/dns_warnings" versions 3 size 10240k;
severity warning;
print-category yes;
print-severity yes;
print-time yes;
};
channel general_dns
{
file "/usr/local/modules/named/var/log/dns_logs" versions 3 size 10240k;
severity info;
print-category yes;
print-severity yes;
print-time yes;
};
category default { warning; } ;
category queries { general_dns; } ;
};
zone "." {
type hint;
file "named.root";
};
zone "0.0.127.IN-ADDR.ARPA" {
type master;
file "localhost.rev";
};
zone "oss4e.org"{
type master;
file "zone.oss4e.org";
notify yes;
};
zone "100.16.172.in-addr.arpa" {
type master;
file "zone.100.16.172.in-addr.arpa";
};
//end of named.conf
touch /usr/local/modules/named/var/log/dns_warnings
touch /usr/local/modules/named/var/log/dns_logs
#获得根提示文件
wget ftp://ftp.internic.org/domain/named.root
#vi named.root
; This file holds the information on root name servers needed to
; initialize cache of Internet domain name servers
; (e.g. reference this file in the "cache . <file>"
; configuration file of BIND domain name servers).
;
; This file is made available by InterNIC
; under anonymous FTP as
; file /domain/named.root
; on server FTP.INTERNIC.NET
;
; last update: Nov 5, 2002
; related version of root zone: 2002110501
;
;
; formerly NS.INTERNIC.NET
;
. 3600000 IN NS A.ROOT-SERVERS.NET.
A.ROOT-SERVERS.NET. 3600000 A 198.41.0.4
;
; formerly NS1.ISI.EDU
;
. 3600000 NS B.ROOT-SERVERS.NET.
B.ROOT-SERVERS.NET. 3600000 A 128.9.0.107
;
; formerly C.PSI.NET
;
. 3600000 NS C.ROOT-SERVERS.NET.
C.ROOT-SERVERS.NET. 3600000 A 192.33.4.12
;
; formerly TERP.UMD.EDU
;
. 3600000 NS D.ROOT-SERVERS.NET.
D.ROOT-SERVERS.NET. 3600000 A 128.8.10.90
;
; formerly NS.NASA.GOV
;
. 3600000 NS E.ROOT-SERVERS.NET.
E.ROOT-SERVERS.NET. 3600000 A 192.203.230.10
;
; formerly NS.ISC.ORG
;
. 3600000 NS F.ROOT-SERVERS.NET.
F.ROOT-SERVERS.NET. 3600000 A 192.5.5.241
;
; formerly NS.NIC.DDN.
MIL
;
. 3600000 NS G.ROOT-SERVERS.NET.
G.ROOT-SERVERS.NET. 3600000 A 192.112.36.4
;
; formerly AOS.ARL.ARMY.MIL
;
. 3600000 NS H.ROOT-SERVERS.NET.
H.ROOT-SERVERS.NET. 3600000 A 128.63.2.53
;
; formerly NIC.NORDU.NET
;
. 3600000 NS I.ROOT-SERVERS.NET.
I.ROOT-SERVERS.NET. 3600000 A 192.36.148.17
;
; operated by VeriSign, Inc.
;
. 3600000 NS J.ROOT-SERVERS.NET.
J.ROOT-SERVERS.NET. 3600000 A 192.58.128.30
;
; housed in LINX, operated by RIPE N
CC
;
. 3600000 NS K.ROOT-SERVERS.NET.
K.ROOT-SERVERS.NET. 3600000 A 193.0.14.129
;
; operated by IANA
;
. 3600000 NS L.ROOT-SERVERS.NET.
L.ROOT-SERVERS.NET. 3600000 A 198.32.64.12
;
; housed in Japan, operated by WIDE
;
. 3600000 NS M.ROOT-SERVERS.NET.
M.ROOT-SERVERS.NET. 3600000 A 202.12.27.33
; End of File
;vi zone.oss4e.org
;begin of zone.oss4e.org
$TTL 3600
@ IN
SOA dns1.oss4e.org. webmaster.oss4e.org. (
12061702 ; Serial (date, 2 digits version of day)
86400 ; refresh (1 day)
7200 ; retry (2 hours)
864000 ; expire (10 days)
86400 ) ; minimum (1 day)
IN NS dns1.oss4e.org.
IN NS dns2.oss4e.org.
IN NS dns.oss4e.org.
IN MX 10 mail.oss4e.org.
oss4e.org. IN A 172.16.100.243
dns IN A 172.16.100.243
dns1 IN A 172.16.100.243
dns2 IN A 172.16.100.243
mail IN A 172.16.100.243
smtp IN CNAME mail.oss4e.org.
;泛域名解析
* IN A 172.16.100.243
;end of zone.oss4e.org
;vi localhost.rev
;begin of localhost.rev
$TTL 3600
@ IN SOA dns1.oss4e.org. webmaster.oss4e.org. (
12061702 ; Serial (date, 2 digits version of day)
86400 ; refresh (1 day)
7200 ; retry (2 hours)
864000 ; expire (10 days)
86400 ) ; minimum (1 day)
IN NS dns1.oss4e.org.
IN NS dns2.oss4e.org.
IN NS dns.oss4e.org.
IN MX 10 mail.oss4e.org.
1 IN PTR localhost.oss4e.org.
;end of localhost.rev
;vi zone.100.16.172.in-addr.arpa
;zone.100.16.172.in-addr.arpa
$TTL 3600
@ IN SOA dns1.oss4e.org. webmaster.oss4e.org. (
12061702 ; Serial (date, 2 digits version of day)
86400 ; refresh (1 day)
7200 ; retry (2 hours)
864000 ; expire (10 days)
86400 ) ; minimum (1 day)
IN NS dns1.oss4e.org.
IN NS dns2.oss4e.org.
IN NS dns.oss4e.org.
IN MX 10 mail.oss4e.org.
243 IN PTR mail.oss4e.org.
;end of zone.100.16.172.in-addr.arpa
7.4.配置环境
#vi /etc/resolv.conf
domain oss4e.org
nameserver 127.0.0.1
nameserver 202.96.134.133
nameserver 202.96.128.110
7.5.#配置日志:
#vi /etc/syslog.conf
#添加local.none到messages的末尾,阻止named发送日志到messages;
# Don't log private authentication messages!
*.info;mail.none;authpriv.none;cron.none;local.none /var/log/messages
#添加如下,其中!named表示named这个进程发来的日志;
!named
*.* /usr/local/modules/named/var/log/named.log
#这个是syslog.conf中要求的;
touch /usr/local/modules/named/var/log/named.log
chown named:named /usr/local/modules/named/var/log/named.log
chmod 766 /usr/local/modules/named/var/log/named.log
killall -HUP syslogd
7.6.配置启动文件
#vi /usr/local/modules/named/bin/named-mgr.sh
#!/bin/sh
if [ `id -u` -ne 0 ]
then
echo "ERROR:For bind to port 53,must run as root."
exit 1
fi
case "$1" in
start)
if [ -x /usr/local/modules/named/sbin/named ]; then
/usr/local/modules/named/sbin/named -u named && echo . && echo 'BIND9 server started.'
fi
;;
stop)
kill `cat /usr/local/modules/named/var/run/named.pid` && echo . && echo 'BIND9 server stopped.'
;;
restart)
echo .
echo "Restart BIND9 server ......"
$0 stop
sleep 10
$0 start
;;
*)
echo "$0 start | stop | restart"
;;
esac
#end of named-mgr.sh
chmod 755 /usr/local/modules/named/bin/named-mgr.sh
ln -s /usr/local/modules/named/bin/named-mgr.sh /usr/local/sbin
ln -s /usr/local/modules/named/bin/named-mgr.sh /usr/local/etc/rc.d
7.7.配置权限
rm -rf /usr/local/modules/named/.*
chown -R named:named /usr/local/modules/named/*
chmod -R 700 /usr/local/modules/named/*
#end of bind9[/code:1:3f69c81bf9]
[code:1:3f69c81bf9][/code:1:3f69c81bf9]
seewind 回复于:2003-06-27 20:45:30
|
:)
刚好,学习学习
谢谢
|
MaxBSD 回复于:2003-06-27 21:31:08
|
JJ!
|
aborigen 回复于:2003-06-27 21:37:27
|
这是为了webmasters那个反解的问题而贴的,这只是笔记,基本上没有解释,虽然你依葫芦画瓢肯定能装上,却是跟吃快食面差不多;想要学到东西还得查资料知道每一步、每个配置文件为什么样这样写。
|
bsdxp 回复于:2003-06-27 23:11:58
|
好同志,同志好。
|
红袖添香 回复于:2003-06-28 05:37:13
|
[quote:6069500fc3="aborigen"]这是为了webmasters那个反解的问题而贴的,这只是笔记,基本上没有解释,虽然你依葫芦画瓢肯定能装上,却是跟吃快食面差不多;想要学到东西还得查资料知道每一步、每个配置文件为什么样这样写。[/quote:6069500fc3]
看 O'Reilly 的那本圣经。

| bind
| quakelee 回复于:2003-06-28 07:09:09
| 偶有这本圣经的中文版~~
| Reinstall 回复于:2003-06-28 08:14:40
| [quote:5dda4a974a="quakelee"]偶有这本圣经的中文版~~[/quote:5dda4a974a]
给down一下啦
| quakelee 回复于:2003-06-28 08:25:20
| [quote:da421ce4d9="Reinstall"]
给down一下啦[/quote:da421ce4d9]
七折在新华书店批销中心买的,是纸板的,偶没有扫描仪的说 :?
| love-centry 回复于:2003-06-28 08:50:21
| 是否有down啊?
| quakelee 回复于:2003-06-28 09:38:06
| 英文版的应该是有当的,不过中文的可能没有
| noress 回复于:2003-06-28 11:03:40
| 中文的我在图书馆看了看,69块(不算太贵,物有所值嘛,E版的就太贵了,110多).绝对的经典!居然不打折!(俺当时口袋刚好只有67,气死偶了)太黑了!偶想去china-pub邮购,便宜几块!
| kinux 回复于:2003-06-28 15:04:51
| [quote:17e45299ce="红袖添香"]
看 O'Reilly 的那本圣经。[/quote:17e45299ce]
i buy 3 edition Chinese version with HK$55 dollars 2 years ago.....
红袖送我一本 4th edition.. :P
| 红袖添香 回复于:2003-06-28 20:46:44
| [quote:269e3b5967="kinux"]
i buy 3 edition Chinese version with HK$55 dollars 2 years ago.....
红袖送我一本 4th edition.. :P[/quote:269e3b5967]
geee, 我自己都没有呢.
也是图书借来看...
| chenhawk 回复于:2003-06-30 17:42:46
| 我在这找到了,http://www.itebook.net/epub/OReilly/netw_03.htm,谁能down下来麻烦发给我一份,谢谢!
chen_hawk@163.com
| 黑夜编码人 回复于:2003-07-01 13:30:44
| 阿土,你这么多好文章也给咱们投点稿嘛,现在我们急需网友们投稿呀。
^_^
http://www.cnfug.org/journal/contribute.html
| aborigen 回复于:2003-07-01 17:32:24
| [quote:da93018e17="黑夜编码人"]阿土,你这么多好文章也给咱们投点稿嘛,现在我们急需网友们投稿呀。
^_^
http://www.cnfug.org/journal/contribute.html[/quote:da93018e17]
:oops: :oops: :oops: :oops:
| Macolex 回复于:2004-12-30 14:52:55
| 呵呵~~~`
那书我们这边有
|
原文转自:http://www.ltesting.net
|
|