2904 ¹ø ±ÛÀÇ ´äÀå±Û: Re: bind ¹®ÀÇ µå¸³´Ï´Ù. |
±Û¾´ÀÌ: »êÀÌ
[ȨÆäÀÌÁö]
|
±Û¾´³¯: 2011³â 08¿ù 22ÀÏ 21:07:01 ¿ù(Àú³á) |
Á¶È¸: 1834 |
[ÆĶõ¾ÆÀÌ]´ÔÀÌ ³²±â½Å ±Û:
>-----------------------------------------
>´äº¯ÀÚ°¡ ±âº»ÀûÀ¸·Î Âü°íÇÒ ³»¿ëÀÔ´Ï´Ù.
>- ¹èÆ÷ÆÇ(¿É¼Ç) : centos 5.5
>- Ä¿³Î¹öÀü(¿É¼Ç) : 2.6.18-238.19.1.el5 #1 SMP
>- µ¥¸ó¹öÀü(¿¹:apache 1.3.27) :
>- µ¥¸ó¼³Ä¡À¯Çü(RPM/ÄÄÆÄÀÏ/±âŸ)
: bind 9.8.0-P4 ¼Ò½º ¼³Ä¡
>-----------------------------------------
>*½ºÆÔÇÊÅ͸µ:ÇÑ±Û 11ÀÚ ÀÌ»ó ¾øÀ¸¸é ½ºÆÔÆäÀÌÁö·Î À̵¿ÇÕ´Ï´Ù
>
>¾È³çÇϼ¼¿ä^^.
>±âÁ¸ DNS ¼¹ö¸¦ ¾÷±×·¹À̵å ÇϱâÀ§ÇØ bind 9.8.0-P4 ¹öÀüÀ» ¼Ò½º·Î ¼³Ä¡¸¦
ÇÏ¿´´Âµ¥¿ä..
>³»ºÎ Äõ¸® (zone ÆÄÀÏ¿¡ ÀÖ´Â ³»¿ë)´Â Á¤»óÀûÀ¸·Î µÇ´Âµ¥..
>¿ÜºÎ Äõ¸® (naver, google)´Â ÀÀ´äÀÌ ¾ø½À´Ï´Ù.
>¿À·ùµµ ¾ø°í¿ä..
>¹æȺ®µµ ¸ðµÎ ¿¿´°í, ¼¹ö¿¡ iptables µµ »ç¿ëÇÏÁö ¾Ê°í Àִµ¥ ¿ÜºÎ¸¸ Äõ¸®°¡
¾ÈµË´Ï´Ù.
>
>±âÁ¸ ¼¹öÀÇ named.conf ÆÄÀÏÀ» °¡Á®´Ù ±×´ë·Î »ç¿ëÇÏ°í Àִµ¥¿ä..
>±âÁ¸ ¼¹ö¿¡¼´Â ³»ºÎ/¿ÜºÎ ¸ðµÎ Á¤»óÀûÀ¸·Î Äõ¸®°¡ µË´Ï´Ù.
>
>Â÷ÀÌÁ¡À̶ó¸é ±âÁ¸ ¼¹ö´Â chroot ¸¦ »ç¿ëÇÏ°í ½Å±Ô ¼¹ö´Â chroot ¸¦ »ç¿ëÇÏÁö
¾Ê½À´Ï´Ù.
>(9.8.0-P4 ¹öÀü¿ë chroot °¡ ¾ø¾î¼ »ç¿ëÇÏÁö ¾Ê°í ÀÖ½À´Ï´Ù.)
>zone ÆÄÀÏ ¹èÆ÷³ª ÀÌ·±°Ç ¸ðµÎ Á¤»ó ÀûÀÌ°í¿ä.
>
>named.conf ¸¦ ¿À·ù °Ë»ç¸¦ ÇØ ºÁµµ ³ª¿À´Â°Ô ¾ø´Âµ¥..
>¾î´À ºÎºÐÀ» ºÁ¾ß µÉ±î¿ä?
>
>
>¾Æ·¡´Â named.conf ¾ÕºÎºÐ ÀÔ´Ï´Ù.
>
>acl trust {
>192.168/16; ±âŸ »ç¿ë IP
>};
>
>options {
> directory "/var/named";
> allow-transfer { 127.0.0.1; };
> allow-recursion { trust; };
> allow-query { any; };
> allow-query-cache { trust; };
>};
>
># Use with the following in named.conf, adjusting the allow list as
needed:
>key " rndc-key" {
> algorithm hmac-md5;
> secret "»èÁ¦";
>};
>
>controls {
> inet 127.0.0.1 port 953
> allow { 127.0.0.1; } keys { "rndc-key"; };
>};
>
>logging {
> channel ch_queries_log {
> file "/var/named/log/ch_queries.log" versions 20 size
10m;
> severity debug;
> print-category yes;
> print-severity yes;
> print-time yes;
>};
>
>category queries { ch_queries_log; };
>};
>
>
>zone "." {
> type hint;
> file "named.ca";
>};
>
>zone "localhost" IN {
> type master;
> file "localhost.zone";
> allow-update { none; };
>};
>
>zone "0.0.127.IN-ADDR.ARPA" {
> type master;
> file "named.local";
>};
========================================
¿ì¼± ¼³Á¤ÆÄÀϸ¸ ºÁ¼´Â ¾îµð°¡ ¹®Á¦ÀÎÁö´Â ÆľÇÇϱâ Èûµå³×¿ä.
/var/log/message ¶Ç´Â /var/named/log/ch_queries.log
·Î±×ÆÄÀÏÀ» ÂüÁ¶Çؼ ¿øÀÎÀ» ã¾Æ¾ß ÇÒµí ÇÕ´Ï´Ù.
±×¿Ü¿¡
shell> dig +trace www.naver.com
ó·³ +trace ¿É¼ÇÀ» ÁÖ°í ¾îµð¿¡¼ °É¸®´ÂÁö È®ÀÎÇØ º¸¼¼¿ä.
|
ÀÌÀü±Û : bind ¹®ÀÇ µå¸³´Ï´Ù.
´ÙÀ½±Û : ¾È³çÇϼ¼¿ä SSH À¯Àúµé ¸í·É±ÇÇÑ ¹®Àǵ帳´Ï´Ù
|
from 211.212.225.115
JS(Redhands)Board 0.4 +@
|