实现Internet 的DNS 服务架构

2021-02-13 12:17

阅读:567

标签:dom   system   forward   admin   echo   ref   span   created   net   

整体架构的构架图如下图(其中服务器用centos8系统搭建,测试客户端用centos7系统实现)

技术图片

 

 1.8台主机介绍

DNS客户端:10.0.0.7/24 
本地DNS服务器(只缓存):10.0.0.8/24
转发目标DNS服务器:10.0.0.18/24
根DNS服务器:10.0.0.28/24
org域DNS服务器:10.0.0.38/24
magedu.org域主DNS服务器:10.0.0.48/24
magedu.org域从DNS服务器:10.0.0.58/24
www.magedu.org的WEB服务器:10.0.0.68/24

2.服务器具体的搭建过程

#为防止服务器搭建过程出现错误,我们从后往前搭建(利用测试客户端不断检测,以免搭建过程出现错误)

 

(1)搭建web服务器10.0.0.68

 

[root@centos68 ~]$yum -y install httpd
[root@centos68 ~]$systemctl enable --now httpd
Created symlink /etc/systemd/system/multi-user.target.wants/httpd.service →/usr/lib/systemd/system/httpd.service.
[root@centos8 ~]$echo www.magedu.org > /var/www/html/index.html

 

(2)搭建主DNS服务器:10.0.0.48

 

[root@centos48 ~]$yum -y install bind bind-utils
[root@centos48 ~]$vim /etc/named.conf
//  listen-on port 53 { 127.0.0.1; };

//  allow-query     { localhost; };
[root@centos48 ~]$vim /etc/named.rfc1912.zones
zone "magedu.org" {
       type master;
       file "magedu.org.zone";
  };

[root@centos48 ~]$vim /var/named/magedu.org.zone

  1 $TTL  1D
  2 @     IN SOA master  admin.magedu.org. (
  3                         1   ; serial
  4                         1D  ; refresh
  5                         1H  ; retry
  6                         1W  ; expire
  7                         3H  )   ; minimum
  8           NS    master  
  9           NS    slave
 10 master    A     10.0.0.48
 11 slave     A     10.0.0.58
 12 www       A     10.0.0.68
[root@centos48 ~]$systemctl start named

 

 

 

 

(3)搭建从DNS服务器:10.0.0.58

 

[root@centos58 ~]$yum -y install bind bind-utils
[root@centos58 ~]$vim /etc/named.conf
//  listen-on port 53 { 127.0.0.1; };

//  allow-query     { localhost; };
[root@centos58 ~]$vim /etc/named.rfc1912.zones
zone "magedu.org" {
      type slave;
      masters {10.0.0.48;};
      file "slaves/magedu.org.zone";
   };
[root@centos58 ~]$systemctl start named
[root@centos58 ~]$ll /var/named/slaves/
total 4
-rw-r--r-- 1 named named 319 May 31 14:53 magedu.org.zone

 

(4)搭建org域DNS服务器:10.0.0.38

 

 

 

 

[root@centos38 ~]$yum -y install bind bind-utils
[root@centos38 ~]$vim /etc/named.conf
//  listen-on port 53 { 127.0.0.1; };

//  allow-query     { localhost; };
[root@centos38 ~]$vim /etc/named.rfc1912.zones
zone "org" IN  {
       type master;
       file "org.zone";
  };
[root@centos38 ~]$vim /var/named/org.zone

    $TTL 1D
    @   IN  SOA     master  admin.magedu.org. ( 1 1D 1H 1W 3D )
                    NS      master
    magedu          NS      mageduns1
    magedu          NS      mageduns2
      master          A       10.0.0.38
     mageduns1       A       10.0.0.48
     mageduns2       A       10.0.0.58
[root@centos38 ~]$systemctl restart named

 

(5)搭建根DNS服务器:10.0.0.28

 

[root@centos28 ~]$yum -y install bind bind-utils
[root@centos28 ~]$vim /etc/named.conf
//  listen-on port 53 { 127.0.0.1; };

//  allow-query     { localhost; };

#默认有根服务器,所有更改在53行
   zone "." IN {
       type master;
       file "root.zone";
   };
[root@centos28 ~]$vim /var/named/root.zone

    $TTL  1D
    @   IN  SOA     master  admin.magedu.org.   ( 1 1D 1H 1W 3D )
                    NS  master
    org             NS  orgns
    master          A   10.0.0.28
    orgns           A   10.0.0.38
[root@centos28 ~]$systemctl start named

 

(6)搭建转发目标DNS服务器:10.0.0.18

 

[root@centos18 ~]$yum -y install bind bind-utils
[root@centos18 ~]$vim /etc/named.conf
//  listen-on port 53 { 127.0.0.1; };

//  allow-query     { localhost; };

33      dnssec-enable no;
34     dnssec-validation no;
[root@centos18 ~]$vim /var/named/named.ca
 .           518400  IN  NS  a.root-servers.net.
 a.root-servers.net. 518400  IN  A   10.0.0.28
[root@centos18 ~]$systemctl restart named

 

(7)搭建本地DNS服务器(只缓存):10.0.0.8

 

[root@centos 8 ~]$yum -y install bind bind-utils
[root@centos 8 ~]$vim /etc/named.conf
//  listen-on port 53 { 127.0.0.1; };
//  allow-query     { localhost; };
forward only;
 forwarders {10.0.0.18;};
33      dnssec-enable no;
34     dnssec-validation no;

[root@centos8 ~]$systemctl restart named

 

(8)客户端10.0.0.7测试部分(此部分并非为最后一步,而是随着七台服务器的搭建过程中随时测试,出现以下测试结果则服务器搭建成功)

[root@centos7 ~]$curl 10.0.0.68
www.magedu.org
[root@centos7 ~]$host www.magedu.org 10.0.0.48
Using domain server:
Name: 10.0.0.48
Address: 10.0.0.48#53
Aliases: 

www.magedu.org has address 10.0.0.68
[root@centos7 ~]$host www.magedu.org 10.0.0.58
Using domain server:
Name: 10.0.0.58
Address: 10.0.0.58#53
Aliases: 

www.magedu.org has address 10.0.0.68
[root@centos7 ~]$host www.magedu.org 10.0.0.38
Using domain server:
Name: 10.0.0.38
Address: 10.0.0.38#53
Aliases: 

www.magedu.org has address 10.0.0.68
[root@centos7 ~]$host www.magedu.org 10.0.0.28
Using domain server:
Name: 10.0.0.28
Address: 10.0.0.28#53
Aliases: 

www.magedu.org has address 10.0.0.68
[root@centos7 ~]$host www.magedu.org 10.0.0.18
Using domain server:
Name: 10.0.0.18
Address: 10.0.0.18#53
Aliases: 

www.magedu.org has address 10.0.0.68
[root@centos7 ~]$host www.magedu.org 10.0.0.8
Using domain server:
Name: 10.0.0.8
Address: 10.0.0.8#53
Aliases: 

www.magedu.org has address 10.0.0.68
[root@centos7 ~]$curl www.magedu.org
www.magedu.org
[root@centos7 ~]$

 

 

 

 

 

 

实现Internet 的DNS 服务架构

标签:dom   system   forward   admin   echo   ref   span   created   net   

原文地址:https://www.cnblogs.com/lidanyue/p/13019878.html


评论


亲,登录后才可以留言!