FastHandle is fast operation tools for infrastructure configurations and tests.
This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
middleware:bind:conf001.html [2018/02/06 23:53] kurihara created |
middleware:bind:conf001.html [2018/02/10 01:33] (current) kurihara |
||
---|---|---|---|
Line 1: | Line 1: | ||
[[middleware: | [[middleware: | ||
- | ====== BIND Default Configuration ====== | + | ====== |
\\ | \\ | ||
Line 6: | Line 6: | ||
\\ | \\ | ||
- | ===== CentOS7 ===== | + | |
- | ==== / | + | ===== / |
+ | |||
+ | *See / | ||
<sxh bash toolbar: | <sxh bash toolbar: | ||
Line 20: | Line 22: | ||
// See the BIND Administrator' | // See the BIND Administrator' | ||
// configuration located in / | // configuration located in / | ||
+ | |||
options { | options { | ||
- | | + | |
- | listen-on-v6 port 53 { ::1; }; | + | listen-on-v6 port 53 { ::1; }; |
- | directory | + | directory |
- | dump-file | + | dump-file |
- | statistics-file "/ | + | statistics-file "/ |
- | memstatistics-file "/ | + | memstatistics-file "/ |
- | allow-query | + | allow-query |
- | | + | /* |
+ | - If you are building an AUTHORITATIVE DNS server, do NOT enable recursion. | ||
+ | - If you are building a RECURSIVE (caching) DNS server, you need to enable | ||
+ | | ||
+ | - If your recursive DNS server has a public IP address, you MUST enable access | ||
+ | | ||
+ | cause your server to become part of large scale DNS amplification | ||
+ | | ||
+ | | ||
+ | */ | ||
+ | | ||
- | | + | |
- | dnssec-validation yes; | + | dnssec-validation yes; |
- | | + | |
- | bindkeys-file "/ | + | bindkeys-file "/ |
- | | + | |
- | | + | |
- | session-keyfile "/ | + | session-keyfile "/ |
}; | }; | ||
Line 51: | Line 64: | ||
zone " | zone " | ||
- | | + | |
- | file " | + | file " |
}; | }; | ||
include "/ | include "/ | ||
include "/ | include "/ | ||
+ | |||
</ | </ | ||
\\ | \\ | ||
- | ==== ftpusers | + | ===== / |
- | Users that are not allowed to login via ftp | + | |
- | < | + | < |
- | # Users that are not allowed to login via ftp | + | $TTL 1D |
- | root | + | @ IN SOA @ rname.invalid. ( |
- | bin | + | |
- | daemon | + | |
- | adm | + | |
- | lp | + | |
- | sync | + | 3H ) ; minimum |
- | shutdown | + | |
- | halt | + | |
- | + | | |
- | news | + | |
- | uucp | + | |
- | operator | + | |
- | games | + | |
- | nobody | + | |
</ | </ | ||
+ | |||
\\ | \\ | ||
- | ==== user_list | + | ===== / |
- | < | + | |
- | # vsftpd userlist | + | < |
- | # If userlist_deny=NO, | + | $TTL 1D |
- | # If userlist_deny=YES (default), never allow users in this file, and | + | @ IN SOA @ rname.invalid. ( |
- | # do not even prompt for a password. | + | |
- | # Note that the default vsftpd pam config also checks / | + | |
- | # for users that are denied. | + | |
- | root | + | |
- | bin | + | 3H ) ; minimum |
- | daemon | + | |
- | adm | + | |
- | lp | + | |
- | sync | + | |
- | shutdown | + | |
- | halt | + | |
- | + | ||
- | news | + | |
- | uucp | + | |
- | operator | + | |
- | games | + | |
- | nobody | + | |
</ | </ | ||
+ | \\ | ||
+ | ===== / | ||
+ | |||
+ | <sxh bash toolbar: | ||
+ | $TTL 3H | ||
+ | @ IN SOA @ rname.invalid. ( | ||
+ | 0 ; serial | ||
+ | 1D ; refresh | ||
+ | 1H ; retry | ||
+ | 1W ; expire | ||
+ | 3H ) ; minimum | ||
+ | NS @ | ||
+ | A | ||
+ | AAAA ::1 | ||
+ | </ | ||
+ | |||
+ | \\ | ||
+ | ===== / | ||
+ | |||
+ | <sxh bash toolbar: | ||
+ | ; <<>> | ||
+ | ; (2 servers found) | ||
+ | ;; global options: +cmd | ||
+ | ;; Got answer: | ||
+ | ;; ->> | ||
+ | ;; flags: qr aa; QUERY: 1, ANSWER: 13, AUTHORITY: 0, ADDITIONAL: 27 | ||
+ | |||
+ | ;; OPT PSEUDOSECTION: | ||
+ | ; EDNS: version: 0, flags:; udp: 1472 | ||
+ | ;; QUESTION SECTION: | ||
+ | ;. IN NS | ||
+ | |||
+ | ;; ANSWER SECTION: | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | . | ||
+ | |||
+ | ;; ADDITIONAL SECTION: | ||
+ | a.root-servers.net. | ||
+ | a.root-servers.net. | ||
+ | b.root-servers.net. | ||
+ | b.root-servers.net. | ||
+ | c.root-servers.net. | ||
+ | c.root-servers.net. | ||
+ | d.root-servers.net. | ||
+ | d.root-servers.net. | ||
+ | e.root-servers.net. | ||
+ | e.root-servers.net. | ||
+ | f.root-servers.net. | ||
+ | f.root-servers.net. | ||
+ | g.root-servers.net. | ||
+ | g.root-servers.net. | ||
+ | h.root-servers.net. | ||
+ | h.root-servers.net. | ||
+ | i.root-servers.net. | ||
+ | i.root-servers.net. | ||
+ | j.root-servers.net. | ||
+ | j.root-servers.net. | ||
+ | k.root-servers.net. | ||
+ | k.root-servers.net. | ||
+ | l.root-servers.net. | ||
+ | l.root-servers.net. | ||
+ | m.root-servers.net. | ||
+ | m.root-servers.net. | ||
+ | |||
+ | ;; Query time: 18 msec | ||
+ | ;; SERVER: 198.41.0.4# | ||
+ | ;; WHEN: Po kv? 22 10:14:44 CEST 2017 | ||
+ | ;; MSG SIZE rcvd: 811 | ||
+ | </ | ||
+ | |||
+ | \\ | ||
+ | ===== / | ||
+ | |||
+ | <sxh bash toolbar: | ||
+ | $ORIGIN . | ||
+ | $TTL 0 ; 0 seconds | ||
+ | @ IN SOA . . ( | ||
+ | 2 ; serial | ||
+ | 0 ; refresh (0 seconds) | ||
+ | 0 ; retry (0 seconds) | ||
+ | 0 ; expire (0 seconds) | ||
+ | 0 ; minimum (0 seconds) | ||
+ | ) | ||
+ | KEYDATA 20180208144048 20180207144048 19700101000000 257 3 8 ( | ||
+ | AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQ | ||
+ | bSEW0O8gcCjFFVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh | ||
+ | / | ||
+ | JQ9VnMVDxP/ | ||
+ | oY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3 | ||
+ | LQpzW5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGO | ||
+ | Yl7OyQdXfZ57relSQageu+ipAdTTJ25AsRTAoub8ONGc | ||
+ | LmqrAmRLKBP1dfwhYB4N7knNnulqQxA+Uk1ihz0= | ||
+ | ) ; KSK; alg = RSASHA256; key id = 19036 | ||
+ | KEYDATA 20180208144048 20180207144048 19700101000000 257 3 8 ( | ||
+ | AwEAAaz/ | ||
+ | iW1vkIbzxeF3+/ | ||
+ | 7SWXgnLh4+B5xQlNVz8Og8kvArMtNROxVQuCaSnIDdD5 | ||
+ | LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF0jLHwVN8 | ||
+ | efS3rCj/ | ||
+ | pr+eoZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLY | ||
+ | A4/ | ||
+ | 9555KrUB5qihylGa8subX2Nn6UwNR1AkUTV74bU= | ||
+ | ) ; KSK; alg = RSASHA256; key id = 20326 | ||
+ | </ | ||
My Sites
SNS
Copyright (c) 2025 FastHandle - IT Operations Examples All Rights Reserved.