Named: Difference between revisions

From Leo's Notes
This page was last edited on 24 February 2017, at 19:14.
m Text replacement - "<code>" to "{{code|"
m Text replacement - "</code>" to "}}"
Line 2: Line 2:


== Enable Query Logging ==
== Enable Query Logging ==
Use {{code|rndc</code> to enable query logging:
Use {{code|rndc}} to enable query logging:
  rndc querylog on
  rndc querylog on


Lookups will then be dumped into {{code|/var/log/messages</code>
Lookups will then be dumped into {{code|/var/log/messages}}


To see whether rndc querylog is enabled, run:
To see whether rndc querylog is enabled, run:
Line 43: Line 43:
</syntaxhighlight>
</syntaxhighlight>


Since I don't have IPv6 on my network, it's obvious why I can't look up addresses using IPv6. To fix this on a RedHat based system, edit the config in {{code|/etc/sysconfig/named</code> do:
Since I don't have IPv6 on my network, it's obvious why I can't look up addresses using IPv6. To fix this on a RedHat based system, edit the config in {{code|/etc/sysconfig/named}} do:


<syntaxhighlight lang="bash" line start="1" enclose="div">
<syntaxhighlight lang="bash" line start="1" enclose="div">
Line 52: Line 52:
== Creating 'zones' via Views ==
== Creating 'zones' via Views ==


If you want to provide a set of IP addresses or subnets with a specific set of zones, use {{code|view</code>s to accomplish this. The basic syntax for a view is:
If you want to provide a set of IP addresses or subnets with a specific set of zones, use {{code|view}}s to accomplish this. The basic syntax for a view is:


<syntaxhighlight lang="text">
<syntaxhighlight lang="text">
Line 62: Line 62:
</syntaxhighlight>
</syntaxhighlight>


You may also use {{code|acl</code> to group multiple subnets into one 'client'.
You may also use {{code|acl}} to group multiple subnets into one 'client'.




Line 75: Line 75:
</syntaxhighlight>
</syntaxhighlight>


To have one specific IP address inside another view instead, use the {{code|!</code> operator in either the ACL definition list or the {{code|match-clients</code> list.
To have one specific IP address inside another view instead, use the {{code|!}} operator in either the ACL definition list or the {{code|match-clients}} list.


<syntaxhighlight lang="text">
<syntaxhighlight lang="text">

Revision as of 19:14, 24 February 2017

This article will go over some features in the BIND DNS service.

Enable Query Logging

Use rndc to enable query logging:

rndc querylog on

Lookups will then be dumped into /var/log/messages

To see whether rndc querylog is enabled, run:

rndc status
 ...
 query logging is ON
 ...
 server is up and running

This will be turned off whenever the service restarts. To enable logging by default, edit /etc/named.conf with:

logging {
        channel "querylog" {
                file "/var/log/named-query.log";
                print-time yes;
        };
        category queries { querylog; };
};

Disable IPv6 Lookups

If you have querylog enabled, you may see lots of messages like:

May  5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns2.google.com/A/IN': 2001:503:231d::2:30#53
May  5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns2.google.com/AAAA/IN': 2001:503:231d::2:30#53
May  5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns3.google.com/A/IN': 2001:503:231d::2:30#53
May  5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns4.google.com/A/IN': 2001:503:231d::2:30#53
May  5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns3.google.com/AAAA/IN': 2001:503:231d::2:30#53
May  5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns1.google.com/A/IN': 2001:503:231d::2:30#53
May  5 12:14:57 linux named[2492]: error (network unreachable) resolving 'ns2.p42.dynect.net/A/IN': 2001:500:3::42#53

Since I don't have IPv6 on my network, it's obvious why I can't look up addresses using IPv6. To fix this on a RedHat based system, edit the config in /etc/sysconfig/named do:

vi /etc/sysconfig/named
 OPTIONS="-4"

Creating 'zones' via Views

If you want to provide a set of IP addresses or subnets with a specific set of zones, use views to accomplish this. The basic syntax for a view is:

view "NetworkAB" {
	match-clients { subnetA; subnetB; };

	# Zones go here
};

You may also use acl to group multiple subnets into one 'client'.


acl subnetAB { subnetA; subnetB; };

view "NetworkAB" {
	match-clients { subnetAB; };

	# Zones go here
};

To have one specific IP address inside another view instead, use the ! operator in either the ACL definition list or the match-clients list.

acl subnetAB { ! leosIPInSubnetA/32; subnetA; subnetB; };
acl subnetLeo { leosIPInSubnetA/32; };

view "NetworkAB" {
	match-clients { subnetAB; };

	# Zones go here
};

view "LeosView" {
	match-clients { subnetLeo; };

	# Zones only Leo can see can go here
}