Named: Difference between revisions
No edit summary |
m Text replacement - "<code>" to "{{code|" |
||
| Line 2: | Line 2: | ||
== Enable Query Logging == | == Enable Query Logging == | ||
Use | Use {{code|rndc</code> to enable query logging: | ||
rndc querylog on | rndc querylog on | ||
Lookups will then be dumped into | Lookups will then be dumped into {{code|/var/log/messages</code> | ||
To see whether rndc querylog is enabled, run: | To see whether rndc querylog is enabled, run: | ||
| Line 43: | Line 43: | ||
</syntaxhighlight> | </syntaxhighlight> | ||
Since I don't have IPv6 on my network, it's obvious why I can't look up addresses using IPv6. To fix this on a RedHat based system, edit the config in | Since I don't have IPv6 on my network, it's obvious why I can't look up addresses using IPv6. To fix this on a RedHat based system, edit the config in {{code|/etc/sysconfig/named</code> do: | ||
<syntaxhighlight lang="bash" line start="1" enclose="div"> | <syntaxhighlight lang="bash" line start="1" enclose="div"> | ||
| Line 52: | Line 52: | ||
== Creating 'zones' via Views == | == Creating 'zones' via Views == | ||
If you want to provide a set of IP addresses or subnets with a specific set of zones, use | If you want to provide a set of IP addresses or subnets with a specific set of zones, use {{code|view</code>s to accomplish this. The basic syntax for a view is: | ||
<syntaxhighlight lang="text"> | <syntaxhighlight lang="text"> | ||
| Line 62: | Line 62: | ||
</syntaxhighlight> | </syntaxhighlight> | ||
You may also use | You may also use {{code|acl</code> to group multiple subnets into one 'client'. | ||
| Line 75: | Line 75: | ||
</syntaxhighlight> | </syntaxhighlight> | ||
To have one specific IP address inside another view instead, use the | To have one specific IP address inside another view instead, use the {{code|!</code> operator in either the ACL definition list or the {{code|match-clients</code> list. | ||
<syntaxhighlight lang="text"> | <syntaxhighlight lang="text"> | ||
Revision as of 19:13, 24 February 2017
This article will go over some features in the BIND DNS service.
Enable Query Logging
Use {{code|rndc to enable query logging:
rndc querylog on
Lookups will then be dumped into {{code|/var/log/messages
To see whether rndc querylog is enabled, run:
rndc status
...
query logging is ON
...
server is up and running
This will be turned off whenever the service restarts. To enable logging by default, edit /etc/named.conf with:
logging {
channel "querylog" {
file "/var/log/named-query.log";
print-time yes;
};
category queries { querylog; };
};
Disable IPv6 Lookups
If you have querylog enabled, you may see lots of messages like:
May 5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns2.google.com/A/IN': 2001:503:231d::2:30#53
May 5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns2.google.com/AAAA/IN': 2001:503:231d::2:30#53
May 5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns3.google.com/A/IN': 2001:503:231d::2:30#53
May 5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns4.google.com/A/IN': 2001:503:231d::2:30#53
May 5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns3.google.com/AAAA/IN': 2001:503:231d::2:30#53
May 5 12:14:44 linux named[2492]: error (network unreachable) resolving 'ns1.google.com/A/IN': 2001:503:231d::2:30#53
May 5 12:14:57 linux named[2492]: error (network unreachable) resolving 'ns2.p42.dynect.net/A/IN': 2001:500:3::42#53
Since I don't have IPv6 on my network, it's obvious why I can't look up addresses using IPv6. To fix this on a RedHat based system, edit the config in {{code|/etc/sysconfig/named do:
vi /etc/sysconfig/named
OPTIONS="-4"
Creating 'zones' via Views
If you want to provide a set of IP addresses or subnets with a specific set of zones, use {{code|views to accomplish this. The basic syntax for a view is:
view "NetworkAB" {
match-clients { subnetA; subnetB; };
# Zones go here
};
You may also use {{code|acl to group multiple subnets into one 'client'.
acl subnetAB { subnetA; subnetB; };
view "NetworkAB" {
match-clients { subnetAB; };
# Zones go here
};
To have one specific IP address inside another view instead, use the {{code|! operator in either the ACL definition list or the {{code|match-clients list.
acl subnetAB { ! leosIPInSubnetA/32; subnetA; subnetB; };
acl subnetLeo { leosIPInSubnetA/32; };
view "NetworkAB" {
match-clients { subnetAB; };
# Zones go here
};
view "LeosView" {
match-clients { subnetLeo; };
# Zones only Leo can see can go here
}
| ||||||