/* - If you are building an AUTHORITATIVE DNS server, do NOT enable recursion. - If you are building a RECURSIVE (caching) DNS server, you need to enable recursion. - If your recursive DNS server has a public IP address, you MUST enable access control to limit queries to your legitimate users. Failing to do so will cause your server to become part of large scale DNS amplification attacks. Implementing BCP38 within your network would greatly reduce such attack surface */ recursion yes;
include "/etc/named.rfc1912.zones"; include "/etc/named.root.key";
增加zone信息 vim /etc/named.rfc1912.zones zone "baidu.com" IN { # 定义要解析主域名 type master; file "baidu.com.zone"; # 具体相关解析的配置文件保存在 /var/named/baidu.com.zone 文件中 };
编辑区域配置文件 vim /var/named/baidu.com.zone
$TTL 1D @ IN SOA baidu.com. root ( 1 ; serial 1D ; refresh 1H ; retry 1W ; expire 0 ) ; minimum
IN NS baidu.com. IN A 192.168.101.1 www IN A 192.168.101.244 test IN A 192.168.101.129
增加权限 并启动服务
chown root:named test.com.zone systemctl start named systemctl enable named