Re: Correct configuration



On Thursday 08 July 2010 8:41:19 am Dimitri
Yioulos wrote:
Hello to all.

I have recently set up a slave DNS server
(bind-9.3.6) on a CentOS 5.x Linux box. The
master is our Windows server and, really, it
directly serves our AD infrastructure, and
forwards external queries to our ISP''s DNS
servers.

I got the basic set-up correct, I believe.
However, yesterday I pushed the envelope a bit.
I want to make sure that, in the temporary
absence of the master, that the slave does the
forwarding to the ISP, but that it only servers
our company (i.e. is not accessible
externally). Here's my named.conf file:


Options {
directory "/var/named"; //Working
directory forwarders {
65.x.1.x;
65.x.7.x;
};
forward only;
version "not currently available";
allow-recursion {192.168.100.0/22;};
};

//Zone entry for my Active Directory domain.
zone "mydomain.com" IN {
type slave;
file "slaves/db.ad.mydomain.com";
masters { 192.168.100.3;};
allow-notify {none;};
forwarders {};
};

// reverse map for class C 192.168.100.0
zone "100.168.192.IN-ADDR.ARPA" IN {
type slave;
file "slaves/db.ad.192.168.100.rev";
masters {192.168.100.3;};
allow-notify {none;};
forwarders {};
};

include "/etc/rndc.key";

logging {
channel log {
file "/var/log/named/bind.log" versions 3
size 5m;
severity info;
print-time yes;
print-severity yes;
print-category yes;
};
category default{ log; };
category statistics { log; };
category queries { log; };
};


Is this correct and secure?

Many thanks.

Dimitri


Anyone?

Dimitri

--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.

.



Relevant Pages

  • Re: Replikations Frage
    ... vom Master auf den Slave kopiert hast und dabei die Permissions auf ... Die Datenbanken auf den Slave Server laufen ohne Probleme. ... # If you want to know which options a program support, ...
    (de.comp.datenbanken.mysql)
  • Correct configuration
    ... I have recently set up a slave DNS server ... absence of the master, ... forwarders; ...
    (comp.protocols.dns.bind)
  • Re: Database locking during kprops, MIT 1.8
    ... condition on the slave server itself. ... Since the switch, we've only seen 1 update failure. ... On the master server, a cron job runs ... And a slightly more complicated one that runs on each slave (currently every 30 ...
    (comp.protocols.kerberos)
  • Using Master as Slave at the same time
    ... The second is configured as Slave using ip 123.123.123.2 ... each server and use the second IP on the master as a slave. ... So, on the Master we added 123.123.123.3, and on the slave we added ... In the slave-DNS we added a new zone as primary-zone with the secondary ip ...
    (microsoft.public.windows.server.dns)
  • Re: SMB Browser Election Thread (Was: Case for an occasional system refresh or clean install)
    ... My Samba experiences are quite old, ... master, and it usually always would be (could be messed up if I ever had ... someone bring a Windows 2000 server to the LAN). ... ## Tim: I am the master... ...
    (Fedora)