Differences between revisions 15 and 49 (spanning 34 versions)
Revision 15 as of 2017-12-09 08:40:03
Size: 1749
Comment:
Revision 49 as of 2017-12-13 09:51:00
Size: 923
Comment:
Deletions are marked like this. Additions are marked like this.
Line 7: Line 7:
= DNS Master = In this setup we use the following IP-addresses for the master and slave:
Line 9: Line 9:
== Network ==  * 192.168.1.34 master
 * 192.168.1.35 slave
Line 11: Line 12:
Since looking up the DNS servers IP-address does not make any sense, we will give the DNS server a statc IP-address. Edit `/etc/networking/interfaces` and make the following changes. Configure the [[DNS Master|master]], then the [[DNS Slave|slave]].
Line 13: Line 14:
{{{
# The primary network interface
#allow-hotplug eth0
#iface eth0 inet dhcp
== Maintenance ==
Line 18: Line 16:
auto eth0
iface eth0 inet static
        address 192.168.1.34
        netmask 255.255.255.0
        gateway 192.168.1.1
        network 192.168.1.0
        gateway 192.168.1.1
}}}
=== DNS changes ===
Line 27: Line 18:
== Install BIND ==

{{{
apt-get install bind9
}}}

== Configure BIND ==

=== Make a DDNS update key ===

We are going to let the DHCP server update BIND. For this we need an update key. Create it with the following command.

{{{#!highlight bash
#!/bin/bash
# entrophy must be available for the key to be generated
# check available entrophy
# /proc/sys/kernel/random/entropy_avail
dnssec-keygen -a HMAC-MD5 -b 512 -n HOST ddns-update
}}}

=== Make BIND listen ===

edit `/etc/bind/named.conf.options` and add

{{{
listen-on { any; };
}}}

=== Create a new zone ===

`/etc/bind/named.conf.kallenberg.dk`
{{{
}}}

Add the new zone file to `/etc/bind/named.conf.local`

{{{
include "/etc/bind/named.conf.kallenberg.dk";
}}}


= DNS Slave =
Once both servers are configured, it is vital to stop making changes to the zone files by hand. From now on manual [[DNS Updates|DNS updates]] has to be made with the `nsupdate` utility using the update key.

DNS

The Domain Name System is really a must for any TCIP/IP network. It is a key component of the network. That is why it is the first service we will configure.

Here we will be using Bind, ISC's DNS server. Bind has a master/slave configuration, where the master gets the DNS changes and then updates the slave. It cannot run truly redundant, in the sense that only the master is allowed to get DNS changes, if the master is down, the slave cannot be updated.

In this setup we use the following IP-addresses for the master and slave:

  • 192.168.1.34 master
  • 192.168.1.35 slave

Configure the master, then the slave.

Maintenance

DNS changes

Once both servers are configured, it is vital to stop making changes to the zone files by hand. From now on manual DNS updates has to be made with the nsupdate utility using the update key.

None: DNS (last edited 2021-01-17 20:10:16 by Kristian Kallenberg)