{"id":292585,"date":"2019-07-25T21:00:53","date_gmt":"2019-07-25T21:00:53","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=292585"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=292585","title":{"rendered":"\u041f\u043e\u0448\u0430\u0433\u043e\u0432\u043e\u0435 \u0440\u0443\u043a\u043e\u0432\u043e\u0434\u0441\u0442\u0432\u043e \u043f\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 BIND \u0432 chroot \u0441\u0440\u0435\u0434\u0435 \u0434\u043b\u044f Red Hat (RHEL \/ CentOS) 7"},"content":{"rendered":"\n<div class=\"post__text post__text-html js-mediator-article\">\n<p><em>\u041f\u0435\u0440\u0435\u0432\u043e\u0434 \u0441\u0442\u0430\u0442\u044c\u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d \u0434\u043b\u044f \u0441\u0442\u0443\u0434\u0435\u043d\u0442\u043e\u0432 \u043a\u0443\u0440\u0441\u0430 <a href=\"https:\/\/otus.pw\/U1cp\/\">\u00ab\u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c Linux\u00bb<\/a>. \u0418\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u043e \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u0434\u0430\u043d\u043d\u043e\u043c \u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0438? \u0421\u043c\u043e\u0442\u0440\u0438\u0442\u0435 \u0437\u0430\u043f\u0438\u0441\u044c \u0442\u0440\u0430\u043d\u0441\u043b\u044f\u0446\u0438\u0438 \u043c\u0430\u0441\u0442\u0435\u0440-\u043a\u043b\u0430\u0441\u0441\u0430 \u0418\u0432\u0430\u043d\u0430 \u041f\u0438\u0441\u043a\u0443\u043d\u043e\u0432\u0430 <a href=\"https:\/\/otus.pw\/6yM3\/\">\u00ab\u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c \u0432 Linux \u0432 \u0441\u0440\u0430\u0432\u043d\u0435\u043d\u0438\u0438 \u0441 Windows \u0438 MacOS\u00bb<\/a><\/em><\/p>\n<p>  <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/ej\/jd\/rm\/ejjdrmoz6mrcllqotaz_0ym9pao.png\"><\/p>\n<p>  <\/p>\n<p>\u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044f \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043e \u0448\u0430\u0433\u0430\u0445 \u043f\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043d\u0430 RHEL 7 \u0438\u043b\u0438 CentOS 7. \u0414\u043b\u044f \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b Red Hat Enterprise Linux 7.4. \u041d\u0430\u0448\u0430 \u0446\u0435\u043b\u044c \u2014 \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043e\u0434\u043d\u0443 A-\u0437\u0430\u043f\u0438\u0441\u044c \u0438 \u043e\u0434\u043d\u0443 PTR-\u0437\u0430\u043f\u0438\u0441\u044c \u0434\u043b\u044f \u0437\u043e\u043d\u044b \u043f\u0440\u044f\u043c\u043e\u0433\u043e \u0438 \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u043c\u043e\u0442\u0440\u0430 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e.<\/p>\n<p><a name=\"habracut\"><\/a>  <\/p>\n<p>\u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u0435 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u0435 rpm-\u043f\u0430\u043a\u0435\u0442\u044b \u0434\u043b\u044f DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430.<\/p>\n<p>  <\/p>\n<p><em>\u041f\u0420\u0418\u041c\u0415\u0427\u0410\u041d\u0418\u0415: \u0414\u043b\u044f RHEL \u0443 \u0432\u0430\u0441 \u0434\u043e\u043b\u0436\u043d\u0430 \u0431\u044b\u0442\u044c <a href=\"https:\/\/www.golinuxcloud.com\/register-rhel-7-attach-subscription-manager\/\">\u0430\u043a\u0442\u0438\u0432\u043d\u0430\u044f \u043f\u043e\u0434\u043f\u0438\u0441\u043a\u0430 \u043d\u0430 RHN<\/a>, \u0438\u043b\u0438 \u0432\u044b \u043c\u043e\u0436\u0435\u0442\u0435 <a href=\"https:\/\/www.golinuxcloud.com\/there-are-no-enabled-repos-yum-dnf-rhel-7-8\/\">\u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u0439 \u0430\u0432\u0442\u043e\u043d\u043e\u043c\u043d\u044b\u0439 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0439<\/a>, \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u00abyum\u00bb \u0441\u043c\u043e\u0436\u0435\u0442 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u0435 rpm-\u043f\u0430\u043a\u0435\u0442\u044b \u0438 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438.<\/em><\/p>\n<p>  <\/p>\n<pre><code class=\"bash\"># yum install bind bind-chroot caching-nameserver<\/code><\/pre>\n<p>  <\/p>\n<p>\u041c\u043e\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438:<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\"># hostname golinuxhub-client.example \u041c\u043e\u0439 IP-\u0430\u0434\u0440\u0435\u0441 192.168.1.7 # ip address | egrep 'inet.*enp0s3'     inet 192.168.1.7\/24 brd 192.168.1.255 scope global dynamic enp0s3<\/code><\/pre>\n<p>  <\/p>\n<p>\u041f\u043e\u0441\u043a\u043e\u043b\u044c\u043a\u0443 \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c chroot, \u043d\u0443\u0436\u043d\u043e \u043e\u0442\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0441\u043b\u0443\u0436\u0431\u0443.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\"># systemctl stop named # systemctl disable named<\/code><\/pre>\n<p>  <\/p>\n<p>\u0417\u0430\u0442\u0435\u043c \u0441\u043a\u043e\u043f\u0438\u0440\u0443\u0439\u0442\u0435 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u0435 \u0444\u0430\u0439\u043b\u044b \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433 chroot.<br \/>  \u041f\u0420\u0418\u041c\u0415\u0427\u0410\u041d\u0418\u0415. \u0418\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0439\u0442\u0435 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442 <em>-p<\/em> \u0432 \u043a\u043e\u043c\u0430\u043d\u0434\u0435 <em>cp<\/em> \u0434\u043b\u044f \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u0430\u0432 \u0438 \u0432\u043b\u0430\u0434\u0435\u043b\u044c\u0446\u0435\u0432.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client ~]# cp -rpvf \/usr\/share\/doc\/bind-9.9.4\/sample\/etc\/*  \/var\/named\/chroot\/etc\/ \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/etc\/named.conf\u2019 -&gt; \u2018\/var\/named\/chroot\/etc\/named.conf\u2019 \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/etc\/named.rfc1912.zones\u2019 -&gt; \u2018\/var\/named\/chroot\/etc\/named.rfc1912.zones\u2019<\/code><\/pre>\n<p>  <\/p>\n<p>\u0417\u0430\u0442\u0435\u043c \u0441\u043a\u043e\u043f\u0438\u0440\u0443\u0439\u0442\u0435 \u0444\u0430\u0439\u043b\u044b, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 \u0437\u043e\u043d\u043e\u0439, \u0432 \u043d\u043e\u0432\u043e\u0435 \u043c\u0435\u0441\u0442\u043e.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client ~]# cp -rpvf \/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/* \/var\/named\/chroot\/var\/named\/ \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/data\u2019 -&gt; \u2018\/var\/named\/chroot\/var\/named\/data\u2019 \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/my.external.zone.db\u2019 -&gt; \u2018\/var\/named\/chroot\/var\/named\/my.external.zone.db\u2019 \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/my.internal.zone.db\u2019 -&gt; \u2018\/var\/named\/chroot\/var\/named\/my.internal.zone.db\u2019 \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/named.ca\u2019 -&gt; \u2018\/var\/named\/chroot\/var\/named\/named.ca\u2019 \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/named.empty\u2019 -&gt; \u2018\/var\/named\/chroot\/var\/named\/named.empty\u2019 \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/named.localhost\u2019 -&gt; \u2018\/var\/named\/chroot\/var\/named\/named.localhost\u2019 \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/named.loopback\u2019 -&gt; \u2018\/var\/named\/chroot\/var\/named\/named.loopback\u2019 \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/slaves\u2019 -&gt; \u2018\/var\/named\/chroot\/var\/named\/slaves\u2019 \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/slaves\/my.ddns.internal.zone.db\u2019 -&gt; \u2018\/var\/named\/chroot\/var\/named\/slaves\/my.ddns.internal.zone.db\u2019 \u2018\/usr\/share\/doc\/bind-9.9.4\/sample\/var\/named\/slaves\/my.slave.internal.zone.db\u2019 -&gt; \u2018\/var\/named\/chroot\/var\/named\/slaves\/my.slave.internal.zone.db\u2019 ```bash \u0422\u0435\u043f\u0435\u0440\u044c \u0434\u0430\u0432\u0430\u0439\u0442\u0435 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0444\u0430\u0439\u043b \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438. ```bash # cd \/var\/named\/chroot\/etc\/<\/code><\/pre>\n<p>  <\/p>\n<p>\u041e\u0447\u0438\u0441\u0442\u0438\u0442\u0435 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 named.conf \u0438 \u0432\u0441\u0442\u0430\u0432\u044c\u0442\u0435 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client etc]# vim named.conf options {         listen-on port 53 { 127.0.0.1; any; }; #       listen-on-v6 port 53 { ::1; };         directory       \"\/var\/named\";         dump-file       \"\/var\/named\/data\/cache_dump.db\";         statistics-file \"\/var\/named\/data\/named_stats.txt\";         memstatistics-file \"\/var\/named\/data\/named_mem_stats.txt\";         allow-query     { localhost; any; };         allow-query-cache { localhost; any; }; };  logging {         channel default_debug {                 file \"data\/named.run\";                 severity dynamic;         }; };  view my_resolver {         match-clients      { localhost; any; };         recursion yes;         include \"\/etc\/named.rfc1912.zones\"; };<\/code><\/pre>\n<p>  <\/p>\n<p>\u0418\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f, \u043e\u0442\u043d\u043e\u0441\u044f\u0449\u0430\u044f\u0441\u044f \u043a \u0437\u043e\u043d\u0435, \u0434\u043e\u043b\u0436\u043d\u0430 \u0431\u044b\u0442\u044c \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0430 \u0432 <em>\/var\/named\/chroot\/etc\/named.rfc1912.zones<\/em>. \u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0437\u0430\u043f\u0438\u0441\u0438, \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d\u043d\u044b\u0435 \u043d\u0438\u0436\u0435. \u0424\u0430\u0439\u043b example.zone \u2014 \u044d\u0442\u043e \u0444\u0430\u0439\u043b \u0437\u043e\u043d\u044b \u043f\u0440\u044f\u043c\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u043c\u043e\u0442\u0440\u0430, \u0430 <em>example.rzone<\/em> \u2014 \u0444\u0430\u0439\u043b \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0439 \u0437\u043e\u043d\u044b.<br \/>  <strong>\u0412\u0410\u0416\u041d\u041e\u0415 \u041f\u0420\u0418\u041c\u0415\u0427\u0410\u041d\u0418\u0415: \u0417\u043e\u043d\u0430 \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u043c\u043e\u0442\u0440\u0430 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u0442 1.168.192, \u043f\u043e\u0441\u043a\u043e\u043b\u044c\u043a\u0443 \u043c\u043e\u0439 IP-\u0430\u0434\u0440\u0435\u0441 192.168.1.7<\/strong><\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">zone \"example\" IN {         type master;         file \"example.zone\";         allow-update { none; }; };  zone \"1.168.192.in-addr.arpa\" IN {         type master;         file \"example.rzone\";         allow-update { none; }; };<\/code><\/pre>\n<p>  <\/p>\n<p>\u0424\u0430\u0439\u043b\u044b, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 \u0437\u043e\u043d\u0430\u043c\u0438, \u043d\u0430\u0445\u043e\u0434\u044f\u0442\u0441\u044f \u0437\u0434\u0435\u0441\u044c:<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\"># cd \/var\/named\/chroot\/var\/named\/<\/code><\/pre>\n<p>  <\/p>\n<p>\u0414\u0430\u043b\u0435\u0435 \u0441\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0444\u0430\u0439\u043b\u044b \u0434\u043b\u044f \u043f\u0440\u044f\u043c\u043e\u0439 \u0438 \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0439 \u0437\u043e\u043d\u044b. \u0418\u043c\u0435\u043d\u0430 \u0444\u0430\u0439\u043b\u043e\u0432 \u0431\u0443\u0434\u0443\u0442 \u0442\u0430\u043a\u0438\u043c\u0438 \u0436\u0435, \u043a\u0430\u043a \u0432\u044b\u0448\u0435 \u0432 \u0444\u0430\u0439\u043b\u0435 <em>named.rfc1912.zones<\/em>. \u0423 \u043d\u0430\u0441 \u0443\u0436\u0435 \u0435\u0441\u0442\u044c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0448\u0430\u0431\u043b\u043e\u043d\u043e\u0432 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u044b \u043c\u043e\u0436\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\"># cp -p named.localhost  example.zone # cp -p named.loopback example.rzone<\/code><\/pre>\n<p>  <\/p>\n<p>\u041a\u0430\u043a \u0432\u0438\u0434\u0438\u0442\u0435, \u0442\u0435\u043a\u0443\u0449\u0438\u0435 \u0440\u0430\u0437\u0440\u0435\u0448\u0435\u043d\u0438\u044f \u043d\u0430 \u0432\u0441\u0435 \u0444\u0430\u0439\u043b\u044b \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0438 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0442 <em>root<\/em>.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client named]# ll total 32 drwxr-xr-x. 2 root root    6 May 22  2017 data -rw-r--r--. 1 root root  168 May 22  2017 example.rzone -rw-r--r--. 1 root root  152 May 22  2017 example.zone -rw-r--r--. 1 root root   56 May 22  2017 my.external.zone.db -rw-r--r--. 1 root root   56 May 22  2017 my.internal.zone.db -rw-r--r--. 1 root root 2281 May 22  2017 named.ca -rw-r--r--. 1 root root  152 May 22  2017 named.empty -rw-r--r--. 1 root root  152 May 22  2017 named.localhost -rw-r--r--. 1 root root  168 May 22  2017 named.loopback drwxr-xr-x. 2 root root   71 Feb 12 21:02 slaves<\/code><\/pre>\n<p>  <\/p>\n<p>\u0418\u0437\u043c\u0435\u043d\u0438\u0442\u0435 \u043f\u0440\u0430\u0432\u0430 \u0432\u0441\u0435\u0445 \u0444\u0430\u0439\u043b\u043e\u0432, \u0443\u043a\u0430\u0437\u0430\u0432 \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0432\u043b\u0430\u0434\u0435\u043b\u044c\u0446\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f <em>root<\/em> \u0438 \u0433\u0440\u0443\u043f\u043f\u0443 <em>named<\/em>.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\"># chown root:named *<\/code><\/pre>\n<p>  <\/p>\n<p>\u041d\u043e \u0434\u043b\u044f data \u0432\u043b\u0430\u0434\u0435\u043b\u0435\u0446 \u0434\u043e\u043b\u0436\u0435\u043d \u0431\u044b\u0442\u044c <em>named:named<\/em>.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\"># chown -R  named:named data # ls -l total 32 drwxr-xr-x. 2 named named    6 May 22  2017 data -rw-r--r--. 1 root  named  168 May 22  2017 example.rzone -rw-r--r--. 1 root  named  152 May 22  2017 example.zone -rw-r--r--. 1 root  named   56 May 22  2017 my.external.zone.db -rw-r--r--. 1 root  named   56 May 22  2017 my.internal.zone.db -rw-r--r--. 1 root  named 2281 May 22  2017 named.ca -rw-r--r--. 1 root  named  152 May 22  2017 named.empty -rw-r--r--. 1 root  named  152 May 22  2017 named.localhost -rw-r--r--. 1 root  named  168 May 22  2017 named.loopback drwxr-xr-x. 2 root  named   71 Feb 12 21:02 slaves<\/code><\/pre>\n<p>  <\/p>\n<p>\u0414\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d\u043d\u043e\u0435 \u043d\u0438\u0436\u0435 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0432 \u0444\u0430\u0439\u043b \u043f\u0440\u044f\u043c\u043e\u0439 \u0437\u043e\u043d\u044b. \u0417\u0434\u0435\u0441\u044c \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u0435\u043c A-\u0437\u0430\u043f\u0438\u0441\u044c \u0434\u043b\u044f localhost (golinuxhub-client) \u0438 \u0435\u0449\u0435 \u043e\u0434\u043d\u0443 \u0434\u043b\u044f \u0441\u0435\u0440\u0432\u0435\u0440\u0430 (golinuxhub-server).<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\"># vim example.zone $TTL 1D @       IN SOA  example. root (                                         1       ; serial                                         3H      ; refresh                                         15M     ; retry                                         1W      ; expire                                         1D )    ; minimum                  IN NS           example.                          IN A 192.168.1.7 golinuxhub-server       IN A 192.168.1.5 golinuxhub-client       IN A 192.169.1.7<\/code><\/pre>\n<p>  <\/p>\n<p>\u0414\u0430\u043b\u0435\u0435 \u0434\u043e\u0431\u0430\u0432\u044c\u0442\u0435 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0432 \u0444\u0430\u0439\u043b \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0439 \u0437\u043e\u043d\u044b. \u0417\u0434\u0435\u0441\u044c \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u0435\u043c PTR-\u0437\u0430\u043f\u0438\u0441\u044c \u0434\u043b\u044f golinuxhub-client \u0438 \u0434\u043b\u044f \u0441\u0435\u0440\u0432\u0435\u0440\u0430 golinuxhub-server.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\"># vim example.rzone $TTL 1D @       IN SOA  example. root.example. (                                         1997022700      ; serial                                         28800           ; refresh                                         14400           ; retry                                         3600000         ; expire                                         86400  )        ; minimum          IN NS   example. 5       IN PTR  golinuxhub-server.example. 7       IN PTR  golinuxhub-client.example.<\/code><\/pre>\n<p>  <\/p>\n<p>\u041f\u0440\u0435\u0436\u0434\u0435 \u0447\u0435\u043c \u043c\u044b \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043c \u0441\u0435\u0440\u0432\u0438\u0441 <em>named-chroot<\/em>, \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u043c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044e \u0444\u0430\u0439\u043b\u0430 \u0437\u043e\u043d\u044b.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client named]# named-checkzone golinuxhub-client.example example.zone zone golinuxhub-client.example\/IN: loaded serial 1 OK  [root@golinuxhub-client named]# named-checkzone golinuxhub-client.example example.rzone zone golinuxhub-client.example\/IN: loaded serial 1997022700 OK<\/code><\/pre>\n<p>  <\/p>\n<p>\u0412\u0441\u0435 \u0432\u044b\u0433\u043b\u044f\u0434\u0438\u0442 \u0445\u043e\u0440\u043e\u0448\u043e. \u0422\u0435\u043f\u0435\u0440\u044c \u043f\u0440\u043e\u0432\u0435\u0440\u044c\u0442\u0435 \u0444\u0430\u0439\u043b \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0443\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u0443.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client named]# named-checkconf -t \/var\/named\/chroot\/ \/etc\/named.conf<\/code><\/pre>\n<p>  <\/p>\n<p>\u0418\u0442\u0430\u043a, \u0432\u0441\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u043e \u0443\u0441\u043f\u0435\u0448\u043d\u043e.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client named]# echo $? 0<\/code><\/pre>\n<p>  <\/p>\n<p><em>\u0412\u0410\u0416\u041d\u041e\u0415 \u041f\u0420\u0418\u041c\u0415\u0427\u0410\u041d\u0418\u0415: \u0443 \u043c\u0435\u043d\u044f SELinux \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 permissive<\/em><\/p>\n<p>  <\/p>\n<pre><code class=\"bash\"># getenforce Permissive<\/code><\/pre>\n<p>  <\/p>\n<p>\u0412\u0441\u0435 \u0432\u044b\u0433\u043b\u044f\u0434\u0438\u0442 \u0445\u043e\u0440\u043e\u0448\u043e, \u0442\u0430\u043a \u0447\u0442\u043e \u043f\u043e\u0440\u0430 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043d\u0430\u0448 \u0441\u0435\u0440\u0432\u0438\u0441 <em>named-chroot<\/em> .<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client named]# systemctl restart named-chroot<\/code><\/pre>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client named]# systemctl status named-chroot \u25cf named-chroot.service - Berkeley Internet Name Domain (DNS)    Loaded: loaded (\/usr\/lib\/systemd\/system\/named-chroot.service; disabled; vendor preset: disabled)    Active: active (running) since Mon 2018-02-12 21:53:23 IST; 19s ago   Process: 5236 ExecStop=\/bin\/sh -c \/usr\/sbin\/rndc stop &gt; \/dev\/null 2&gt;&amp;1 || \/bin\/kill -TERM $MAINPID (code=exited, status=0\/SUCCESS)   Process: 5327 ExecStart=\/usr\/sbin\/named -u named -c ${NAMEDCONF} -t \/var\/named\/chroot $OPTIONS (code=exited, status=0\/SUCCESS)   Process: 5325 ExecStartPre=\/bin\/bash -c if [ ! \"$DISABLE_ZONE_CHECKING\" == \"yes\" ]; then \/usr\/sbin\/named-checkconf -t \/var\/named\/chroot -z \"$NAMEDCONF\"; else echo \"Checking of zone files is disabled\"; fi (code=exited, status=0\/SUCCESS)  Main PID: 5330 (named)    CGroup: \/system.slice\/named-chroot.service            \u2514\u25005330 \/usr\/sbin\/named -u named -c \/etc\/named.conf -t \/var\/named\/chroot  Feb 12 21:53:23 golinuxhub-client.example named[5330]: managed-keys-zone\/my_resolver: loaded serial 0 Feb 12 21:53:23 golinuxhub-client.example named[5330]: zone 0.in-addr.arpa\/IN\/my_resolver: loaded serial 0 Feb 12 21:53:23 golinuxhub-client.example named[5330]: zone 1.0.0.127.in-addr.arpa\/IN\/my_resolver: loaded serial 0 Feb 12 21:53:23 golinuxhub-client.example named[5330]: zone 1.168.192.in-addr.arpa\/IN\/my_resolver: loaded serial 1997022700 Feb 12 21:53:23 golinuxhub-client.example named[5330]: zone example\/IN\/my_resolver: loaded serial 1 Feb 12 21:53:23 golinuxhub-client.example named[5330]: zone localhost\/IN\/my_resolver: loaded serial 0 Feb 12 21:53:23 golinuxhub-client.example named[5330]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa\/IN\/my_resolver: loaded serial 0 Feb 12 21:53:23 golinuxhub-client.example named[5330]: zone localhost.localdomain\/IN\/my_resolver: loaded serial 0 Feb 12 21:53:23 golinuxhub-client.example named[5330]: all zones loaded Feb 12 21:53:23 golinuxhub-client.example named[5330]: running ```bash \u0423\u0431\u0435\u0434\u0438\u0442\u0435\u0441\u044c, \u0447\u0442\u043e resolv.conf \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u0442 \u0432\u0430\u0448 IP-\u0430\u0434\u0440\u0435\u0441, \u0447\u0442\u043e\u0431\u044b \u043e\u043d \u043c\u043e\u0433 \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430. ```bash # cat \/etc\/resolv.conf search example nameserver 192.168.1.7 ```bash \u0414\u0430\u0432\u0430\u0439\u0442\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u043c \u043d\u0430\u0448 DNS-\u0441\u0435\u0440\u0432\u0435\u0440 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0439 \u0437\u043e\u043d\u044b, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f dig. ```bash [root@golinuxhub-client named]# dig -x 192.168.1.5  ; &lt;&lt;&gt;&gt; DiG 9.9.4-RedHat-9.9.4-50.el7 &lt;&lt;&gt;&gt; -x 192.168.1.5 ;; global options: +cmd ;; Got answer: ;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 40331 ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 2  ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;5.1.168.192.in-addr.arpa.      IN      PTR  ;; ANSWER SECTION: 5.1.168.192.in-addr.arpa. 86400 IN      PTR     golinuxhub-server.example.  ;; AUTHORITY SECTION: 1.168.192.in-addr.arpa. 86400   IN      NS      example.  ;; ADDITIONAL SECTION: example.                86400   IN      A       192.168.1.7  ;; Query time: 1 msec ;; SERVER: 192.168.1.7#53(192.168.1.7) ;; WHEN: Mon Feb 12 22:13:17 IST 2018 ;; MSG SIZE  rcvd: 122<\/code><\/pre>\n<p>  <\/p>\n<p>\u041a\u0430\u043a \u0432\u044b \u0432\u0438\u0434\u0438\u0442\u0435, \u043c\u044b \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0438 \u043f\u043e\u043b\u043e\u0436\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0439 \u043e\u0442\u0432\u0435\u0442 (ANSWER) \u043d\u0430 \u043d\u0430\u0448 \u0437\u0430\u043f\u0440\u043e\u0441 (QUERY).<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client named]# dig -x 192.168.1.7  ; &lt;&lt;&gt;&gt; DiG 9.9.4-RedHat-9.9.4-50.el7 &lt;&lt;&gt;&gt; -x 192.168.1.7 ;; global options: +cmd ;; Got answer: ;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 55804 ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 2  ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;7.1.168.192.in-addr.arpa.      IN      PTR  ;; ANSWER SECTION: 7.1.168.192.in-addr.arpa. 86400 IN      PTR     golinuxhub-client.example.  ;; AUTHORITY SECTION: 1.168.192.in-addr.arpa. 86400   IN      NS      example.  ;; ADDITIONAL SECTION: example.                86400   IN      A       192.168.1.7  ;; Query time: 1 msec ;; SERVER: 192.168.1.7#53(192.168.1.7) ;; WHEN: Mon Feb 12 22:12:54 IST 2018 ;; MSG SIZE  rcvd: 122<\/code><\/pre>\n<p>  <\/p>\n<p>\u0422\u043e\u0447\u043d\u043e \u0442\u0430\u043a \u0436\u0435 \u043c\u044b \u043c\u043e\u0436\u0435\u043c \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c \u043f\u0440\u044f\u043c\u0443\u044e \u0437\u043e\u043d\u0443.<\/p>\n<p>  <\/p>\n<pre><code class=\"bash\">[root@golinuxhub-client named]# nslookup golinuxhub-client.example Server:         192.168.1.7 Address:        192.168.1.7#53  Name:   golinuxhub-client.example Address: 192.169.1.7  [root@golinuxhub-client named]# nslookup golinuxhub-server.example Server:         192.168.1.7 Address:        192.168.1.7#53  Name:   golinuxhub-server.example Address: 192.168.1.5<\/code><\/pre>\n<p>  <\/p>\n<p>\u042d\u0442\u0430 \u0441\u0442\u0430\u0442\u044c\u044f \u043d\u0435\u043c\u043d\u043e\u0433\u043e \u0443\u0441\u0442\u0430\u0440\u0435\u043b\u0430, \u0442\u0430\u043a \u043a\u0430\u043a \u0432 RHEL 7 \u0442\u0435\u043f\u0435\u0440\u044c \u043d\u0435 \u043d\u0443\u0436\u043d\u043e \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 bind \u0432 chroot. <a href=\"https:\/\/www.golinuxcloud.com\/configure-dns-server-bind-chroot-named-centos\/\">Step-by-Step Tutorial: Configure DNS Server using bind chroot (CentOS\/RHEL 7)<\/a>.<\/p>\n<\/div>\n<p>               <script class=\"js-mediator-script\">!function(e){function t(t,n){if(!(n in e)){for(var r,a=e.document,i=a.scripts,o=i.length;o--;)if(-1!==i[o].src.indexOf(t)){r=i[o];break}if(!r){r=a.createElement(\"script\"),r.type=\"text\/javascript\",r.async=!0,r.defer=!0,r.src=t,r.charset=\"UTF-8\";var d=function(){var e=a.getElementsByTagName(\"script\")[0];e.parentNode.insertBefore(r,e)};\"[object Opera]\"==e.opera?a.addEventListener?a.addEventListener(\"DOMContentLoaded\",d,!1):e.attachEvent(\"onload\",d):d()}}}t(\"\/\/mediator.mail.ru\/script\/2820404\/\",\"_mediator\")}(window);<\/script>     <br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/461281\/\"> https:\/\/habr.com\/ru\/company\/otus\/blog\/461281\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"\n<div class=\"post__text post__text-html js-mediator-article\">\n<p><em>\u041f\u0435\u0440\u0435\u0432\u043e\u0434 \u0441\u0442\u0430\u0442\u044c\u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d \u0434\u043b\u044f \u0441\u0442\u0443\u0434\u0435\u043d\u0442\u043e\u0432 \u043a\u0443\u0440\u0441\u0430 <a href=\"https:\/\/otus.pw\/U1cp\/\">\u00ab\u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c Linux\u00bb<\/a>. \u0418\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u043e \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u0434\u0430\u043d\u043d\u043e\u043c \u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0438? \u0421\u043c\u043e\u0442\u0440\u0438\u0442\u0435 \u0437\u0430\u043f\u0438\u0441\u044c \u0442\u0440\u0430\u043d\u0441\u043b\u044f\u0446\u0438\u0438 \u043c\u0430\u0441\u0442\u0435\u0440-\u043a\u043b\u0430\u0441\u0441\u0430 \u0418\u0432\u0430\u043d\u0430 \u041f\u0438\u0441\u043a\u0443\u043d\u043e\u0432\u0430 <a href=\"https:\/\/otus.pw\/6yM3\/\">\u00ab\u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c \u0432 Linux \u0432 \u0441\u0440\u0430\u0432\u043d\u0435\u043d\u0438\u0438 \u0441 Windows \u0438 MacOS\u00bb<\/a><\/em><\/p>\n<p>  <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/ej\/jd\/rm\/ejjdrmoz6mrcllqotaz_0ym9pao.png\"><\/p>\n<p>  <\/p>\n<p>\u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044f \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043e \u0448\u0430\u0433\u0430\u0445 \u043f\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043d\u0430 RHEL 7 \u0438\u043b\u0438 CentOS 7. \u0414\u043b\u044f \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b Red Hat Enterprise Linux 7.4. \u041d\u0430\u0448\u0430 \u0446\u0435\u043b\u044c \u2014 \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043e\u0434\u043d\u0443 A-\u0437\u0430\u043f\u0438\u0441\u044c \u0438 \u043e\u0434\u043d\u0443 PTR-\u0437\u0430\u043f\u0438\u0441\u044c \u0434\u043b\u044f \u0437\u043e\u043d\u044b \u043f\u0440\u044f\u043c\u043e\u0433\u043e \u0438 \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u043c\u043e\u0442\u0440\u0430 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-292585","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/292585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=292585"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/292585\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=292585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=292585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=292585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}