Red Hat LINUX 7.2 - OFFICIAL LINUX CUSTOMIZATION GUIDE Guida di Installazione Pagina 236

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 282
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 235
236 Chapter 17. Berkeley Internet Name Domain (BIND)
17.4. BIND Advanced Features
Most BIND implementations only use named to provide name resolution services or to act as an au-
thority for a particular domain or sub-domain. However, BIND version 9 has a number of advanced
features that, when properly configured and utilized, allow for a more secure and efficient DNS ser-
vice.
Caution
Some of these advanced features, such as DNSSEC, TSIG, and IXFR, should only be used in net-
work environments with nameservers that support the features. If your network environment includes
non-BIND or older BIND nameservers, check to see if a particular advanced feature is available
before attempting to use it.
Do not assume another type of nameserver supports all of these features, as many do not.
All of the features discussed here are discussed in greater detail in the BIND 9 Administrator Reference
Manual. See Section 17.6 for places to find this manual.
17.4.1. DNS Protocol Enhancements
BIND supports Incremental Zone Transfers (IXFR), where slave nameserver will only download the
updated portions of a zone modified on a master nameserver. The standard transfer AXFR process
requires that the entire zone be transferred to each slave nameserver for even the smallest change.
For very popular domains with very lengthy zone files and many slave nameservers, IXFR makes the
notification and update process much less resource intensive.
Note that IXFR is only available if you are also using dynamic updating to make changes to master
zone records. If you are manually editing zone files to make changes, AXFR will be used. More
information on dynamic updating is available in the BIND 9 Administrator Reference Manual.
17.4.2. Multiple Views
Through the use of the view statement in /etc/named.conf, BIND allows you to configure a name-
server to answer queries for some clients in a different way than it answers them for others.
This is primarily used to deny particular types of DNS queries from clients outside of your network,
while allowing those same queries from clients on the local network.
The view statement uses the match-clients option to match IP addresses or entire networks and
give them special options and zone data.
17.4.3. Security
BIND supports a number of different methods to protect the updating and transfer of zones, on both
master and slave nameservers:
DNSSEC Short for DNS SECurity, this feature allows for zones to be cryptographically signed
with a zone key.
In this way, the information about a specific zone can be verified as coming from a nameserver that
has signed it with a particular private key, as long as the recipient has that nameserver’s public key.
BIND version 9 also supports the SIG(0) public/private key method of message authentication.
Vedere la pagina 235
1 2 ... 231 232 233 234 235 236 237 238 239 240 241 ... 281 282

Commenti su questo manuale

Nessun commento