{"id":61737,"date":"2025-04-29T08:17:53","date_gmt":"2025-04-29T00:17:53","guid":{"rendered":"https:\/\/fwq.ai\/blog\/61737\/"},"modified":"2025-04-29T08:17:53","modified_gmt":"2025-04-29T00:17:53","slug":"%e5%a6%82%e4%bd%95%e5%9c%a8linux%e4%b8%8a%e9%85%8d%e7%bd%ae%e9%ab%98%e5%8f%af%e7%94%a8%e7%9a%84dns%e9%9b%86%e7%be%a4-2","status":"publish","type":"post","link":"https:\/\/fwq.ai\/blog\/61737\/","title":{"rendered":"\u5982\u4f55\u5728Linux\u4e0a\u914d\u7f6e\u9ad8\u53ef\u7528\u7684DNS\u96c6\u7fa4"},"content":{"rendered":"<p>\u5982\u4f55\u5728linux\u4e0a\u914d\u7f6e\u9ad8\u53ef\u7528\u7684dns\u96c6\u7fa4<\/p>\n<p>\u5f15\u8a00\uff1a<br \/>\u968f\u7740\u4e92\u8054\u7f51\u7684\u8fc5\u731b\u53d1\u5c55\uff0cDNS (Domain Name System) \u4f5c\u4e3a\u91cd\u8981\u7684\u7f51\u7edc\u57fa\u7840\u8bbe\u65bd\u4e4b\u4e00\uff0c\u626e\u6f14\u7740\u5c06\u57df\u540d\u8f6c\u6362\u4e3a IP \u5730\u5740\u7684\u5173\u952e\u89d2\u8272\u3002\u5728\u5927\u6d41\u91cf\u7684\u7f51\u7edc\u73af\u5883\u4e2d\uff0cDNS \u670d\u52a1\u5668\u7684\u9ad8\u53ef\u7528\u6027\u5c31\u53d8\u5f97\u81f3\u5173\u91cd\u8981\u3002\u672c\u6587\u5c06\u4ecb\u7ecd\u5982\u4f55\u5728 Linux \u7cfb\u7edf\u4e0a\u914d\u7f6e\u9ad8\u53ef\u7528\u7684 DNS \u96c6\u7fa4\uff0c\u5e76\u63d0\u4f9b\u4e00\u4e9b\u4ee3\u7801\u793a\u4f8b\u3002<\/p>\n<ol>\n<li>\u5b89\u88c5 DNS \u670d\u52a1\u5668\uff1a<br \/>\u9996\u5148\uff0c\u6211\u4eec\u9700\u8981\u5728 Linux \u7cfb\u7edf\u4e0a\u5b89\u88c5 DNS \u670d\u52a1\u5668\u3002\u672c\u6587\u4ee5\u5e38\u7528\u7684 BIND\uff08Berkeley Internet Name Domain\uff09\u670d\u52a1\u5668\u4e3a\u4f8b\uff0c\u8fdb\u884c\u914d\u7f6e\u3002\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u6765\u5b89\u88c5 BIND\uff1a<\/li>\n<\/ol>\n<pre>sudo apt-get update\nsudo apt-get install bind9<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<ol>\n<li>\u914d\u7f6e\u4e3b DNS \u670d\u52a1\u5668\uff1a<br \/>\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u9700\u8981\u5728\u4e3b DNS \u670d\u52a1\u5668\u4e0a\u8fdb\u884c\u914d\u7f6e\u3002\u6253\u5f00 BIND \u7684\u4e3b\u914d\u7f6e\u6587\u4ef6 \/etc\/bind\/named.conf.local\uff0c\u5e76\u6dfb\u52a0\u4ee5\u4e0b\u5185\u5bb9\uff1a<\/li>\n<\/ol>\n<pre>zone \"example.com\" {\n    type master;\n    file \"\/etc\/bind\/db.example.com\";\n    allow-transfer { IP_ADDRESS_OF_SECONDARY_DNS_SERVER; };\n};<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u6ce8\u610f\u5c06 example.com \u66ff\u6362\u4e3a\u4f60\u81ea\u5df1\u7684\u57df\u540d\uff0c\u5e76\u5c06 IP_ADDRESS_OF_SECONDARY_DNS_SERVER \u66ff\u6362\u4e3a\u8f85\u52a9 DNS \u670d\u52a1\u5668\u7684 IP \u5730\u5740\u3002<\/p>\n<p>\u7136\u540e\uff0c\u521b\u5efa\u57df\u540d\u89e3\u6790\u6587\u4ef6 \/etc\/bind\/db.example.com\uff0c\u5e76\u6dfb\u52a0\u4ee5\u4e0b\u5185\u5bb9\uff1a<\/p>\n<pre>;\n; BIND data file for example.com\n;\n$TTL    604800\n@       IN      SOA     ns1.example.com. admin.example.com. (\n                  3        ; Serial\n             604800         ; Refresh\n              86400         ; Retry\n            2419200         ; Expire\n             604800 )       ; Negative Cache TTL\n;\n@       IN      NS      ns1.example.com.\n@       IN      A       IP_ADDRESS_OF_PRIMARY_DNS_SERVER\nns1     IN      A       IP_ADDRESS_OF_PRIMARY_DNS_SERVER\nwww     IN      CNAME   example.com.<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u786e\u4fdd\u5c06 example.com \u66ff\u6362\u4e3a\u4f60\u81ea\u5df1\u7684\u57df\u540d\uff0c\u5e76\u5c06 IP_ADDRESS_OF_PRIMARY_DNS_SERVER \u66ff\u6362\u4e3a\u4e3b DNS \u670d\u52a1\u5668\u7684 IP \u5730\u5740\u3002<\/p>\n<ol>\n<li>\u914d\u7f6e\u8f85\u52a9 DNS \u670d\u52a1\u5668\uff1a<br \/>\u63a5\u7740\uff0c\u6211\u4eec\u9700\u8981\u5728\u8f85\u52a9 DNS \u670d\u52a1\u5668\u4e0a\u8fdb\u884c\u914d\u7f6e\u3002\u6253\u5f00 BIND \u7684\u4e3b\u914d\u7f6e\u6587\u4ef6 \/etc\/bind\/named.conf.local\uff0c\u5e76\u6dfb\u52a0\u4ee5\u4e0b\u5185\u5bb9\uff1a<\/li>\n<\/ol>\n<pre>zone \"example.com\" {\n    type slave;\n    file \"\/etc\/bind\/db.example.com\";\n    masters { IP_ADDRESS_OF_PRIMARY_DNS_SERVER; };\n};<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u540c\u6837\u5730\uff0c\u5c06 example.com \u66ff\u6362\u4e3a\u4f60\u81ea\u5df1\u7684\u57df\u540d\uff0c\u5e76\u5c06 IP_ADDRESS_OF_PRIMARY_DNS_SERVER \u66ff\u6362\u4e3a\u4e3b DNS \u670d\u52a1\u5668\u7684 IP \u5730\u5740\u3002<\/p>\n<ol>\n<li>\u542f\u52a8 DNS \u670d\u52a1\u5668\uff1a<br \/>\u5b8c\u6210\u914d\u7f6e\u540e\uff0c\u6211\u4eec\u9700\u8981\u542f\u52a8 DNS \u670d\u52a1\u5668\uff0c\u5e76\u4f7f\u5176\u5728\u7cfb\u7edf\u542f\u52a8\u65f6\u81ea\u52a8\u542f\u52a8\u3002\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u5206\u522b\u542f\u52a8\u4e3b DNS \u548c\u8f85\u52a9 DNS\uff1a<\/li>\n<\/ol>\n<pre>sudo systemctl start bind9\nsudo systemctl enable bind9<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<ol>\n<li>\u914d\u7f6e\u9ad8\u53ef\u7528\u6027\uff1a<br \/>\u4e3a\u4e86\u5b9e\u73b0\u9ad8\u53ef\u7528\u7684 DNS \u670d\u52a1\uff0c\u6211\u4eec\u53ef\u4ee5\u4f7f\u7528\u8d1f\u8f7d\u5747\u8861\u548c\u6545\u969c\u8f6c\u79fb\u6280\u672f\u3002\u8fd9\u91cc\u6211\u4eec\u4f7f\u7528 Keepalived \u548c HAProxy \u5b9e\u73b0\u8d1f\u8f7d\u5747\u8861\u548c\u6545\u969c\u8f6c\u79fb\u3002<\/li>\n<\/ol>\n<p>\u9996\u5148\uff0c\u5b89\u88c5 Keepalived \u548c HAProxy\uff1a<\/p>\n<pre>sudo apt-get install keepalived\nsudo apt-get install haproxy<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u7136\u540e\uff0c\u5206\u522b\u5728\u4e3b DNS \u670d\u52a1\u5668\u548c\u8f85\u52a9 DNS \u670d\u52a1\u5668\u4e0a\u8fdb\u884c\u914d\u7f6e\u3002<\/p>\n<p>\u5728\u4e3b DNS \u670d\u52a1\u5668\u4e0a\uff0c\u7f16\u8f91 Keepalived \u7684\u914d\u7f6e\u6587\u4ef6 \/etc\/keepalived\/keepalived.conf\uff0c\u6dfb\u52a0\u4ee5\u4e0b\u5185\u5bb9\uff1a<\/p>\n<pre>global_defs {\n    router_id LVS_DEVEL\n}\n\nvrrp_instance VI_1 {\n    state MASTER\n    interface eth0\n    virtual_router_id 51\n    priority 100\n\n    virtual_ipaddress {\n        IP_ADDRESS_OF_DNS_CLUSTER\n    }\n}<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u5c06 IP_ADDRESS_OF_DNS_CLUSTER \u66ff\u6362\u4e3a\u7528\u4e8e\u8d1f\u8f7d\u5747\u8861\u7684\u865a\u62df IP \u5730\u5740\u3002<\/p>\n<p>\u5728\u8f85\u52a9 DNS \u670d\u52a1\u5668\u4e0a\uff0c\u7f16\u8f91 Keepalived \u7684\u914d\u7f6e\u6587\u4ef6 \/etc\/keepalived\/keepalived.conf\uff0c\u6dfb\u52a0\u4ee5\u4e0b\u5185\u5bb9\uff1a<\/p>\n<pre>global_defs {\n    router_id LVS_DEVEL\n}\n\nvrrp_instance VI_1 {\n    state BACKUP\n    interface eth0\n    virtual_router_id 51\n    priority 99\n\n    virtual_ipaddress {\n        IP_ADDRESS_OF_DNS_CLUSTER\n    }\n}<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u540c\u6837\u5730\uff0c\u5c06 IP_ADDRESS_OF_DNS_CLUSTER \u66ff\u6362\u4e3a\u7528\u4e8e\u8d1f\u8f7d\u5747\u8861\u7684\u865a\u62df IP \u5730\u5740\u3002<\/p>\n<p>\u6700\u540e\uff0c\u5728\u4e3b DNS \u670d\u52a1\u5668\u548c\u8f85\u52a9 DNS \u670d\u52a1\u5668\u4e0a\u5206\u522b\u7f16\u8f91 HAProxy \u7684\u914d\u7f6e\u6587\u4ef6 \/etc\/haproxy\/haproxy.cfg\uff0c\u53c2\u8003\u4ee5\u4e0b\u793a\u4f8b\uff1a<\/p>\n<pre>frontend dns_cluster\n    bind IP_ADDRESS_OF_DNS_CLUSTER:53\n    mode tcp\n    default_backend dns_servers\n\nbackend dns_servers\n    mode tcp\n    balance roundrobin\n    server primary_dns IP_ADDRESS_OF_PRIMARY_DNS_SERVER:53 check\n    server secondary_dns IP_ADDRESS_OF_SECONDARY_DNS_SERVER:53 check<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u786e\u4fdd\u5c06 IP_ADDRESS_OF_DNS_CLUSTER \u66ff\u6362\u4e3a\u7528\u4e8e\u8d1f\u8f7d\u5747\u8861\u7684\u865a\u62df IP \u5730\u5740\uff0c\u5e76\u5c06 IP_ADDRESS_OF_PRIMARY_DNS_SERVER \u548c IP_ADDRESS_OF_SECONDARY_DNS_SERVER \u66ff\u6362\u4e3a\u4e3b DNS \u670d\u52a1\u5668\u548c\u8f85\u52a9 DNS \u670d\u52a1\u5668\u7684 IP \u5730\u5740\u3002<\/p>\n<ol>\n<li>\u542f\u52a8\u548c\u6d4b\u8bd5\uff1a<br \/>\u5b8c\u6210\u914d\u7f6e\u540e\uff0c\u6211\u4eec\u542f\u52a8 Keepalived \u548c HAProxy \u670d\u52a1\uff0c\u5e76\u68c0\u67e5 DNS \u670d\u52a1\u7684\u53ef\u7528\u6027\u3002\u5728\u4e3b DNS \u670d\u52a1\u5668\u548c\u8f85\u52a9 DNS \u670d\u52a1\u5668\u4e0a\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u6765\u542f\u52a8\u670d\u52a1\uff1a<\/li>\n<\/ol>\n<pre>sudo systemctl start keepalived\nsudo systemctl start haproxy<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u7136\u540e\uff0c\u901a\u8fc7\u57df\u540d\u89e3\u6790\u5de5\u5177\uff08\u5982 dig\uff09\u6765\u6d4b\u8bd5 DNS \u670d\u52a1\u662f\u5426\u6b63\u5e38\u5de5\u4f5c\u3002\u4f8b\u5982\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\uff1a<\/p>\n<pre>dig example.com @IP_ADDRESS_OF_DNS_CLUSTER<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u786e\u4fdd\u5c06 IP_ADDRESS_OF_DNS_CLUSTER \u66ff\u6362\u4e3a\u7528\u4e8e\u8d1f\u8f7d\u5747\u8861\u7684\u865a\u62df IP \u5730\u5740\u3002<\/p>\n<p>\u7ed3\u8bba\uff1a<br \/>\u901a\u8fc7\u672c\u6587\u7684\u4ecb\u7ecd\u548c\u4ee3\u7801\u793a\u4f8b\uff0c\u4f60\u5df2\u7ecf\u5b66\u4f1a\u5982\u4f55\u5728 Linux \u7cfb\u7edf\u4e0a\u914d\u7f6e\u9ad8\u53ef\u7528\u7684 DNS \u96c6\u7fa4\u3002\u901a\u8fc7\u8d1f\u8f7d\u5747\u8861\u548c\u6545\u969c\u8f6c\u79fb\u6280\u672f\uff0c\u4f60\u53ef\u4ee5\u63d0\u9ad8 DNS \u670d\u52a1\u5668\u7684\u53ef\u7528\u6027\u548c\u6027\u80fd\uff0c\u786e\u4fdd\u7f51\u7edc\u670d\u52a1\u7684\u7a33\u5b9a\u6027\u3002\u795d\u4f60\u5728\u914d\u7f6e\u9ad8\u53ef\u7528\u7684 DNS \u96c6\u7fa4\u65f6\u53d6\u5f97\u6210\u529f\uff01<\/p>\n<p>\u4ee5\u4e0a\u5c31\u662f\u5982\u4f55\u5728Linux\u4e0a\u914d\u7f6e\u9ad8\u53ef\u7528\u7684DNS\u96c6\u7fa4\u7684\u8be6\u7ec6\u5185\u5bb9\uff0c\u66f4\u591a\u8bf7\u5173\u6ce8FDCServers\u5176\u5b83\u76f8\u5173\u6587\u7ae0\uff01<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5982\u4f55\u5728linux\u4e0a\u914d\u7f6e\u9ad8\u53ef\u7528\u7684dns\u96c6\u7fa4 \u5f15\u8a00\uff1a\u968f\u7740\u4e92\u8054\u7f51\u7684\u8fc5\u731b\u53d1\u5c55\uff0cDNS (Domain Name System) \u4f5c\u4e3a\u91cd\u8981\u7684\u7f51\u7edc\u57fa\u7840\u8bbe\u65bd\u4e4b\u4e00\uff0c\u626e\u6f14\u7740\u5c06\u57df\u540d\u8f6c\u6362\u4e3a IP \u5730\u5740\u7684\u5173\u952e\u89d2\u8272\u3002\u5728\u5927\u6d41\u91cf\u7684\u7f51\u7edc\u73af\u5883\u4e2d\uff0cDNS \u670d\u52a1\u5668\u7684\u9ad8\u53ef\u7528\u6027\u5c31\u53d8\u5f97\u81f3\u5173\u91cd\u8981\u3002\u672c\u6587\u5c06\u4ecb\u7ecd\u5982\u4f55\u5728 Linux \u7cfb\u7edf\u4e0a\u914d\u7f6e\u9ad8\u53ef\u7528\u7684 DNS \u96c6\u7fa4\uff0c\u5e76\u63d0\u4f9b\u4e00\u4e9b\u4ee3\u7801\u793a\u4f8b\u3002 \u5b89\u88c5 DNS \u670d\u52a1\u5668\uff1a\u9996\u5148\uff0c\u6211\u4eec\u9700\u8981\u5728 Linux \u7cfb\u7edf\u4e0a\u5b89\u88c5 DNS \u670d\u52a1\u5668\u3002\u672c\u6587\u4ee5\u5e38\u7528\u7684 BIND\uff08Berkeley Internet Name Domain\uff09\u670d\u52a1\u5668\u4e3a\u4f8b\uff0c\u8fdb\u884c\u914d\u7f6e\u3002\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u6765\u5b89\u88c5 BIND\uff1a sudo apt-get update sudo apt-get install bind9 \u767b\u5f55\u540e\u590d\u5236 \u914d\u7f6e\u4e3b DNS \u670d\u52a1\u5668\uff1a\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u9700\u8981\u5728\u4e3b DNS \u670d\u52a1\u5668\u4e0a\u8fdb\u884c\u914d\u7f6e\u3002\u6253\u5f00 BIND \u7684\u4e3b\u914d\u7f6e\u6587\u4ef6 \/etc\/bind\/named.conf.local\uff0c\u5e76\u6dfb\u52a0\u4ee5\u4e0b\u5185\u5bb9\uff1a zone &#8220;example.com&#8221; { type master; file &#8220;\/etc\/bind\/db.example.com&#8221;; allow-transfer { IP_ADDRESS_OF_SECONDARY_DNS_SERVER; }; }; \u767b\u5f55\u540e\u590d\u5236 \u6ce8\u610f\u5c06 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-61737","post","type-post","status-publish","format-standard","hentry","category-os"],"_links":{"self":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts\/61737","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/comments?post=61737"}],"version-history":[{"count":0,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts\/61737\/revisions"}],"wp:attachment":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/media?parent=61737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/categories?post=61737"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/tags?post=61737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}