diff --git a/sisr1/tp03-reseaux-prive/srv-service/db.monlabo.lan.rev b/sisr1/tp03-reseaux-prive/srv-service/db.monlabo.lan.rev new file mode 100644 index 0000000..353bba7 --- /dev/null +++ b/sisr1/tp03-reseaux-prive/srv-service/db.monlabo.lan.rev @@ -0,0 +1,19 @@ +; +; BIND data file for local loopback interface +; +$TTL 604800 +@ IN SOA srv-service.monlabo.lan. root.srv-service.monlabo.lan. ( + 2 ; Serial + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL; + NS srv-service.monlabo.lan. + +srv-service IN A 172.16.0.1 + +1 PTR srv-service.monlabo.lan. +254 PTR srv-admin-ca.monlabo.lan. + + + diff --git a/sisr1/tp03-reseaux-prive/srv-service/named.conf.local b/sisr1/tp03-reseaux-prive/srv-service/named.conf.local new file mode 100644 index 0000000..d01b042 --- /dev/null +++ b/sisr1/tp03-reseaux-prive/srv-service/named.conf.local @@ -0,0 +1,18 @@ +// +// Do any local configuration here +// zone directe + zone "monlabo.lan" { + type master; + file "/etc/bind/db.monlabo.lan"; + }; + +// zone inverse + zone "0.16.172.in-addr.arpa" { + type master; + notify no; + file "/etc/bind/db.monlabo.lan.rev"; + }; +// Consider adding the 1918 zones here, if they are not used in your +// organization +//include "/etc/bind/zones.rfc1918"; + diff --git a/sisr1/tp03-reseaux-prive/srv-service/named.conf.options b/sisr1/tp03-reseaux-prive/srv-service/named.conf.options new file mode 100644 index 0000000..6076f39 --- /dev/null +++ b/sisr1/tp03-reseaux-prive/srv-service/named.conf.options @@ -0,0 +1,24 @@ +options { + directory "/var/cache/bind"; + + // If there is a firewall between you and nameservers you want + // to talk to, you may need to fix the firewall to allow multiple + // ports to talk. See http://www.kb.cert.org/vuls/id/800113 + + // If your ISP provided one or more IP addresses for stable + // nameservers, you probably want to use them as forwarders. + // Uncomment the following block, and insert the addresses replacing + // the all-0's placeholder. + + forwarders { + 10.121.38.7; + }; + + //======================================================================== + // If BIND logs error messages about the root key being expired, + // you will need to update your keys. See https://www.isc.org/bind-keys + //======================================================================== + dnssec-validation auto; + + listen-on-v6 { any; }; +};