diff --git a/sio1/02-dns/db.domaine.lan b/sio1/02-dns/db.domaine.lan new file mode 100644 index 0000000..dd3c58d --- /dev/null +++ b/sio1/02-dns/db.domaine.lan @@ -0,0 +1,21 @@ +; +; BIND data file for local loopback interface +; +$TTL 604800 +domaine.lan. IN SOA srv1.domaine.lan. root.srv1.domaine.lan. ( + 2 ; Serial + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL + +; + + NS srv1.domaine.lan. +srv1.domaine.lan. A 192.168.0.29 +srv2.domaine.lan. A 192.168.0.41 + +$ORIGIN domaine.lan. +poste1 A 192.168.0.22 +www CNAME poste1.domaine.lan. + diff --git a/sio1/02-dns/db.domaine.lan.rev b/sio1/02-dns/db.domaine.lan.rev new file mode 100644 index 0000000..4d5a101 --- /dev/null +++ b/sio1/02-dns/db.domaine.lan.rev @@ -0,0 +1,19 @@ +; +; BIND data file for local loopback interface +; +$TTL 604800 +@ IN SOA srv1.domaine.lan. root.domaine.lan. ( + 2021022600 ; Serial + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL +; + IN NS srv1.domaine.lan. +srv1.domaine.lan. A 192.168.0.29 +srv2.domaine.lan. A 192.168.0.41 + +29 IN PTR srv1.domaine.lan. +22 IN PTR poste1.domaine.lan. +41 IN PTR srv2.domaine.lan. + diff --git a/sio1/02-dns/named.conf.local b/sio1/02-dns/named.conf.local new file mode 100644 index 0000000..6ab2f31 --- /dev/null +++ b/sio1/02-dns/named.conf.local @@ -0,0 +1,17 @@ +// +// Do any local configuration here +// + +// Consider adding the 1918 zones here, if they are not used in your +// organization +//include "/etc/bind/zones.rfc1918"; +zone "domaine.lan" { + type master; + file "/etc/bind/db.domaine.lan"; +}; + +zone "0.168.192.in-addr.arpa" { + type master; + notify no; + file "/etc/bind/db.domaine.lan.rev"; +}; diff --git a/sio1/02-dns/named.conf.options b/sio1/02-dns/named.conf.options new file mode 100644 index 0000000..e562e68 --- /dev/null +++ b/sio1/02-dns/named.conf.options @@ -0,0 +1,24 @@ +options { + directory "/var/cache/bind"; + + // If there is a firewall between you and nameservers you want + // to talk to, you may need to fix the firewall to allow multiple + // ports to talk. See http://www.kb.cert.org/vuls/id/800113 + + // If your ISP provided one or more IP addresses for stable + // nameservers, you probably want to use them as forwarders. + // Uncomment the following block, and insert the addresses replacing + // the all-0's placeholder. + + forwarders { + 192.168.0.1; + }; + + //======================================================================== + // If BIND logs error messages about the root key being expired, + // you will need to update your keys. See https://www.isc.org/bind-keys + //======================================================================== + dnssec-validation no; + + listen-on-v6 { any; }; +};