Примечание
/etc/bind/options.conf:
options {
forwarders { 8.8.8.8; };
};
/etc/bind/options.conf:
zone "trust.dom" in {
type forward;
forwarders { 10.64.224.10; };
};
Таблица 33.1. Исходные данные
| |
Имя домена
|
Контроллер домена
|
IP-адрес
|
ОС контроллера домена
|
Версия Samba
|
|---|---|---|---|---|---|
|
Домен Linux
|
TEST.ALT
|
dc1.test.alt
|
192.168.0.132
|
ALT Server 10.2
|
4.19.9
|
|
Домен Linux
|
EXAMPLE.ALT
|
s1.example.alt
|
192.168.0.172
|
ALT Server 10.2
|
4.19.9
|
|
Выделенный DNS-сервер
|
|
|
192.168.0.150
|
ALT Server 10.2
|
|
/etc/bind/options.conf:
zone "example.alt" {
type forward;
forwarders { 192.168.0.172; };
};
zone "test.alt" {
type forward;
forwarders { 192.168.0.132; };
};
# systemctl restart bind.service
Примечание
/etc/bind/options.conf в секцию options добавить параметр:
dnssec-validation no;И перезапустить службу DNS:
# systemctl restart bind.service
/etc/samba/smb.conf (в параметре dns forwarder). Например:
dns forwarder = 192.168.0.150 8.8.8.8
# systemctl restart samba
/etc/bind/options.conf:
options добавить параметр:
dnssec-validation no;
/etc/bind/options.conf (или /etc/bind/ddns.conf) добавить информацию о зонах:
zone "example.alt" {
type forward;
forwarders { 192.168.0.172; };
};
zone "test.alt" {
type forward;
forwarders { 192.168.0.132; };
};
# systemctl restart bind.service
#host -t srv _kerberos._tcp.example.alt_kerberos._tcp.example.alt has SRV record 0 100 88 s1.example.alt. #host -t srv _kerberos._tcp.test.alt_kerberos._tcp.test.alt has SRV record 0 100 88 dc1.test.alt.
#host -t srv _kerberos._tcp.example.alt_kerberos._tcp.example.alt has SRV record 0 100 88 s1.example.alt. #host -t srv _kerberos._tcp.test.alt_kerberos._tcp.test.alt has SRV record 0 100 88 dc1.test.alt.
#kinit administrator@EXAMPLE.ALTPassword for administrator@EXAMPLE.ALT: #klistTicket cache: KEYRING:persistent:0:krb_ccache_eFyZ8Tr Default principal: administrator@EXAMPLE.ALT Valid starting Expires Service principal 27.03.2024 14:14:36 28.03.2024 00:14:36 krbtgt/TEST.ALT@TEST.ALT renew until 28.03.2024 14:14:32
#kinit administrator@TEST.ALTPassword for administrator@TEST.ALT: #klistTicket cache: FILE:/tmp/krb5cc_0 Default principal: administrator@TEST.ALT Valid starting Expires Service principal 27.03.2024 15:17:50 28.03.2024 01:17:50 krbtgt/TEST.ALT@TEST.ALT renew until 28.03.2024 15:17:46
Важно