LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 05-10-2017, 01:34 AM   #1
pix9
Member
 
Registered: Jan 2010
Location: Mumbai, India
Distribution: ArchLinux, Fedora 24, Centos 7.0
Posts: 177

Rep: Reputation: 19
Question Better Approach for configuring DNS (bind9) master-slave?


Dear Friends,
I am having a bind9 server configured with multiple zones, This is a standalone box. Now I want to configure slave to this. To configure slave I will have to go and edit the zone config file and add allow-transfer for each zone. What I am trying to achieve is Instead of defining allow transfer for each zone block I would like to define allow zone transfer at single place in config file. Future constraints I am considering are.
If in future we change the slave ip or add another slave I would like to keep config editing requirement to minimal. Also dns is mostlikely going to be used over internal network only.

So question here is

* Is it possible to define allow zone transfer at single place or I will have to define allow-transfer every individual zone block?
* IS there better approach to this?
* what trade-off is advisable in terms of security to achive more simplicity in terms of config and managing internal dns service?

Other Detais:-
OS:- centos7
APP Version:- bind9
ENV :- (chroot)

Thank you.
 
Old 05-10-2017, 04:58 AM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,164
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Quote:
So question here is

* Is it possible to define allow zone transfer at single place or I will have to define allow-transfer every individual zone block?
* IS there better approach to this?
* what trade-off is advisable in terms of security to achive more simplicity in terms of config and managing internal dns service?
* Sure it's possible. You need to put the allow-transfer directive into the "Options" part of the main named.conf.

* None that I can think of

* Better read the full e-book from the link above.


Cheers
 
Old 05-11-2017, 02:06 AM   #3
pix9
Member
 
Registered: Jan 2010
Location: Mumbai, India
Distribution: ArchLinux, Fedora 24, Centos 7.0
Posts: 177

Original Poster
Rep: Reputation: 19
Solved

Thank For reply bathory

I've settled for global allow-transfer directive on master server and TSIG setup.

Regards
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
I find file zone in the slave zone to the do a transfer of zone from Windows Server 2012 as master dns and CentOS as slave DNS. To learn Linux - Newbie 1 09-02-2016 09:36 AM
Bind9 Master/Slave Install deibertine Linux - Server 6 08-20-2009 01:22 AM
BIND9 Master Slave Sync problem on Etch 4 servers dholgado Linux - Newbie 1 09-20-2008 09:12 PM
LXer: Installing A Bind9 Master/Slave DNS System LXer Syndicated Linux News 0 08-27-2006 01:33 PM
BIND9 slave DNS problem HELP!!! mlu Linux - Networking 2 05-05-2005 06:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 05:16 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration