Linux/보안장비 운용

DNS 서버 설정

GGkeeper 2022. 3. 2. 15:49

실습> DNS 서버 설정


1. DNS 서버 등록
DNS서버의 허용할 네트워크나 호스트를 추가한다.

[Network Services] > [DNS] > [Global]

Allowed Networks
- Internal (Network)
- WEB#1


내부망의 호스트와 DMZ의 WEB#1의 DNS서버를 아래처럼 변경한다.
Win7 or WinXP: 192.168.102.254 
WEB#1: 192.168.101.254 


2. 도메인 등록
도메인을 아래처럼 등록한다.
도메인 등록 : server1.kr, www.server1.kr server2.kr, www.server2.kr, server3.kr, www.server3.kr 

[Network Services] > [DNS] > [Static Entries] > [Static Entries] 버튼을 클릭하면

[Definitions & Users] > [Network Definitions] 메뉴로 이동한다.

[+ New Network Definition...] 클릭해서 등록한다.
Edit Network Definition
Name: WEB#1
Type: Host
IPv4 address: 192.168.101.101
DHCP Settings: x
DNS Settings:
    - Hostname: server1.kr
    - Reverse DNS: 체크 안함
    - Additional Hostnames:
      - www.server1.kr 
      - server2.kr 
      - www.server2.kr 
      - server3.kr 
      - www.server3.kr 

Comment: 내부망 WEB#1 서버
Advanced: 체크 안함

Save 버튼을 클릭해서 설정한 내용을 저장한다.

3. 도메인 확인
Win7, WinXP, WEB#1에서 도메인을 확인한다.

C:\Users\victim>nslookup
기본 서버:  UnKnown
Address:  192.168.102.254

> server1.kr
서버:    UnKnown
Address:  192.168.102.254

이름:    server1.kr
Address:  192.168.101.101

www.server1.kr
서버:    UnKnown
Address:  192.168.102.254

이름:    www.server1.kr
Address:  192.168.101.101

> server2.kr
서버:    UnKnown
Address:  192.168.102.254

이름:    server2.kr
Address:  192.168.101.101

www.server2.kr
서버:    UnKnown
Address:  192.168.102.254

이름:    www.server2.kr
Address:  192.168.101.101

> server3.kr
서버:    UnKnown
Address:  192.168.102.254

이름:    server3.kr
Address:  192.168.101.101

www.server3.kr
서버:    UnKnown
Address:  192.168.102.254

이름:    www.server3.kr
Address:  192.168.101.101

> server4.kr
서버:    UnKnown
Address:  192.168.102.254

*** UnKnown이(가) server4.kr을(를) 찾을 수 없습니다. Non-existent domain
>


[root@web1 ~]# nslookup
> server1.kr
Server: 192.168.101.254
Address: 192.168.101.254#53

Name: server1.kr
Address: 192.168.101.101
> server2.kr
Server: 192.168.101.254
Address: 192.168.101.254#53

Name: server2.kr
Address: 192.168.101.101
> server3.kr
Server: 192.168.101.254
Address: 192.168.101.254#53

Name: server3.kr
Address: 192.168.101.101
www.server1.kr
Server: 192.168.101.254
Address: 192.168.101.254#53

Name: www.server1.kr
Address: 192.168.101.101
www.server2.kr
Server: 192.168.101.254
Address: 192.168.101.254#53

Name: www.server2.kr
Address: 192.168.101.101
www.server3.kr
Server: 192.168.101.254
Address: 192.168.101.254#53

Name: www.server3.kr
Address: 192.168.101.101
> server4.kr
Server: 192.168.101.254
Address: 192.168.101.254#53

** server can't find server4.kr: NXDOMAIN


server4.kr, www.server4.kr 이 없으므로 Win7, WEB#1에서는 nslookup으로 찾을 수 없다.
그래서 server4.kr, www.server4.kr을 등록하고 Win7, WEB#1에서 다시 확인하면 192.168.101.101이 잘 
나오는 것을 확인할 수 있다.

Win7에서 확인한 모습
> server4.kr
서버:    UnKnown
Address:  192.168.102.254

이름:    server4.kr
Address:  192.168.101.101

www.server4.kr
서버:    UnKnown
Address:  192.168.102.254

이름:    www.server4.kr
Address:  192.168.101.101


WEB#1에서 확인한 모습
Name: server4.kr
Address: 192.168.101.101
www.server4.kr
Server: 192.168.101.254
Address: 192.168.101.254#53

Name: www.server4.kr
Address: 192.168.101.101


dig을 이용해서 도메인을 한번에 확인한다.
[root@web1 ~]# dig +short \
server1.kr www.server1.kr \
server2.kr www.server2.kr \
server3.kr www.server3.kr \
server4.kr www.server4.kr 
192.168.101.101
192.168.101.101
192.168.101.101
192.168.101.101
192.168.101.101
192.168.101.101
192.168.101.101
192.168.101.101

'Linux > 보안장비 운용' 카테고리의 다른 글

IPS 설정  (0) 2022.03.02
DMZ WEB#1 서버의 가상 호스트 설정  (0) 2022.03.02
Masquerading 설정  (0) 2022.03.02
DHCP 서버 설정  (0) 2022.03.02
WEB#1 서버 설정  (0) 2022.03.02