Skip to content
mwildnrxPublic

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

Internal DNS Server Setup – BIND

Purpose: This document provides the configuration notes and exploration results for deploying an internal DNS server using BIND (named) on the 10.10.10.0/24 network.

The DNS server provides:

  • Forward DNS resolution
  • Reverse DNS resolution
  • Internal authoritative zone management
  • Recursive DNS resolution for trusted clients

1. Environment Overview

Component Value
DNS Server IP 10.10.10.109
Internal Network 10.10.10.0/24
Forward Zone test.co.id
Reverse Zone 10.10.10.in-addr.arpa
Name Server confluent.test.co.id
DNS Service BIND / named
DNS Port 53

Architecture

                    Internal DNS Clients
                            |
                            |
                            v
                  +-------------------+
                  |    BIND / named   |
                  |                   |
                  | 10.10.10.109:53   |
                  +---------+---------+
                            |
              +-------------+-------------+
              |                           |
              v                           v
    Internal Forward Zone         Reverse Lookup Zone
     test.co.id          10.10.10.in-addr.arpa
              |
              v
       Internal Resources

2. Install BIND

Install the BIND DNS server and DNS utilities.

sudo dnf install -y bind bind-utils

Enable the service:

sudo systemctl enable named

Check the installed version:

named -v

3. Configure named.conf

Edit the BIND main configuration file:

sudo vi /etc/named.conf

Use the following configuration:

//
// named.conf
//
// Internal BIND DNS Server Configuration
//

acl "trusted" {
    10.10.10.0/24;
};

options {
    listen-on port 53 {
        10.10.10.109;
        127.0.0.1;
    };

    listen-on-v6 port 53 {
        any;
    };

    directory "/var/named";

    dump-file "/var/named/data/cache_dump.db";
    statistics-file "/var/named/data/named_stats.txt";
    memstatistics-file "/var/named/data/named_mem_stats.txt";
    secroots-file "/var/named/data/named.secroots";
    recursing-file "/var/named/data/named.recursing";

    recursion yes;

    allow-query {
        localhost;
        trusted;
    };

    allow-recursion {
        localhost;
        trusted;
    };

    allow-transfer {
        none;
    };

    forwarders {
        8.8.8.8;
        8.8.4.4;
    };

    dnssec-validation yes;

    managed-keys-directory "/var/named/dynamic";
    geoip-directory "/usr/share/GeoIP";

    pid-file "/run/named/named.pid";
    session-keyfile "/run/named/session.key";

    include "/etc/crypto-policies/back-ends/bind.config";
};

logging {
    channel default_debug {
        file "data/named.run";
        severity dynamic;
    };
};

zone "." IN {
    type hint;
    file "named.ca";
};

include "/etc/named.rfc1912.zones";

//
// Internal DNS Zones
//

zone "test.co.id" IN {
    type master;
    file "internal-colocation.zone";
};

zone "10.10.10.in-addr.arpa" IN {
    type master;
    file "internal-colocation.rev";
};

4. Configure Forward Lookup Zone

Create the forward zone file:

sudo vi /var/named/internal-colocation.zone

internal-colocation.zone

$TTL 604800

@       IN      SOA     test.co.id. admin.test.co.id. (
                        2025052302 ; Serial
                        604800     ; Refresh
                        86400      ; Retry
                        2419200    ; Expire
                        604800 )   ; Negative Cache TTL

; Name Server
@       IN      NS      confluent.test.co.id.

; Root Domain
@       IN      A       10.10.10.109

; DNS Name Server
confluent.test.co.id.         IN  A   10.10.10.109

; Internal Infrastructure
data-warehouse.test.co.id.    IN  A   10.10.10.105
oracle.test.co.id.            IN  A   10.10.10.101
db2-primary.test.co.id.       IN  A   10.10.10.102
db2-standby.test.co.id.       IN  A   10.10.10.106
transform-engine.test.co.id.  IN  A   10.10.10.107

; Worker Nodes
worker1.test.co.id.           IN  A   10.10.10.71
worker2.test.co.id.           IN  A   10.10.10.72
worker3.test.co.id.           IN  A   10.10.10.73
worker4.test.co.id.           IN  A   10.10.10.74

5. Configure Reverse Lookup Zone

Create the reverse zone file:

sudo vi /var/named/internal-colocation.rev

internal-colocation.rev

$TTL 604800

@   IN  SOA test.co.id. admin.test.co.id. (
        2024052301 ; Serial
        604800     ; Refresh
        86400      ; Retry
        2419200    ; Expire
        604800 )   ; Negative Cache TTL

; Name Server
@   IN  NS  confluent.test.co.id.

; Reverse DNS Records
109 IN  PTR confluent.test.co.id.
101 IN  PTR oracle.test.co.id.
102 IN  PTR db2-primary.test.co.id.
105 IN  PTR data-warehouse.test.co.id.
106 IN  PTR db2-standby.test.co.id.
107 IN  PTR transform-engine.test.co.id.
71  IN  PTR worker1.test.co.id.
72  IN  PTR worker2.test.co.id.
73  IN  PTR worker3.test.co.id.
74  IN  PTR worker4.test.co.id.

6. DNS Record Mapping

Hostname IP Address
confluent.test.co.id 10.10.10.109
oracle.test.co.id 10.10.10.101
db2-primary.test.co.id 10.10.10.102
data-warehouse.test.co.id 10.10.10.105
db2-standby.test.co.id 10.10.10.106
transform-engine.test.co.id 10.10.10.107
worker1.test.co.id 10.10.10.71
worker2.test.co.id 10.10.10.72
worker3.test.co.id 10.10.10.73
worker4.test.co.id 10.10.10.74

7. Validate BIND Configuration

Before starting or reloading the DNS service, validate the main configuration:

sudo named-checkconf

If there is no output, the configuration syntax is valid.


Validate the Forward Zone

sudo named-checkzone \
test.co.id \
/var/named/internal-colocation.zone

Expected result:

zone test.co.id/IN: loaded serial 2025052302
OK

Validate the Reverse Zone

sudo named-checkzone \
10.10.10.in-addr.arpa \
/var/named/internal-colocation.rev

Expected result:

zone 10.10.10.in-addr.arpa/IN: loaded serial 2024052301
OK

8. Configure File Ownership and SELinux Context

Ensure the zone files have the correct ownership:

sudo chown root:named /var/named/internal-colocation.zone
sudo chown root:named /var/named/internal-colocation.rev

Set the appropriate permissions:

sudo chmod 640 /var/named/internal-colocation.zone
sudo chmod 640 /var/named/internal-colocation.rev

Restore the default SELinux context:

sudo restorecon -Rv /var/named

Verify the SELinux labels:

ls -lZ /var/named/internal-colocation.*

9. Start and Manage DNS Service

Start DNS Service

sudo systemctl start named

Check service status:

sudo systemctl status named

Stop DNS Service

sudo systemctl stop named

Restart DNS Service

sudo systemctl restart named

Reload BIND Configuration

Reload the complete DNS configuration:

sudo rndc reload

Reload only the forward zone:

sudo rndc reload test.co.id

Reload the reverse zone:

sudo rndc reload 10.10.10.in-addr.arpa

10. Verify DNS Server Listening Port

Verify that named is listening on port 53.

sudo ss -lntup | grep :53

Expected service:

10.10.10.109:53
127.0.0.1:53

11. Verify Forward DNS Resolution

Test the DNS server directly.

dig @10.10.10.109 confluent.test.co.id

Test another internal record:

dig @10.10.10.109 data-warehouse.test.co.id

Simple lookup:

nslookup db2-primary.test.co.id 10.10.10.109

Example:

Name:    db2-primary.test.co.id
Address: 10.10.10.102

12. Verify Reverse DNS Resolution

Test reverse DNS lookup:

dig -x 10.10.10.109 @10.10.10.109

Expected result:

109.10.10.10.in-addr.arpa. IN PTR confluent.test.co.id.

Test another server:

dig -x 10.10.10.105 @10.10.10.109

Expected result:

105.10.10.10.in-addr.arpa. IN PTR data-warehouse.test.co.id.

13. Configure Linux Server as DNS Client

Configure the NetworkManager connection to use the internal DNS server.

sudo nmcli con mod ens33 ipv4.dns "10.10.10.109"

sudo nmcli con mod ens33 ipv4.ignore-auto-dns yes

sudo nmcli con up ens33

Verify the DNS configuration:

nmcli dev show ens33 | grep DNS

Alternative verification:

cat /etc/resolv.conf

Expected DNS server:

nameserver 10.10.10.109

14. Verify DNS Resolution from Client

After configuring the DNS client, test the internal records:

getent hosts data-warehouse.test.co.id
getent hosts db2-primary.test.co.id
getent hosts worker1.test.co.id

Test reverse lookup:

getent hosts 10.10.10.105

15. Update DNS Zone Records

When adding, removing, or modifying a DNS record:

  1. Edit the appropriate zone file.
  2. Increase the zone serial number.
  3. Validate the zone syntax.
  4. Reload the updated zone.
  5. Verify the DNS record.

Example Serial Number Update

Previous serial:

2025052302

New serial:

2025052303

Example:

@       IN      SOA     test.co.id. admin.test.co.id. (
                        2025052303 ; Serial
                        604800     ; Refresh
                        86400      ; Retry
                        2419200    ; Expire
                        604800 )   ; Negative Cache TTL

Important: Every modification to a zone file should be followed by a serial number increment.


16. Example DNS Change Procedure

Step 1 – Update the Zone File

sudo vi /var/named/internal-colocation.zone

Step 2 – Increase the Serial Number

Example:

2025052302

Change to:

2025052303

Step 3 – Validate the Zone

sudo named-checkzone \
test.co.id \
/var/named/internal-colocation.zone

Step 4 – Reload the Zone

sudo rndc reload test.co.id

Step 5 – Verify the New Record

dig @10.10.10.109 <hostname>.test.co.id

17. Troubleshooting Commands

Check Service Status

sudo systemctl status named

Check BIND Logs

sudo journalctl -u named -f

Validate Main Configuration

sudo named-checkconf

Validate Forward Zone

sudo named-checkzone \
test.co.id \
/var/named/internal-colocation.zone

Validate Reverse Zone

sudo named-checkzone \
10.10.10.in-addr.arpa \
/var/named/internal-colocation.rev

Check DNS Port

sudo ss -lntup | grep :53

Test Forward Lookup

dig @10.10.10.109 test.co.id

Test Reverse Lookup

dig -x 10.10.10.109 @10.10.10.109

18. Deployment Checklist

  • BIND and BIND utilities are installed.
  • The named service is enabled.
  • The trusted network ACL is configured.
  • DNS is listening on 10.10.10.109.
  • The forward zone is configured.
  • The reverse zone is configured.
  • The zone serial number is valid.
  • The forward zone passes named-checkzone.
  • The reverse zone passes named-checkzone.
  • The main configuration passes named-checkconf.
  • Zone file ownership is configured correctly.
  • SELinux context is configured correctly.
  • The named service is running.
  • Forward DNS resolution is successful.
  • Reverse DNS resolution is successful.
  • Client DNS configuration points to 10.10.10.109.
  • Internal hosts can resolve all required records.

19. Important Notes

Serial Number Management

Always increase the SOA serial number whenever the zone file is modified.

DNS Reload

Use rndc reload <zone> when only one zone has been modified. This is preferable to restarting the entire DNS service.

Production Consideration

For a production environment, consider using:

  • Multiple DNS servers
  • Secondary/slave DNS zones
  • Restricted recursion
  • Internal upstream DNS forwarders
  • Firewall rules for TCP and UDP port 53
  • Automated configuration backup

Security

The configuration should allow DNS queries only from trusted networks and localhost unless external DNS access is explicitly required.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors