Purpose: This document provides the configuration notes and exploration results for deploying an internal DNS server using BIND (
named) on the10.10.10.0/24network.The DNS server provides:
- Forward DNS resolution
- Reverse DNS resolution
- Internal authoritative zone management
- Recursive DNS resolution for trusted clients
| Component | Value |
|---|---|
| DNS Server IP | 10.10.10.109 |
| Internal Network | 10.10.10.0/24 |
| Forward Zone | test.co.id |
| Reverse Zone | 10.10.10.in-addr.arpa |
| Name Server | confluent.test.co.id |
| DNS Service | BIND / named |
| DNS Port | 53 |
Internal DNS Clients
|
|
v
+-------------------+
| BIND / named |
| |
| 10.10.10.109:53 |
+---------+---------+
|
+-------------+-------------+
| |
v v
Internal Forward Zone Reverse Lookup Zone
test.co.id 10.10.10.in-addr.arpa
|
v
Internal Resources
Install the BIND DNS server and DNS utilities.
sudo dnf install -y bind bind-utilsEnable the service:
sudo systemctl enable namedCheck the installed version:
named -vEdit the BIND main configuration file:
sudo vi /etc/named.confUse the following configuration:
//
// named.conf
//
// Internal BIND DNS Server Configuration
//
acl "trusted" {
10.10.10.0/24;
};
options {
listen-on port 53 {
10.10.10.109;
127.0.0.1;
};
listen-on-v6 port 53 {
any;
};
directory "/var/named";
dump-file "/var/named/data/cache_dump.db";
statistics-file "/var/named/data/named_stats.txt";
memstatistics-file "/var/named/data/named_mem_stats.txt";
secroots-file "/var/named/data/named.secroots";
recursing-file "/var/named/data/named.recursing";
recursion yes;
allow-query {
localhost;
trusted;
};
allow-recursion {
localhost;
trusted;
};
allow-transfer {
none;
};
forwarders {
8.8.8.8;
8.8.4.4;
};
dnssec-validation yes;
managed-keys-directory "/var/named/dynamic";
geoip-directory "/usr/share/GeoIP";
pid-file "/run/named/named.pid";
session-keyfile "/run/named/session.key";
include "/etc/crypto-policies/back-ends/bind.config";
};
logging {
channel default_debug {
file "data/named.run";
severity dynamic;
};
};
zone "." IN {
type hint;
file "named.ca";
};
include "/etc/named.rfc1912.zones";
//
// Internal DNS Zones
//
zone "test.co.id" IN {
type master;
file "internal-colocation.zone";
};
zone "10.10.10.in-addr.arpa" IN {
type master;
file "internal-colocation.rev";
};Create the forward zone file:
sudo vi /var/named/internal-colocation.zone$TTL 604800
@ IN SOA test.co.id. admin.test.co.id. (
2025052302 ; Serial
604800 ; Refresh
86400 ; Retry
2419200 ; Expire
604800 ) ; Negative Cache TTL
; Name Server
@ IN NS confluent.test.co.id.
; Root Domain
@ IN A 10.10.10.109
; DNS Name Server
confluent.test.co.id. IN A 10.10.10.109
; Internal Infrastructure
data-warehouse.test.co.id. IN A 10.10.10.105
oracle.test.co.id. IN A 10.10.10.101
db2-primary.test.co.id. IN A 10.10.10.102
db2-standby.test.co.id. IN A 10.10.10.106
transform-engine.test.co.id. IN A 10.10.10.107
; Worker Nodes
worker1.test.co.id. IN A 10.10.10.71
worker2.test.co.id. IN A 10.10.10.72
worker3.test.co.id. IN A 10.10.10.73
worker4.test.co.id. IN A 10.10.10.74
Create the reverse zone file:
sudo vi /var/named/internal-colocation.rev$TTL 604800
@ IN SOA test.co.id. admin.test.co.id. (
2024052301 ; Serial
604800 ; Refresh
86400 ; Retry
2419200 ; Expire
604800 ) ; Negative Cache TTL
; Name Server
@ IN NS confluent.test.co.id.
; Reverse DNS Records
109 IN PTR confluent.test.co.id.
101 IN PTR oracle.test.co.id.
102 IN PTR db2-primary.test.co.id.
105 IN PTR data-warehouse.test.co.id.
106 IN PTR db2-standby.test.co.id.
107 IN PTR transform-engine.test.co.id.
71 IN PTR worker1.test.co.id.
72 IN PTR worker2.test.co.id.
73 IN PTR worker3.test.co.id.
74 IN PTR worker4.test.co.id.
| Hostname | IP Address |
|---|---|
confluent.test.co.id |
10.10.10.109 |
oracle.test.co.id |
10.10.10.101 |
db2-primary.test.co.id |
10.10.10.102 |
data-warehouse.test.co.id |
10.10.10.105 |
db2-standby.test.co.id |
10.10.10.106 |
transform-engine.test.co.id |
10.10.10.107 |
worker1.test.co.id |
10.10.10.71 |
worker2.test.co.id |
10.10.10.72 |
worker3.test.co.id |
10.10.10.73 |
worker4.test.co.id |
10.10.10.74 |
Before starting or reloading the DNS service, validate the main configuration:
sudo named-checkconfIf there is no output, the configuration syntax is valid.
sudo named-checkzone \
test.co.id \
/var/named/internal-colocation.zoneExpected result:
zone test.co.id/IN: loaded serial 2025052302
OK
sudo named-checkzone \
10.10.10.in-addr.arpa \
/var/named/internal-colocation.revExpected result:
zone 10.10.10.in-addr.arpa/IN: loaded serial 2024052301
OK
Ensure the zone files have the correct ownership:
sudo chown root:named /var/named/internal-colocation.zone
sudo chown root:named /var/named/internal-colocation.revSet the appropriate permissions:
sudo chmod 640 /var/named/internal-colocation.zone
sudo chmod 640 /var/named/internal-colocation.revRestore the default SELinux context:
sudo restorecon -Rv /var/namedVerify the SELinux labels:
ls -lZ /var/named/internal-colocation.*sudo systemctl start namedCheck service status:
sudo systemctl status namedsudo systemctl stop namedsudo systemctl restart namedReload the complete DNS configuration:
sudo rndc reloadReload only the forward zone:
sudo rndc reload test.co.idReload the reverse zone:
sudo rndc reload 10.10.10.in-addr.arpaVerify that named is listening on port 53.
sudo ss -lntup | grep :53Expected service:
10.10.10.109:53
127.0.0.1:53
Test the DNS server directly.
dig @10.10.10.109 confluent.test.co.idTest another internal record:
dig @10.10.10.109 data-warehouse.test.co.idSimple lookup:
nslookup db2-primary.test.co.id 10.10.10.109Example:
Name: db2-primary.test.co.id
Address: 10.10.10.102
Test reverse DNS lookup:
dig -x 10.10.10.109 @10.10.10.109Expected result:
109.10.10.10.in-addr.arpa. IN PTR confluent.test.co.id.
Test another server:
dig -x 10.10.10.105 @10.10.10.109Expected result:
105.10.10.10.in-addr.arpa. IN PTR data-warehouse.test.co.id.
Configure the NetworkManager connection to use the internal DNS server.
sudo nmcli con mod ens33 ipv4.dns "10.10.10.109"
sudo nmcli con mod ens33 ipv4.ignore-auto-dns yes
sudo nmcli con up ens33Verify the DNS configuration:
nmcli dev show ens33 | grep DNSAlternative verification:
cat /etc/resolv.confExpected DNS server:
nameserver 10.10.10.109
After configuring the DNS client, test the internal records:
getent hosts data-warehouse.test.co.idgetent hosts db2-primary.test.co.idgetent hosts worker1.test.co.idTest reverse lookup:
getent hosts 10.10.10.105When adding, removing, or modifying a DNS record:
- Edit the appropriate zone file.
- Increase the zone serial number.
- Validate the zone syntax.
- Reload the updated zone.
- Verify the DNS record.
Previous serial:
2025052302
New serial:
2025052303
Example:
@ IN SOA test.co.id. admin.test.co.id. (
2025052303 ; Serial
604800 ; Refresh
86400 ; Retry
2419200 ; Expire
604800 ) ; Negative Cache TTL
Important: Every modification to a zone file should be followed by a serial number increment.
sudo vi /var/named/internal-colocation.zoneExample:
2025052302
Change to:
2025052303
sudo named-checkzone \
test.co.id \
/var/named/internal-colocation.zonesudo rndc reload test.co.iddig @10.10.10.109 <hostname>.test.co.idsudo systemctl status namedsudo journalctl -u named -fsudo named-checkconfsudo named-checkzone \
test.co.id \
/var/named/internal-colocation.zonesudo named-checkzone \
10.10.10.in-addr.arpa \
/var/named/internal-colocation.revsudo ss -lntup | grep :53dig @10.10.10.109 test.co.iddig -x 10.10.10.109 @10.10.10.109- BIND and BIND utilities are installed.
- The
namedservice is enabled. - The trusted network ACL is configured.
- DNS is listening on
10.10.10.109. - The forward zone is configured.
- The reverse zone is configured.
- The zone serial number is valid.
- The forward zone passes
named-checkzone. - The reverse zone passes
named-checkzone. - The main configuration passes
named-checkconf. - Zone file ownership is configured correctly.
- SELinux context is configured correctly.
- The
namedservice is running. - Forward DNS resolution is successful.
- Reverse DNS resolution is successful.
- Client DNS configuration points to
10.10.10.109. - Internal hosts can resolve all required records.
Serial Number Management
Always increase the SOA serial number whenever the zone file is modified.
DNS Reload
Use
rndc reload <zone>when only one zone has been modified. This is preferable to restarting the entire DNS service.
Production Consideration
For a production environment, consider using:
- Multiple DNS servers
- Secondary/slave DNS zones
- Restricted recursion
- Internal upstream DNS forwarders
- Firewall rules for TCP and UDP port
53- Automated configuration backup
Security
The configuration should allow DNS queries only from trusted networks and localhost unless external DNS access is explicitly required.