Bv9ARM.ch04.html revision adc714a24a1ae71bfcfe8833d9f314864c3f073b
fa9e4066f08beec538e775443c5be79dd423fcabahrens>Advanced Concepts</TITLE
99653d4ee642c6528e88224f12409a5f23060994eschrockNAME="GENERATOR"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCONTENT="Modular DocBook HTML Stylesheet Version 1.41"><LINK
fa9e4066f08beec538e775443c5be79dd423fcabahrensREL="PREVIOUS"
fa9e4066f08beec538e775443c5be79dd423fcabahrensTITLE="Nameserver Configuration"
fa9e4066f08beec538e775443c5be79dd423fcabahrensTITLE="The BIND 9 Lightweight Resolver"
fa9e4066f08beec538e775443c5be79dd423fcabahrensBGCOLOR="#FFFFFF"
fa9e4066f08beec538e775443c5be79dd423fcabahrensTEXT="#000000"
fa9e4066f08beec538e775443c5be79dd423fcabahrensLINK="#0000FF"
fa9e4066f08beec538e775443c5be79dd423fcabahrensVLINK="#840084"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlALINK="#0000FF"
d87468da622d0a816b26cc636aa7dcc08249300ermCLASS="NAVHEADER"
2b61b799b28717ea21febf9eab30c7867477f280mmusanteWIDTH="100%"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCELLPADDING="0"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCELLSPACING="0"
fa9e4066f08beec538e775443c5be79dd423fcabahrensALIGN="center"
fa9e4066f08beec538e775443c5be79dd423fcabahrensALIGN="left"
fa9e4066f08beec538e775443c5be79dd423fcabahrensVALIGN="bottom"
fa9e4066f08beec538e775443c5be79dd423fcabahrensALIGN="center"
fa9e4066f08beec538e775443c5be79dd423fcabahrensVALIGN="bottom"
fa9e4066f08beec538e775443c5be79dd423fcabahrensALIGN="right"
fa9e4066f08beec538e775443c5be79dd423fcabahrensVALIGN="bottom"
fa9e4066f08beec538e775443c5be79dd423fcabahrensALIGN="LEFT"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="chapter"
fa9e4066f08beec538e775443c5be79dd423fcabahrens>Chapter 4. Advanced Concepts</A
fa9e4066f08beec538e775443c5be79dd423fcabahrens>Table of Contents</B
99653d4ee642c6528e88224f12409a5f23060994eschrockHREF="Bv9ARM.ch04.html#dynamic_update"
99653d4ee642c6528e88224f12409a5f23060994eschrock>Dynamic Update</A
99653d4ee642c6528e88224f12409a5f23060994eschrockHREF="Bv9ARM.ch04.html#incremental_zone_transfers"
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock>Incremental Zone Transfers (IXFR)</A
fa9e4066f08beec538e775443c5be79dd423fcabahrens>Split DNS</A
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>IPv6 Support in <SPAN
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="acronym"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>BIND</SPAN
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="sect1"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="sect1"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlNAME="dynamic_update"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>4.1. Dynamic Update</A
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>Dynamic update is the term used for the ability under
cc4231e55a9c2eb07b3aa5b3e602a93d2415d284mmusante certain specified conditions to add, modify or delete records or
2b61b799b28717ea21febf9eab30c7867477f280mmusante RRsets in the master zone files. Dynamic update is fully described
2b61b799b28717ea21febf9eab30c7867477f280mmusante in RFC 2136.</P
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>Dynamic update is enabled on a zone-by-zone basis, by
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl including an <B
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="command"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>allow-update</B
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="command"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>update-policy</B
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl> clause in the
d5b4fe4dcc1b674d5e848db057a30cf882f73b22dougmCLASS="command"
d5b4fe4dcc1b674d5e848db057a30cf882f73b22dougm> statement.</P
d5b4fe4dcc1b674d5e848db057a30cf882f73b22dougm>Updating of secure zones (zones using DNSSEC) is modelled
d5b4fe4dcc1b674d5e848db057a30cf882f73b22dougm after the <I
0069fd67511146f5f43175204d5b71d2b357be71Tim HaleyCLASS="emphasis"
d5b4fe4dcc1b674d5e848db057a30cf882f73b22dougm>simple-secure-update</I
d5b4fe4dcc1b674d5e848db057a30cf882f73b22dougm> proposal, a
d5b4fe4dcc1b674d5e848db057a30cf882f73b22dougm work in progress in the DNS Extensions working group of the IETF.
d5b4fe4dcc1b674d5e848db057a30cf882f73b22dougmHREF="http://www.ietf.org/html.charters/dnsext-charter.html"
d5b4fe4dcc1b674d5e848db057a30cf882f73b22dougmTARGET="_top"
d5b4fe4dcc1b674d5e848db057a30cf882f73b22dougm>http://www.ietf.org/html.charters/dnsext-charter.html</A
e7437265dc2a4920c197ed4337665539d358b22cahrens for information about the DNS Extensions working group.) SIG and
fa9e4066f08beec538e775443c5be79dd423fcabahrens NXT records affected by updates are automatically regenerated by
fa9e4066f08beec538e775443c5be79dd423fcabahrens the server using an online zone key. Update authorization is based
2b61b799b28717ea21febf9eab30c7867477f280mmusante on transaction signatures and an explicit server policy.</P
2b61b799b28717ea21febf9eab30c7867477f280mmusante>The zone files of dynamic zones cannot normally be edited by hand.
fa9e4066f08beec538e775443c5be79dd423fcabahrens The zone file on disk at any given time may not contain the latest
fa9e4066f08beec538e775443c5be79dd423fcabahrens changes performed by dynamic update. The zone file is only
fa9e4066f08beec538e775443c5be79dd423fcabahrens written to disk only occasionally, and when shutting down the server using
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="command"
fa9e4066f08beec538e775443c5be79dd423fcabahrens>rndc stop</B
fa9e4066f08beec538e775443c5be79dd423fcabahrens>. Changes that have occurred since the
fa9e4066f08beec538e775443c5be79dd423fcabahrens zone file was last written to disk are stored only in the zone's
fa9e4066f08beec538e775443c5be79dd423fcabahrens journal (<TT
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrens>If you have to make changes to a dynamic zone
fa9e4066f08beec538e775443c5be79dd423fcabahrens manually, the following procedure will work: Shut down
fa9e4066f08beec538e775443c5be79dd423fcabahrens the server using <B
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="command"
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drm>rndc stop</B
6733190958bbcc0bd6d1d601e7ae0a6994dafb45dougm> (sending a signal
fa9e4066f08beec538e775443c5be79dd423fcabahrens or using <B
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="command"
fa9e4066f08beec538e775443c5be79dd423fcabahrens>rndc halt</B
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="emphasis"
fa9e4066f08beec538e775443c5be79dd423fcabahrens sufficient). Wait for the server to exit,
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="emphasis"
fa9e4066f08beec538e775443c5be79dd423fcabahrens> the zone's
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
6733190958bbcc0bd6d1d601e7ae0a6994dafb45dougm> file, edit the zone file,
6733190958bbcc0bd6d1d601e7ae0a6994dafb45dougm and restart the server. Removing the <TT
6733190958bbcc0bd6d1d601e7ae0a6994dafb45dougmCLASS="filename"
6733190958bbcc0bd6d1d601e7ae0a6994dafb45dougm file is necessary because the manual edits will not be
d8689a57b109f75e2654627f1847266e18f5a7f2dougm present in the journal, rendering it inconsistent with the
d8689a57b109f75e2654627f1847266e18f5a7f2dougm contents of the zone file.</P
6733190958bbcc0bd6d1d601e7ae0a6994dafb45dougmCLASS="sect1"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="sect1"
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drmNAME="incremental_zone_transfers"
fa9e4066f08beec538e775443c5be79dd423fcabahrens>4.2. Incremental Zone Transfers (IXFR)</A
3a55fc6b85230272df26c2c8c82f1176c0503e3arm>The incremental zone transfer (IXFR) protocol is a way for
3a55fc6b85230272df26c2c8c82f1176c0503e3arm slave servers to transfer only changed data, instead of having to
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw transfer the entire zone. The IXFR protocol is documented in RFC
3a55fc6b85230272df26c2c8c82f1176c0503e3arm 1995. See <A
fa9e4066f08beec538e775443c5be79dd423fcabahrensHREF="Bv9ARM.ch09.html#proposed_standards"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>Proposed Standards</I
fa9e4066f08beec538e775443c5be79dd423fcabahrens>When acting as a master, <SPAN
cc4231e55a9c2eb07b3aa5b3e602a93d2415d284mmusanteCLASS="acronym"
2b61b799b28717ea21febf9eab30c7867477f280mmusante> 9 supports IXFR for those zones
2b61b799b28717ea21febf9eab30c7867477f280mmusantewhere the necessary change history information is available. These
2b61b799b28717ea21febf9eab30c7867477f280mmusanteinclude master zones maintained by dynamic update and slave zones
fa9e4066f08beec538e775443c5be79dd423fcabahrenswhose data was obtained by IXFR, but not manually maintained master
fa9e4066f08beec538e775443c5be79dd423fcabahrenszones nor slave zones obtained by performing a full zone transfer
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>When acting as a slave, <SPAN
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="acronym"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>BIND</SPAN
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl> 9 will attempt to use IXFR unless
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlit is explicitly disabled. For more information about disabling
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlIXFR, see the description of the <B
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drmCLASS="command"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>request-ixfr</B
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="command"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl> statement.</P
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drmCLASS="sect1"
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drmCLASS="sect1"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlNAME="AEN663"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>4.3. Split DNS</A
fa9e4066f08beec538e775443c5be79dd423fcabahrens>Setting up different views, or visibility, of DNS space to
fa9e4066f08beec538e775443c5be79dd423fcabahrensinternal and external resolvers is usually referred to as a <I
3a55fc6b85230272df26c2c8c82f1176c0503e3armCLASS="emphasis"
3a55fc6b85230272df26c2c8c82f1176c0503e3arm> setup. There are several reasons an organization
3a55fc6b85230272df26c2c8c82f1176c0503e3armwould want to set up its DNS this way.</P
3a55fc6b85230272df26c2c8c82f1176c0503e3arm>One common reason for setting up a DNS system this way is
3a55fc6b85230272df26c2c8c82f1176c0503e3armto hide "internal" DNS information from "external" clients on the
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwInternet. There is some debate as to whether or not this is actually useful.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwInternal DNS information leaks out in many ways (via email headers,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwfor example) and most savvy "attackers" can find the information
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwthey need using other means.</P
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw>Another common reason for setting up a Split DNS system is
fa9e4066f08beec538e775443c5be79dd423fcabahrensto allow internal networks that are behind filters or in RFC 1918
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drmspace (reserved IP space, as documented in RFC 1918) to resolve DNS
fa9e4066f08beec538e775443c5be79dd423fcabahrenson the Internet. Split DNS can also be used to allow mail from outside
fa9e4066f08beec538e775443c5be79dd423fcabahrensback in to the internal network.</P
fa9e4066f08beec538e775443c5be79dd423fcabahrens>Here is an example of a split DNS setup:</P
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drm>Let's say a company named <I
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drmCLASS="emphasis"
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drm>Example, Inc.</I
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drmhas several corporate sites that have an internal network with reserved
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drmInternet Protocol (IP) space and an external demilitarized zone (DMZ),
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drmor "outside" section of a network, that is available to the public.</P
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="emphasis"
3d7934e1eaaab784a1928c5c9bdb6273eeb7275drm>Example, Inc.</I
fa9e4066f08beec538e775443c5be79dd423fcabahrens> wants its internal clients
fa9e4066f08beec538e775443c5be79dd423fcabahrensto be able to resolve external hostnames and to exchange mail with
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingpeople on the outside. The company also wants its internal resolvers
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingto have access to certain internal-only zones that are not available
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingat all outside of the internal network.</P
55406565bb21da3b769184726b3306b334df62e9mmusante>In order to accomplish this, the company will set up two sets
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingof nameservers. One set will be on the inside network (in the reserved
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingIP space) and the other set will be on bastion hosts, which are "proxy"
b12a1c38fc215cc54fa6014069fd2b8dbb496646llinghosts that can talk to both sides of its network, in the DMZ.</P
b12a1c38fc215cc54fa6014069fd2b8dbb496646lling>The internal servers will be configured to forward all queries,
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingexcept queries for <TT
55406565bb21da3b769184726b3306b334df62e9mmusanteCLASS="filename"
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingCLASS="filename"
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingCLASS="filename"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="filename"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>, to the servers in the
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlDMZ. These internal servers will have complete sets of information
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="emphasis"
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingCLASS="filename"
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrens>To protect the <TT
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensthe internal nameservers must be configured to disallow all queries
fa9e4066f08beec538e775443c5be79dd423fcabahrensto these domains from any external hosts, including the bastion
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw>The external servers, which are on the bastion hosts, will
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwbe configured to serve the "public" version of the <TT
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensThis could include things such as the host records for public servers
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensand mail exchange (MX) records (<TT
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>In addition, the public <TT
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
fa9e4066f08beec538e775443c5be79dd423fcabahrensshould have special MX records that contain wildcard (`*') records
fa9e4066f08beec538e775443c5be79dd423fcabahrenspointing to the bastion hosts. This is needed because external mail
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingservers do not have any other way of looking up how to deliver mail
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingto those internal hosts. With the wildcard records, the mail will
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingbe delivered to the bastion host, which can then forward it on to
b12a1c38fc215cc54fa6014069fd2b8dbb496646llinginternal hosts.</P
b12a1c38fc215cc54fa6014069fd2b8dbb496646lling>Here's an example of a wildcard MX record:</P
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingCLASS="programlisting"
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingCLASS="literal"
b12a1c38fc215cc54fa6014069fd2b8dbb496646lling>Now that they accept mail on behalf of anything in the internal
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingnetwork, the bastion hosts will need to know how to deliver mail
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingto internal hosts. In order for this to work properly, the resolvers on
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingthe bastion hosts will need to be configured to point to the internal
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingnameservers for DNS resolution.</P
b12a1c38fc215cc54fa6014069fd2b8dbb496646lling>Queries for internal hostnames will be answered by the internal
fa9e4066f08beec538e775443c5be79dd423fcabahrensservers, and queries for external hostnames will be forwarded back
fa9e4066f08beec538e775443c5be79dd423fcabahrensout to the DNS servers on the bastion hosts.</P
fa9e4066f08beec538e775443c5be79dd423fcabahrens>In order for all this to work properly, internal clients will
fa9e4066f08beec538e775443c5be79dd423fcabahrensneed to be configured to query <I
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="emphasis"
68f944b71d3feda491e30f04cc360be6cdb79f21eschrock> the internal
fa9e4066f08beec538e775443c5be79dd423fcabahrensnameservers for DNS queries. This could also be enforced via selective
94de1d4cf6ec0a3bf040dcc4b8df107c4ed36b51eschrockfiltering on the network.</P
68f944b71d3feda491e30f04cc360be6cdb79f21eschrock>If everything has been set properly, <I
94de1d4cf6ec0a3bf040dcc4b8df107c4ed36b51eschrockCLASS="emphasis"
94de1d4cf6ec0a3bf040dcc4b8df107c4ed36b51eschrock>Example, Inc.</I
fa9e4066f08beec538e775443c5be79dd423fcabahrensinternal clients will now be able to:</P
fa9e4066f08beec538e775443c5be79dd423fcabahrens>Look up any hostnames in the <TT
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="literal"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="literal"
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw>Look up any hostnames in the <TT
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="literal"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="literal"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl> domains.</P
fa9e4066f08beec538e775443c5be79dd423fcabahrens>Look up any hostnames on the Internet.</P
99653d4ee642c6528e88224f12409a5f23060994eschrock>Exchange mail with internal AND external people.</P
fa9e4066f08beec538e775443c5be79dd423fcabahrens>Hosts on the Internet will be able to:</P
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw>Look up any hostnames in the <TT
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwCLASS="literal"
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwCLASS="literal"
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw> zones.</P
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw>Exchange mail with anyone in the <TT
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwCLASS="literal"
99653d4ee642c6528e88224f12409a5f23060994eschrockCLASS="literal"
0069fd67511146f5f43175204d5b71d2b357be71Tim Haley>Here is an example configuration for the setup we just
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl described above. Note that this is only configuration information;
fa9e4066f08beec538e775443c5be79dd423fcabahrens for information on how to configure your zone files, see <A
cc4231e55a9c2eb07b3aa5b3e602a93d2415d284mmusanteHREF="Bv9ARM.ch03.html#sample_configuration"
fa9e4066f08beec538e775443c5be79dd423fcabahrens>Section 3.1</A
99653d4ee642c6528e88224f12409a5f23060994eschrock>Internal DNS server config:</P
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="programlisting"
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrockacl externals { <TT
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrockCLASS="varname"
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock>bastion-ips-go-here</TT
b12a1c38fc215cc54fa6014069fd2b8dbb496646lling forward only;
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock forwarders { // forward to external servers
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrockCLASS="varname"
fa9e4066f08beec538e775443c5be79dd423fcabahrens>bastion-ips-go-here</TT
fa9e4066f08beec538e775443c5be79dd423fcabahrens allow-transfer { none; }; // sample allow-transfer (no one)
fa9e4066f08beec538e775443c5be79dd423fcabahrens allow-query { internals; externals; }; // restrict query access
fa9e4066f08beec538e775443c5be79dd423fcabahrens allow-recursion { internals; }; // restrict recursion
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrockzone "site1.example.com" { // sample slave zone
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock type master;
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock forwarders { }; // do normal iterative
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock // resolution (do not forward)
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock allow-query { internals; externals; };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock allow-transfer { internals; };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock type slave;
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock masters { 172.16.72.3; };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock forwarders { };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock allow-query { internals; externals; };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock allow-transfer { internals; };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock type master;
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock forwarders { };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock allow-query { internals; };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock allow-transfer { internals; }
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock type slave;
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock masters { 172.16.72.3; };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock forwarders { };
fa9e4066f08beec538e775443c5be79dd423fcabahrens allow-query { internals };
fa9e4066f08beec538e775443c5be79dd423fcabahrens allow-transfer { internals; }
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>External (bastion host) DNS server config:</P
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="programlisting"
fa9e4066f08beec538e775443c5be79dd423fcabahrens> acl internals { 172.16.72.0/24; 192.168.1.0/24; };
0069fd67511146f5f43175204d5b71d2b357be71Tim Haleyacl externals { bastion-ips-go-here; };
fa9e4066f08beec538e775443c5be79dd423fcabahrens allow-transfer { none; }; // sample allow-transfer (no one)
fa9e4066f08beec538e775443c5be79dd423fcabahrens allow-query { internals; externals; }; // restrict query access
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock allow-recursion { internals; externals; }; // restrict recursion
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrockzone "site1.example.com" { // sample slave zone
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock type master;
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock allow-query { any; };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock allow-transfer { internals; externals; };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock type slave;
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock masters { another_bastion_host_maybe; };
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock allow-query { any; };
fa9e4066f08beec538e775443c5be79dd423fcabahrens allow-transfer { internals; externals; }
94de1d4cf6ec0a3bf040dcc4b8df107c4ed36b51eschrockCLASS="filename"
94de1d4cf6ec0a3bf040dcc4b8df107c4ed36b51eschrock> (or equivalent) on
94de1d4cf6ec0a3bf040dcc4b8df107c4ed36b51eschrockthe bastion host(s):</P
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="programlisting"
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock> search ...
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrocknameserver 172.16.72.2
0069fd67511146f5f43175204d5b71d2b357be71Tim Haleynameserver 172.16.72.3
0069fd67511146f5f43175204d5b71d2b357be71Tim Haleynameserver 172.16.72.4
94de1d4cf6ec0a3bf040dcc4b8df107c4ed36b51eschrockCLASS="sect1"
94de1d4cf6ec0a3bf040dcc4b8df107c4ed36b51eschrockCLASS="sect1"
fa9e4066f08beec538e775443c5be79dd423fcabahrens>4.4. TSIG</A
fa9e4066f08beec538e775443c5be79dd423fcabahrens>This is a short guide to setting up Transaction SIGnatures
b12a1c38fc215cc54fa6014069fd2b8dbb496646lling(TSIG) based transaction security in <SPAN
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="acronym"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>BIND</SPAN
fa9e4066f08beec538e775443c5be79dd423fcabahrens>. It describes changes
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingto the configuration file as well as what changes are required for
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingdifferent features, including the process of creating transaction
99653d4ee642c6528e88224f12409a5f23060994eschrockkeys and using transaction signatures with <SPAN
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingCLASS="acronym"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlCLASS="acronym"
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>BIND</SPAN
e7437265dc2a4920c197ed4337665539d358b22cahrens> primarily supports TSIG for server to server communication.
e7437265dc2a4920c197ed4337665539d358b22cahrensThis includes zone transfer, notify, and recursive query messages.
fa9e4066f08beec538e775443c5be79dd423fcabahrensResolvers based on newer versions of <SPAN
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="acronym"
fa9e4066f08beec538e775443c5be79dd423fcabahrens> 8 have limited support
fa9e4066f08beec538e775443c5be79dd423fcabahrensfor TSIG.</P
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl>TSIG might be most useful for dynamic update. A primary
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw server for a dynamic zone should use access control to control
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahl updates, but IP-based access control is insufficient. Key-based
fa9e4066f08beec538e775443c5be79dd423fcabahrens access control is far superior, see <A
fa9e4066f08beec538e775443c5be79dd423fcabahrensHREF="Bv9ARM.ch09.html#proposed_standards"
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw>Proposed Standards</I
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwCLASS="command"
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw>nsupdate</B
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw program supports TSIG via the <TT
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwCLASS="option"
b12a1c38fc215cc54fa6014069fd2b8dbb496646llingCLASS="option"
b12a1c38fc215cc54fa6014069fd2b8dbb496646lling> command line options.</P
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="sect2"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="sect2"
fa9e4066f08beec538e775443c5be79dd423fcabahrensNAME="AEN754"
fa9e4066f08beec538e775443c5be79dd423fcabahrens>4.4.1. Generate Shared Keys for Each Pair of Hosts</A
990b4856d0eaada6f8140335733a1b1771ed2746lling>A shared secret is generated to be shared between <I
99653d4ee642c6528e88224f12409a5f23060994eschrockCLASS="emphasis"
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="emphasis"
fa9e4066f08beec538e775443c5be79dd423fcabahrensAn arbitrary key name is chosen: "host1-host2.". The key name must
fa9e4066f08beec538e775443c5be79dd423fcabahrensbe the same on both hosts.</P
99653d4ee642c6528e88224f12409a5f23060994eschrockCLASS="sect3"
99653d4ee642c6528e88224f12409a5f23060994eschrockCLASS="sect3"
99653d4ee642c6528e88224f12409a5f23060994eschrockNAME="AEN759"
99653d4ee642c6528e88224f12409a5f23060994eschrock>4.4.1.1. Automatic Generation</A
0069fd67511146f5f43175204d5b71d2b357be71Tim Haley>The following command will generate a 128 bit (16 byte) HMAC-MD5
f3861e1a2ceec23a5b699c24d814b7775a9e0b52ahlkey as described above. Longer keys are better, but shorter keys
fa9e4066f08beec538e775443c5be79dd423fcabahrensare easier to read. Note that the maximum key length is 512 bits;
cc4231e55a9c2eb07b3aa5b3e602a93d2415d284mmusantekeys longer than that will be digested with MD5 to produce a 128
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrockCLASS="userinput"
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock>dnssec-keygen -a hmac-md5 -b 128 -n HOST host1-host2.</B
3bb79bece53191f2cf27aa61a72ea1784a7ce700eschrock>The key is in the file <TT
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="filename"
3a55fc6b85230272df26c2c8c82f1176c0503e3armNothing directly uses this file, but the base-64 encoded string
fa9e4066f08beec538e775443c5be79dd423fcabahrensfollowing "<TT
3a55fc6b85230272df26c2c8c82f1176c0503e3armCLASS="literal"
a227b7f4f323ad89c40a86c430a5e891504a8e8bhscan be extracted from the file and used as a shared secret:</P
a227b7f4f323ad89c40a86c430a5e891504a8e8bhsCLASS="programlisting"
a227b7f4f323ad89c40a86c430a5e891504a8e8bhs>The string "<TT
a227b7f4f323ad89c40a86c430a5e891504a8e8bhsCLASS="literal"
a227b7f4f323ad89c40a86c430a5e891504a8e8bhsbe used as the shared secret.</P
fa9e4066f08beec538e775443c5be79dd423fcabahrensCLASS="sect3"
HREF="Bv9ARM.ch06.html#dynamic_update_policies"
that the tools shipped with BIND 9.0.x are not fully compatible
HREF="Bv9ARM.ch05.html"
> $ORIGIN example.com.
> $ORIGIN example.com.
> $ORIGIN example.com.
host 3600 IN A6 64 0:0:0:0:42::1 company.example1.net.
host 3600 IN A6 64 0:0:0:0:42::1 company.example2.net.
> $ORIGIN example1.net.
> $ORIGIN example2.net.
> $ORIGIN example.com.
> $ORIGIN 0.6.8.1.1.0.2.0.0.5.0.8.e.f.f.3.ip6.int.
1.0.0.0.0.0.0.0.0.0.0.0.2.4.0.0 14400 IN PTR host.example.com.
> $ORIGIN example.com.
host A6 64 ::1234:5678:1212:5675 cust1.example.net.
A6 64 ::1234:5678:1212:5675 subnet5.example2.net.
$ORIGIN example.net.
cust1 A6 48 0:0:0:dddd:: ipv6net.example.net.
$ORIGIN example2.net.
subnet5 A6 48 0:0:0:1:: ipv6net2.example2.net.
> $ORIGIN ipv6-rev.example.com.
HREF="Bv9ARM.ch03.html"
HREF="Bv9ARM.html"
HREF="Bv9ARM.ch05.html"