Добрый день, не получается настроить master/slave dns, прошу помощи. Вот что я делаю
MASTER
/etc/named.conf
options {
directory "/var/named";
dump-file "/var/named/data/cache_dump.db";
statistics-file "/var/named/data/named_stats.txt";
memstatistics-file "/var/named/data/named_mem_stats.txt";
recursion yes;
allow-query { any; };
version "Forbidden";
listen-on { ip-master; 127.0.0.1; };
allow-recursion { none; };
allow-transfer { ip-slave; };
dnssec-enable yes;
dnssec-validation yes;
dnssec-lookaside auto;
/* Path to ISC DLV key */
bindkeys-file "/etc/named.iscdlv.key";
managed-keys-directory "/var/named/dynamic";
};
...
zone "site.com" IN {
type master;
file "/var/named/master/site.com";
allow-transfer { ip-slave; };
notify yes;
};
далее описываю зону в /var/named/master/site.com
SLAVE
options {
//listen-on port 53 { 127.0.0.1; };
listen-on port 53 { ip-slave; 127.0.0.1; };
listen-on-v6 port 53 { none; };
version "No info";
directory "/var/named";
dump-file "/var/named/data/cache_dump.db";
statistics-file "/var/named/data/named_stats.txt";
memstatistics-file "/var/named/data/named_mem_stats.txt";
//allow-query { localhost; };
allow-query { any; };
recursion yes;
allow-recursion { none; };
dnssec-enable yes;
dnssec-validation yes;
dnssec-lookaside auto;
/* Path to ISC DLV key */
bindkeys-file "/etc/named.iscdlv.key";
managed-keys-directory "/var/named/dynamic";
};
...
zone "site.com" IN {
type slave;
file "/var/named/dinhost-slave/site-slave.conf";
masters { ip-master; };
};
рестартую оба бинда и мастер не копирует в слэйв
команда dig @ns1.site.com site.com. axfr выдает
; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.17.rc1.el6.3 <<>> @ns1.site.com site.com. axfr
; (1 server found)
;; global options: +cmd
; Transfer failed.
отключал на обоих серверах iptables эффект тот же.