ΪʲôҪʹÓÃÕý·´½âÎöÓòÃû?
[DNS] reverse domain µÄʹÓÃʱ»ú (long)
ժҪ˵Ã÷:
1.ÓÉ IP addr. ÕÒʹÓõ¥Î»
2.reverse DNS ϵͳµÄʹÓÃʱ»ú
3.DNS Caching ( positive & negative caching )
4.¶Ô SPAM (e-mail, usenet), Ò»°ã¹ÜÀíÕ߸ÃÓеÄÈÏÖªÓëÅäºÏ´ëÊ©
--------------------------------------------------------------------------------
Ðí¶àÈË¶Ô DNS µÄÔË×÷, ͨ³£ÊÇÒ»Öª°ë½â. ¼´Ê¹ÊÇÏà¹ØÏµÍ³µÄʵ¼Ê¸ºÔðÈË,
¶ÔÕû¸öϵͳ, ÓÐʱºò, »¹ÊÇÓÐÒ»Ð©ËÆÊǶø·ÇµÄ¹ÛÄî.
ÉõÖÁ, »¹ÓÐЩµ¥Î»µÄ¹ÜÀíÕß, ˵ÊÇ»ùì¶ security µÄ¿¼Á¿, ËùÒÔ²»Éè forward
and/or reverse domain name µÄ database.
´óÌåÉÏ, ²»¹ÜÊÇÒ»°ãʹÓÃÕß, »òϵͳ¹ÜÀíÔ±, ºÜ¶àÈ˶¼Á˽â forward domain zone,
µÄÖØÒªÓëÓ÷¨. Õâ, ²»´òËã¶à˵.
µ«ÊÇ reverse domain name µÄ database, ÔÚ¹úÄÚ, Æù½ñ»¹Ò»Ö±Ã»Óеõ½Ó¦ÓеÄÖØÊÓ.
-- Ðí¶àÈË, ¿ÉÄÜûÓг¢¹ý±» ftp.uu.net µÈ¹ú¼Ê×ÅÃûվ̨, access deny µÄ¾Ñé...
½ÓÏÂÀ´, 7/1 ÈÕ, Ò²ÐíÓÐÈË»áÓлú»á¼ûʶһÏÂ, ¹úÄÚվ̨µÄÁªºÏ access deny
»î¶¯...
ÎÊÌâ±³¾°ËµÃ÷
============
ĿǰµÄ Internet, SPAM (email spam, usenet spam, ...) µÄÇé¿ö. Ï൱ÆÕ±é
ÓÐЩµØ·½, ÔçÒѾÊǶñÃûÕÑÕÃ.
¶Ô¸¶ÕâÀàµÄ SPAM, ÉõÖÁ cracker ÐÐΪ, ·½Ê½ºÜ¶à. ÀíÂÛÉÏ, ÿ¸öÍøÕ¾, ¶¼¿ÉÄÜ
ÅöÉÏ»ò³öÏÖÕâÀ໵Åß. Òò´Ë, ´óÌåÉÏ, ¸÷µ¥Î»¹ÜÀíÕß, »ù±¾É϶¼ÊǶÔÕâÖÖÊÂÇé,
ÊÇÒÔ»¥Ïà°ïæΪǰÌá. µ«ÊÇʵ¼ÊµÄ case, ³£»áÒòΪÓб¾µ¥Î»µÄʹÓÃÕßÇ©ÉæÔÚÄÚ,
ͨ³£´¦ÀíÉÏ, ¶¼»áתÇ÷±£ÊØ, ±È½ÏСÐĽöÉ÷.
»ù±¾ÉÏ, ³öÎÊÌâʱ, ÓÉÍøÂ·ÉÏÆäËûµ¥Î», À´¿´Ä³Ò»¸öµ¥Î»ÍøÂ·¹ÜÀí, ×öµÃºÃ²»ºÃ
µÄ¼¸¸ö, ³£¼ûÆðÂëÒªÇó:
1) ¸Ãµ¥Î»µÄ reverse DNS ϵͳ, µÇ¼ÊÇ·ñÍêÕû.
2) "postmaster@your-domain-zone", "abuse@your-domain-zone"
µÈ e-mail addr. »á²»»á work.
3) mail ¼Ä¹ýÈ¥, ÓÐûÓлØÓ¦, ¼°Ïà¹Ø´¦Àí.
Èç¹ûÕâÀàµÄ×ÊÁϵǼ, or contact person ûÓÐ. »òÕß, e-mail response ûÓÐ,
ÖîÈç´ËÀà, ¿ÉÄÜÈÃÈË»áÓкõĹ۸ÐÂð ?
Èç¹û, ÉÔ×ö¼ìÊÓ. ¹úÄÚµÄÍøÕ¾, TANet, HiNet, SeedNet, ... µÈµÈ, Ðí¶àÍøÕ¾
Õâ·½Ãæ¶¼Ã»ÓÐ×öµÃºÜºÃ.
ÎÒÃÇ¿´ÊÂÇé, ͨ³£¶¼Ó¦¸Ã¿´, ÕûÌåµÄ±íÏÖ.
ÊÂÇéΪʲ÷áÊÇÏÖÔÚÕâ¸öÑù×Ó, ͨ³£¶¼ÊÇÓÐÔÒòµÄ, ÆäÀ´ÓÐ×Ô. µ½×îáá, ²»Íâºõ
¾ÍÊÇÒ»¸ö, È˵ÄÒòËØ. ÊÂÔÚÈËΪ(¿É²»ÊǵçÄÔ³Ìʽ¿ÉÒÔ¾ö¶¨), ÕâЩ¹ÜÀíÕß, ¹ÛÄî
ŪͨÁË, ʣϵÄ, ¾ÍºÃ°ìÁË.
×î½ü, ÒòΪÓÐÒ»¸ö DES µÄÃÜÂë, ¹²Í¬ÕÒ key µÄ»î¶¯, ÏÆÆðÁË, Ðí¶àÈË×¢Òâµ½,
reverse DNS Ãû³ÆÔÚÐí¶àÍøÂ·Ê¹ÓÃ, ͳ¼Æ±¨±íµÄ·½±ãÓëÒâÒå.
-- ÁíÒ»¸ö, ÈðÊ¿ÂåÉ̹ÜÀíѧԺµÄ¾¤ÕùÁ¦±¨¸æ, Ò²ÏÔʾÍåµÄÍøÕ¾, µÇ¼×ÊÁÏ,
ËÆºõ²ÐȱºÜ¶à.
--ÏñÕâÑù, ÎÒÃÇÆ¾Ê²÷áÈ¥¸ú APNIC ÕùÈ¡¸ü¶àµÄ¿ÉÓà IP address.
Æäʵ, ¸ü»ý¼«µØËµ, reverse domain name µÄµÇ¼Ç, »¹¿ÉÒÔ°ïæ×öºÜ¶àÊÂÇé.
* scecurity,
* ·½±ã access control
* ·½±ã load balancing µÈÉ趨.
µ×ÏÂ, ¾ÍÕë¶Ô security µÈ·½Ãæ, ÉÔΪ×öÑÓÉê˵Ã÷.
============================================
×î½ü, SeedNet ·½Ãæ, ¿ªÊ¼»ý¼«»ØÓ¦Õâ·½ÃæµÄ¶«Î÷, ¶ÔÍøÓѶøÑÔ, ËãÊǺÃÊÂÒ»¼þ.
-- ²»¹ý, ¼¼ÊõÉÏ, Ðí¶àµØ·½, »¹ÊǰëÉú²»Êì.
( Ò²ÐíÊÇ, ¹ÜÀíÕßתÊÖ¹ý¶àµÄááÒÉÖ¢Ö®Ò»°É )
µ×ϵÄÒ»¸öÀý×Ó, ˵Ã÷Ò»ÏÂ, Ò»¸ö reverse DNS É趨µÄÏà¹ØÉ趨, Óë DNS
ϵͳ, ºÍÆäËü AP µÄ»¥¶¯¹Ø.
Maggie Liang (liang@mozart.seed.net.tw) Ìáµ½:
: kftseng.bbs@bbs.ccu.edu.tw (ÂÞÔÆ°ãÈô) wrote:
: > Ç븺Ôð seednet dialup domain µÄ¹ÜÀíÕß×¢ÒâÒ»ÏÂ.
:
: ¿É·ñÖªµÀÊÇʲ÷áÎÊÌâÄØ£¿
:
: >Jun 1 10:30:35 ccnews nnrpd[16950]:
: > gethostbyaddr: s26-49.dialup.seed.net.tw != 139.175.26.49
ÕâÖÖѶϢËù±íʾµÄÒâÒå. ÊÇÕý·´½â domain name ²»Ò»ÖµÄÇé¿ö.
Ðí¶àµÄ AP, ÔÚ·¢ÏÖÁ½ÕßÓгöÈëʱ, ¾Í»á½«ÕâЩ×ÊѶ¼Ç¼ÏÂÀ´.
-- °üÀ¨ IP addr ºÍ forward domain name.
ÏÖÔÚµÄ AP,( Èç sendmail, news, ftp, rlogin, tcp wrapper, ...), Éè¼ÆÊ±,
´ó¸Å¶¼ÊÇÕâÑù×ö.
-------------------------------------------------------------------
1) ½ÓÊÕµ½Ò»¸ö IP addr. A µÄ connection ÐèÇó, ì¶ÊÇ͸¹ý reverse DNS È¥
ÕÒ³öÒ»¸ö¶ÔÓ¦µÄ forward domain name B. Èç¹ûÕÒ²»µ½, ¾ÍÍ£Ö¹.
* ì¶ÊÇ, ¹ÜÀíÕß, ¾Í¿ÉÒÔ¾ø¶¨, ½øÐÐ access deny, :-) !
2) ¸ù¾Ý²½Öè 1) ËùÕÒµ½Õý½â domain name B, È¥ forward DNS "²é", È¡µÃ
Ò»×é IP addr. C ( ¿ÉÄÜΪһ¸ö, or Á½¸öÒÔÉÏ, Èç multi-homed host,
³£¼ûµÃÏñ router ).
3) ±È¶Ô IP addr. A, ÊÇ·ñ°üÀ¨ÔÚ IP addr. C ÖÐ.
-- Èç¹û²»¶Ô, Ôòϵͳ»áÌá³ö¾¯¸æ. ²úÉúÈçÉÏÊöµÄѶϢ.
ÕâʱºòËù´ú±íµÄÒâÒå, Ò²ÐíÊÇ database ÓÐÎó. ÁíÍâÒ»ÖÖ¿ÉÄÜ, ¾ÍÊÇÔì¼Ù.
ÓÐʱºò, Ò»¸öµ¥Î»ËùÔÚµÄ forward & reverse domain zone, DNS ²á,
¼°×ÊÁÏά»¤, ·ÖÊô²»Í¬µ¥Î», ÓÐʱáá»á²úÉú, ×öÒµ²»Ð¡ÐÄ, Ò²»á²úÉúÕâÀàÇé¿ö.
-------------------------------------------------------------------
¼¸¸öÎÊÌâ:
========
Õë¶ÔÉÏÃæµÄÇé¿ö, ÎÒÃÇ¿ÉÄÜ»á²úÉúÐí¶àÎÊÌâ.
Q1: ϵͳΪʲ÷áÒªÕâ÷áÂé·³ ? ²½Öè 1). ×öÍêáá, ²»¾Í¿ÉÒÔÁË.
A: ¶à×ö 2) ºÍ 3), Ò»·½ÃæÊÇΪÁË security ÉϵĿ¼Á¿. ×ÜÊÇÒª¸üÉ÷Щ, ±ÜÃâ
ÓÐһЩµ¥Î», ºúÂÒÉèÉè, È»áá²úÉúһЪÂÒÆß°ËÔãѶϢ, ÈÏÒâÖ¸. »òÏݺ¦ËûÈË.
ÁíÍâһЩ»ý¼«µÄÒâÒå, ÊÇÓÐÀû access control. ·½±ã load balance ¹ÜÀíµÈ.
¾ÙÀý:
139.75.26.49, 192.72.90.129 ÕÕĿǰ¶¼ÊÇ SeedNet µÄÓà »§ IP.
±È½Ï *.seed.net.tw, ÄÄÒ»ÖֱȽÏÈÝÒ×±æÈÏ. Ö»ÒªÉÔΪÏëÒ»ÏÂ,
¾Í²»ÄÑÃ÷.
ÍøÂ·É쵀 traffic. ¶¼ÊÇÒÔ IP addr. µÄ×ÊѶÔÚÁ÷ͨ, µ½Ä¿µÄµØáá, Èç¹û¼º
·½µÄ reverse DNS ×ÊÁÏ, ûµÇ¼, ÄÇ÷á¶Ô·½Ðí¶à AP ÔÚ×÷ access control,
performance tuning ʱ, ½«±äµÃ·Ç³£À§ÄÑ.
ÓÈÆä, Ðí¶àµ¥Î»¶¼ÊDz»Á¬ÐøµÄ class C, IP address. ÔÚ·Ö±æÊ±¾Í¸üÀ§ÄÑÁË.
-----------------------------------------------------------------------
Q2: ²»Éè reverse DNS, Ö»ÓÐ forward domain name, ²»ÊDZȽÏÊ¡ÊÂ. ¿´À´ traffic
½ÏÉÙ, Á¬ 2), 3) ¶¼²»ÓÃÁË ?
A: ÊÂÇé²»ÊÇÕâÑùµÄ.
µ±ÄãËùÓÃµÄ DNS server NS1, µÚ 1 ´ÎÅÜÆðÀ´, ±»ÆäËü³Ìʽ, query µ½Ä³Ò»
±ÊÆäËü domain zone µÄ entry ʱ, ( ²»ÂÛ forward & reverse domain ),
Õâʱáá, NS1 ¶¼²»»áÓÐ answer (data), ì¶ÊÇÕâ¸ö NS1 , ±ã»á͸¹ýÕý³£Ìåϵ,
´Ó root ×îÉϲãµÄijһ¸ö DNS server (e.g. NS2) ÎÊÆð, һ·ÕÒÏÂÀ´, ÕÒµ½? ¸ºÔð¸Ã domain zone µÄijһ¸ö DNS server (e.g NS3). È»áá, NS1 ½« query
½»¸ø NS3, NS3 ÕÒÁË×Ô¼ºµÄ database ( ´æÔÚ memory ÖÐ, ÀíÏë״̬ ), Èç
¹ûÓÐÕâ±Ê×ÊÁÏ, ¾Í½«¸Ã answer, ½»¸ø NS1. ½ÓÏÂÀ´, NS1 ¾Í½«Õâ¸ö answer,
¼ÇÏÂÀ´. ( ÒÔÏ嵀 NS3 Ö¸, ¸ºÔðij domain zone µÄ DNS server Ö®Ò»)
ÒòΪÓÐ caching, Èç¹û¸ú×ÅÓÐÈË(³Ìʽ)ÔÙÎÊ, NS1 ¾Í¿ÉÒÔÂíÉϽ«´ð°¸»Ø¸øËü.
µ«ÊÇÈç¹û, NS3 ¸æËß NS1, ûÓÐÕâ±Ê query µÄ¶ÔÓ¦¼Ç¼. ÄÇ÷á NS1, ½ÓÏÂÀ´
»áÔõ÷á×ö ?
Èç¹û NS1 ÊÇ, ÔçÆÚµÄ BIND ( 4.9.5 or ÒÔÏÂ), ½Ó
ժҪ˵Ã÷:
1.ÓÉ IP addr. ÕÒʹÓõ¥Î»
2.reverse DNS ϵͳµÄʹÓÃʱ»ú
3.DNS Caching ( positive & negative caching )
4.¶Ô SPAM (e-mail, usenet), Ò»°ã¹ÜÀíÕ߸ÃÓеÄÈÏÖªÓëÅäºÏ´ëÊ©
--------------------------------------------------------------------------------
Ðí¶àÈË¶Ô DNS µÄÔË×÷, ͨ³£ÊÇÒ»Öª°ë½â. ¼´Ê¹ÊÇÏà¹ØÏµÍ³µÄʵ¼Ê¸ºÔðÈË,
¶ÔÕû¸öϵͳ, ÓÐʱºò, »¹ÊÇÓÐÒ»Ð©ËÆÊǶø·ÇµÄ¹ÛÄî.
ÉõÖÁ, »¹ÓÐЩµ¥Î»µÄ¹ÜÀíÕß, ˵ÊÇ»ùì¶ security µÄ¿¼Á¿, ËùÒÔ²»Éè forward
and/or reverse domain name µÄ database.
´óÌåÉÏ, ²»¹ÜÊÇÒ»°ãʹÓÃÕß, »òϵͳ¹ÜÀíÔ±, ºÜ¶àÈ˶¼Á˽â forward domain zone,
µÄÖØÒªÓëÓ÷¨. Õâ, ²»´òËã¶à˵.
µ«ÊÇ reverse domain name µÄ database, ÔÚ¹úÄÚ, Æù½ñ»¹Ò»Ö±Ã»Óеõ½Ó¦ÓеÄÖØÊÓ.
-- Ðí¶àÈË, ¿ÉÄÜûÓг¢¹ý±» ftp.uu.net µÈ¹ú¼Ê×ÅÃûվ̨, access deny µÄ¾Ñé...
½ÓÏÂÀ´, 7/1 ÈÕ, Ò²ÐíÓÐÈË»áÓлú»á¼ûʶһÏÂ, ¹úÄÚվ̨µÄÁªºÏ access deny
»î¶¯...
ÎÊÌâ±³¾°ËµÃ÷
============
ĿǰµÄ Internet, SPAM (email spam, usenet spam, ...) µÄÇé¿ö. Ï൱ÆÕ±é
ÓÐЩµØ·½, ÔçÒѾÊǶñÃûÕÑÕÃ.
¶Ô¸¶ÕâÀàµÄ SPAM, ÉõÖÁ cracker ÐÐΪ, ·½Ê½ºÜ¶à. ÀíÂÛÉÏ, ÿ¸öÍøÕ¾, ¶¼¿ÉÄÜ
ÅöÉÏ»ò³öÏÖÕâÀ໵Åß. Òò´Ë, ´óÌåÉÏ, ¸÷µ¥Î»¹ÜÀíÕß, »ù±¾É϶¼ÊǶÔÕâÖÖÊÂÇé,
ÊÇÒÔ»¥Ïà°ïæΪǰÌá. µ«ÊÇʵ¼ÊµÄ case, ³£»áÒòΪÓб¾µ¥Î»µÄʹÓÃÕßÇ©ÉæÔÚÄÚ,
ͨ³£´¦ÀíÉÏ, ¶¼»áתÇ÷±£ÊØ, ±È½ÏСÐĽöÉ÷.
»ù±¾ÉÏ, ³öÎÊÌâʱ, ÓÉÍøÂ·ÉÏÆäËûµ¥Î», À´¿´Ä³Ò»¸öµ¥Î»ÍøÂ·¹ÜÀí, ×öµÃºÃ²»ºÃ
µÄ¼¸¸ö, ³£¼ûÆðÂëÒªÇó:
1) ¸Ãµ¥Î»µÄ reverse DNS ϵͳ, µÇ¼ÊÇ·ñÍêÕû.
2) "postmaster@your-domain-zone", "abuse@your-domain-zone"
µÈ e-mail addr. »á²»»á work.
3) mail ¼Ä¹ýÈ¥, ÓÐûÓлØÓ¦, ¼°Ïà¹Ø´¦Àí.
Èç¹ûÕâÀàµÄ×ÊÁϵǼ, or contact person ûÓÐ. »òÕß, e-mail response ûÓÐ,
ÖîÈç´ËÀà, ¿ÉÄÜÈÃÈË»áÓкõĹ۸ÐÂð ?
Èç¹û, ÉÔ×ö¼ìÊÓ. ¹úÄÚµÄÍøÕ¾, TANet, HiNet, SeedNet, ... µÈµÈ, Ðí¶àÍøÕ¾
Õâ·½Ãæ¶¼Ã»ÓÐ×öµÃºÜºÃ.
ÎÒÃÇ¿´ÊÂÇé, ͨ³£¶¼Ó¦¸Ã¿´, ÕûÌåµÄ±íÏÖ.
ÊÂÇéΪʲ÷áÊÇÏÖÔÚÕâ¸öÑù×Ó, ͨ³£¶¼ÊÇÓÐÔÒòµÄ, ÆäÀ´ÓÐ×Ô. µ½×îáá, ²»Íâºõ
¾ÍÊÇÒ»¸ö, È˵ÄÒòËØ. ÊÂÔÚÈËΪ(¿É²»ÊǵçÄÔ³Ìʽ¿ÉÒÔ¾ö¶¨), ÕâЩ¹ÜÀíÕß, ¹ÛÄî
ŪͨÁË, ʣϵÄ, ¾ÍºÃ°ìÁË.
×î½ü, ÒòΪÓÐÒ»¸ö DES µÄÃÜÂë, ¹²Í¬ÕÒ key µÄ»î¶¯, ÏÆÆðÁË, Ðí¶àÈË×¢Òâµ½,
reverse DNS Ãû³ÆÔÚÐí¶àÍøÂ·Ê¹ÓÃ, ͳ¼Æ±¨±íµÄ·½±ãÓëÒâÒå.
-- ÁíÒ»¸ö, ÈðÊ¿ÂåÉ̹ÜÀíѧԺµÄ¾¤ÕùÁ¦±¨¸æ, Ò²ÏÔʾÍåµÄÍøÕ¾, µÇ¼×ÊÁÏ,
ËÆºõ²ÐȱºÜ¶à.
--ÏñÕâÑù, ÎÒÃÇÆ¾Ê²÷áÈ¥¸ú APNIC ÕùÈ¡¸ü¶àµÄ¿ÉÓà IP address.
Æäʵ, ¸ü»ý¼«µØËµ, reverse domain name µÄµÇ¼Ç, »¹¿ÉÒÔ°ïæ×öºÜ¶àÊÂÇé.
* scecurity,
* ·½±ã access control
* ·½±ã load balancing µÈÉ趨.
µ×ÏÂ, ¾ÍÕë¶Ô security µÈ·½Ãæ, ÉÔΪ×öÑÓÉê˵Ã÷.
============================================
×î½ü, SeedNet ·½Ãæ, ¿ªÊ¼»ý¼«»ØÓ¦Õâ·½ÃæµÄ¶«Î÷, ¶ÔÍøÓѶøÑÔ, ËãÊǺÃÊÂÒ»¼þ.
-- ²»¹ý, ¼¼ÊõÉÏ, Ðí¶àµØ·½, »¹ÊǰëÉú²»Êì.
( Ò²ÐíÊÇ, ¹ÜÀíÕßתÊÖ¹ý¶àµÄááÒÉÖ¢Ö®Ò»°É )
µ×ϵÄÒ»¸öÀý×Ó, ˵Ã÷Ò»ÏÂ, Ò»¸ö reverse DNS É趨µÄÏà¹ØÉ趨, Óë DNS
ϵͳ, ºÍÆäËü AP µÄ»¥¶¯¹Ø.
Maggie Liang (liang@mozart.seed.net.tw) Ìáµ½:
: kftseng.bbs@bbs.ccu.edu.tw (ÂÞÔÆ°ãÈô) wrote:
: > Ç븺Ôð seednet dialup domain µÄ¹ÜÀíÕß×¢ÒâÒ»ÏÂ.
:
: ¿É·ñÖªµÀÊÇʲ÷áÎÊÌâÄØ£¿
:
: >Jun 1 10:30:35 ccnews nnrpd[16950]:
: > gethostbyaddr: s26-49.dialup.seed.net.tw != 139.175.26.49
ÕâÖÖѶϢËù±íʾµÄÒâÒå. ÊÇÕý·´½â domain name ²»Ò»ÖµÄÇé¿ö.
Ðí¶àµÄ AP, ÔÚ·¢ÏÖÁ½ÕßÓгöÈëʱ, ¾Í»á½«ÕâЩ×ÊѶ¼Ç¼ÏÂÀ´.
-- °üÀ¨ IP addr ºÍ forward domain name.
ÏÖÔÚµÄ AP,( Èç sendmail, news, ftp, rlogin, tcp wrapper, ...), Éè¼ÆÊ±,
´ó¸Å¶¼ÊÇÕâÑù×ö.
-------------------------------------------------------------------
1) ½ÓÊÕµ½Ò»¸ö IP addr. A µÄ connection ÐèÇó, ì¶ÊÇ͸¹ý reverse DNS È¥
ÕÒ³öÒ»¸ö¶ÔÓ¦µÄ forward domain name B. Èç¹ûÕÒ²»µ½, ¾ÍÍ£Ö¹.
* ì¶ÊÇ, ¹ÜÀíÕß, ¾Í¿ÉÒÔ¾ø¶¨, ½øÐÐ access deny, :-) !
2) ¸ù¾Ý²½Öè 1) ËùÕÒµ½Õý½â domain name B, È¥ forward DNS "²é", È¡µÃ
Ò»×é IP addr. C ( ¿ÉÄÜΪһ¸ö, or Á½¸öÒÔÉÏ, Èç multi-homed host,
³£¼ûµÃÏñ router ).
3) ±È¶Ô IP addr. A, ÊÇ·ñ°üÀ¨ÔÚ IP addr. C ÖÐ.
-- Èç¹û²»¶Ô, Ôòϵͳ»áÌá³ö¾¯¸æ. ²úÉúÈçÉÏÊöµÄѶϢ.
ÕâʱºòËù´ú±íµÄÒâÒå, Ò²ÐíÊÇ database ÓÐÎó. ÁíÍâÒ»ÖÖ¿ÉÄÜ, ¾ÍÊÇÔì¼Ù.
ÓÐʱºò, Ò»¸öµ¥Î»ËùÔÚµÄ forward & reverse domain zone, DNS ²á,
¼°×ÊÁÏά»¤, ·ÖÊô²»Í¬µ¥Î», ÓÐʱáá»á²úÉú, ×öÒµ²»Ð¡ÐÄ, Ò²»á²úÉúÕâÀàÇé¿ö.
-------------------------------------------------------------------
¼¸¸öÎÊÌâ:
========
Õë¶ÔÉÏÃæµÄÇé¿ö, ÎÒÃÇ¿ÉÄÜ»á²úÉúÐí¶àÎÊÌâ.
Q1: ϵͳΪʲ÷áÒªÕâ÷áÂé·³ ? ²½Öè 1). ×öÍêáá, ²»¾Í¿ÉÒÔÁË.
A: ¶à×ö 2) ºÍ 3), Ò»·½ÃæÊÇΪÁË security ÉϵĿ¼Á¿. ×ÜÊÇÒª¸üÉ÷Щ, ±ÜÃâ
ÓÐһЩµ¥Î», ºúÂÒÉèÉè, È»áá²úÉúһЪÂÒÆß°ËÔãѶϢ, ÈÏÒâÖ¸. »òÏݺ¦ËûÈË.
ÁíÍâһЩ»ý¼«µÄÒâÒå, ÊÇÓÐÀû access control. ·½±ã load balance ¹ÜÀíµÈ.
¾ÙÀý:
139.75.26.49, 192.72.90.129 ÕÕĿǰ¶¼ÊÇ SeedNet µÄÓà »§ IP.
±È½Ï *.seed.net.tw, ÄÄÒ»ÖֱȽÏÈÝÒ×±æÈÏ. Ö»ÒªÉÔΪÏëÒ»ÏÂ,
¾Í²»ÄÑÃ÷.
ÍøÂ·É쵀 traffic. ¶¼ÊÇÒÔ IP addr. µÄ×ÊѶÔÚÁ÷ͨ, µ½Ä¿µÄµØáá, Èç¹û¼º
·½µÄ reverse DNS ×ÊÁÏ, ûµÇ¼, ÄÇ÷á¶Ô·½Ðí¶à AP ÔÚ×÷ access control,
performance tuning ʱ, ½«±äµÃ·Ç³£À§ÄÑ.
ÓÈÆä, Ðí¶àµ¥Î»¶¼ÊDz»Á¬ÐøµÄ class C, IP address. ÔÚ·Ö±æÊ±¾Í¸üÀ§ÄÑÁË.
-----------------------------------------------------------------------
Q2: ²»Éè reverse DNS, Ö»ÓÐ forward domain name, ²»ÊDZȽÏÊ¡ÊÂ. ¿´À´ traffic
½ÏÉÙ, Á¬ 2), 3) ¶¼²»ÓÃÁË ?
A: ÊÂÇé²»ÊÇÕâÑùµÄ.
µ±ÄãËùÓÃµÄ DNS server NS1, µÚ 1 ´ÎÅÜÆðÀ´, ±»ÆäËü³Ìʽ, query µ½Ä³Ò»
±ÊÆäËü domain zone µÄ entry ʱ, ( ²»ÂÛ forward & reverse domain ),
Õâʱáá, NS1 ¶¼²»»áÓÐ answer (data), ì¶ÊÇÕâ¸ö NS1 , ±ã»á͸¹ýÕý³£Ìåϵ,
´Ó root ×îÉϲãµÄijһ¸ö DNS server (e.g. NS2) ÎÊÆð, һ·ÕÒÏÂÀ´, ÕÒµ½? ¸ºÔð¸Ã domain zone µÄijһ¸ö DNS server (e.g NS3). È»áá, NS1 ½« query
½»¸ø NS3, NS3 ÕÒÁË×Ô¼ºµÄ database ( ´æÔÚ memory ÖÐ, ÀíÏë״̬ ), Èç
¹ûÓÐÕâ±Ê×ÊÁÏ, ¾Í½«¸Ã answer, ½»¸ø NS1. ½ÓÏÂÀ´, NS1 ¾Í½«Õâ¸ö answer,
¼ÇÏÂÀ´. ( ÒÔÏ嵀 NS3 Ö¸, ¸ºÔðij domain zone µÄ DNS server Ö®Ò»)
ÒòΪÓÐ caching, Èç¹û¸ú×ÅÓÐÈË(³Ìʽ)ÔÙÎÊ, NS1 ¾Í¿ÉÒÔÂíÉϽ«´ð°¸»Ø¸øËü.
µ«ÊÇÈç¹û, NS3 ¸æËß NS1, ûÓÐÕâ±Ê query µÄ¶ÔÓ¦¼Ç¼. ÄÇ÷á NS1, ½ÓÏÂÀ´
»áÔõ÷á×ö ?
Èç¹û NS1 ÊÇ, ÔçÆÚµÄ BIND ( 4.9.5 or ÒÔÏÂ), ½Ó
ÆÀÂÛÄÚÈÝÖ»´ú±íÍøÓѹ۵㣬Óë±¾Õ¾Á¢³¡Î޹أ¡
¡¡¡¡ÆÀÂÛÈË£ºWeston ¡¡¡¡´ò·Ö£º85 ·Ö¡¡¡¡·¢±íʱ¼ä£º2007-5-6 2:01:47
¡¤ http://9abcc0b783d050b9d2d27eb9db7db607-t.ghoiou0.info<ahref...
¡¤ http://9abcc0b783d050b9d2d27eb9db7db607-t.ghoiou0.info<ahref...

