ื”ืคื•ืš ื”ืืฆืœืช ืื–ื•ืจ ืœืจืฉืชื•ืช ืžืฉื ื” ืคื—ื•ืช ืž-/24 ื‘-BIND. ืื™ืš ื–ื” ืขื•ื‘ื“

ื™ื•ื ืื—ื“ ืขืžื“ืชื™ ื‘ืคื ื™ ื”ืžืฉื™ืžื” ืœืชืช ืœืื—ื“ ืžืœืงื•ื—ื•ืชื™ื™ ืืช ื”ื–ื›ื•ืช ืœืขืจื•ืš ืจืฉื•ืžื•ืช PTR ืฉืœ ืจืฉืช ื”ืžืฉื ื” /28 ืฉื”ื•ืงืฆืชื” ืœื•. ืื™ืŸ ืœื™ ืื•ื˜ื•ืžืฆื™ื” ืœืขืจื™ื›ืช ื”ื’ื“ืจื•ืช BIND ืžื‘ื—ื•ืฅ. ืœื›ืŸ, ื”ื—ืœื˜ืชื™ ืœืงื—ืช ืžืกืœื•ืœ ืื—ืจ - ืœื”ืืฆื™ืœ ืœืœืงื•ื— ื—ืœืง ืžืื–ื•ืจ ื”-PTR ืฉืœ ืจืฉืช ื”ืžืฉื ื” /24.

ื ืจืื” - ืžื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ื™ื•ืชืจ ืคืฉื•ื˜? ืื ื• ืคืฉื•ื˜ ืจื•ืฉืžื™ื ืืช ื”ืจืฉืช ื”ืžืฉื ื” ื›ื ื“ืจืฉ ื•ืžืคื ื™ื ืื•ืชื” ืœ-NS ื”ืจืฆื•ื™, ื›ืคื™ ืฉื ืขืฉื” ืขื ืชืช-ื“ื•ืžื™ื™ืŸ. ืื‘ืœ ืœื. ื–ื” ืœื ื›ืœ ื›ืš ืคืฉื•ื˜ (ืœืžืจื•ืช ืฉื‘ืžืฆื™ืื•ืช ื–ื” ื‘ื›ืœืœ ืคืจื™ืžื™ื˜ื™ื‘ื™, ืื‘ืœ ืื™ื ื˜ื•ืื™ืฆื™ื” ืœื ืชืขื–ื•ืจ), ื–ื• ื”ืกื™ื‘ื” ืฉืื ื™ ื›ื•ืชื‘ ืืช ื”ืžืืžืจ ื”ื–ื”.

ืžื™ ืฉืจื•ืฆื” ืœื”ื‘ื™ืŸ ื‘ืขืฆืžื• ื™ื›ื•ืœ ืœืงืจื•ื RFC
ืžื™ ืฉืจื•ืฆื” ืคืชืจื•ืŸ ืžื•ื›ืŸ, ื‘ืจื•ืš ื”ื‘ื ืœื—ืชื•ืœ.

ื›ื“ื™ ืœื ืœืขื›ื‘ ืืช ืžื™ ืฉืื•ื”ื‘ ืืช ืฉื™ื˜ืช ื”ืขืชืง-ื”ื“ื‘ืง, ืืคืจืกื ืงื•ื“ื ืืช ื”ื—ืœืง ื”ืžืขืฉื™ ื•ืœืื—ืจ ืžื›ืŸ ืืช ื”ื—ืœืง ื”ืขื™ื•ื ื™.

1. ืชืจื’ื•ืœ. ืื–ื•ืจ ื”ืืฆืœื” /28

ื ื ื™ื— ืฉื™ืฉ ืœื ื• ืชืช-ืจืฉืช 7.8.9.0/24. ืื ื—ื ื• ืฆืจื™ื›ื™ื ืœื”ืืฆื™ืœ ืืช ืจืฉืช ื”ืžืฉื ื” 7.8.9.240/28 ืœืœืงื•ื— dns 7.8.7.8 (ns1.client.domain).

ื‘-DNS ืฉืœ ื”ืกืคืง ืืชื” ืฆืจื™ืš ืœืžืฆื•ื ืงื•ื‘ืฅ ืฉืžืชืืจ ืืช ื”ืื–ื•ืจ ื”ื”ืคื•ืš ืฉืœ ืจืฉืช ื”ืžืฉื ื” ื”ื–ื•. ืชืŸ ืœื–ื” ืœื”ื™ื•ืช 9.8.7.in-addr.harp.
ืื ื• ืžื’ื™ื‘ื™ื ืœืขืจื›ื™ื ืž-240 ืขื“ 255, ืื ื™ืฉ ื›ืืœื”. ื•ื‘ืกื•ืฃ ื”ืงื•ื‘ืฅ ื ื›ืชื•ื‘ ืืช ื”ื“ื‘ืจื™ื ื”ื‘ืื™ื:

255-240  IN  NS      7.8.7.8
$GENERATE 240-255 $ CNAME $.255-240

ืืœ ืชืฉื›ื— ืœื”ื’ื“ื™ืœ ืืช ื”ืื–ื•ืจ ื”ืกื“ืจืชื™ ื•ืœืขืฉื•ืช

rndc reload

ื–ื” ืžืฉืœื™ื ืืช ื—ืœืง ื”ืกืคืง. ื‘ื•ืื• ื ืขื‘ื•ืจ ืœ-dns ืฉืœ ื”ืœืงื•ื—.

ืจืืฉื™ืช, ื‘ื•ืื• ื ื™ืฆื•ืจ ืงื•ื‘ืฅ /etc/bind/master/255-240.9.8.7.in-addr.arpa ื”ืชื•ื›ืŸ ื”ื‘ื:

$ORIGIN 255-240.9.8.7.in-addr.arpa.
$TTL 1W
@                       1D IN SOA       ns1.client.domain. root.client.domain. (
                        2008152607      ; serial
                        3H              ; refresh
                        15M             ; retry
                        1W              ; expiry
                        1D )            ; minimum
@                       IN NS        ns1.client.domain.
@                       IN NS        ns2.client.domain.
241                     IN PTR          test.client.domain.
242                     IN PTR          test2.client.domain.
245                     IN PTR          test5.client.domain.

ื•ื‘ืคื ื™ื ื‘ืฉื.ืงื•ื ืฃ ื”ื•ืกืฃ ืชื™ืื•ืจ ืฉืœ ื”ืงื•ื‘ืฅ ื”ื—ื“ืฉ ืฉืœื ื•:

zone "255-240.9.8.7.in-addr.arpa." IN {
        type master;
        file "master/255-240.9.8.7.in-addr.arpa";
};

B ื”ืคืขืœ ืžื—ื“ืฉ ืืช ืชื”ืœื™ืš ื”ืงื™ืฉื•ืจ.

/etc/init.d/named restart

ืืช ื›ืœ. ืขื›ืฉื™ื• ืืชื” ื™ื›ื•ืœ ืœื‘ื“ื•ืง.

#>  host 7.8.9.245 
245.9.8.7.in-addr.arpa is an alias for 245.255-240.9.8.7.in-addr.arpa.
245.255-240.9.8.7.in-addr.arpa domain name pointer test5.client.domain.

ืฉื™ืžื• ืœื‘ ืฉืœื ืจืง ืจืฉื•ืžืช ื”-PTR ื ื™ืชื ืช, ืืœื ื’ื ื”-CNAME. ื›ื›ื” ื–ื” ืฆืจื™ืš ืœื”ื™ื•ืช. ืื ืืชื” ืชื•ื”ื” ืœืžื”, ืื– ื‘ืจื•ืš ื”ื‘ื ืœืคืจืง ื”ื‘ื.

2. ืชื™ืื•ืจื™ื”. ืื™ืš ื–ื” ืขื•ื‘ื“.

ืงืฉื” ืœื”ื’ื“ื™ืจ ื•ืœื ืงื•ืช ื‘ืื’ื™ื ื‘ืงื•ืคืกื” ืฉื—ื•ืจื”. ื–ื” ื”ืจื‘ื” ื™ื•ืชืจ ืงืœ ืื ืืชื” ืžื‘ื™ืŸ ืžื” ืงื•ืจื” ื‘ืคื ื™ื.

ื›ืืฉืจ ืื ื• ืžืืฆื™ืœื™ื ืชืช-ื“ื•ืžื™ื™ืŸ ื‘ื“ื•ืžื™ื™ืŸ ืชื—ื•ื, ืื– ื ื›ืชื•ื‘ ืžืฉื”ื• ื›ื–ื”:

client.domain.	NS	ns1.client.domain.
ns1.client.domain.	A	7.8.7.8

ืื ื—ื ื• ืื•ืžืจื™ื ืœื›ืœ ืžื™ ืฉืฉื•ืืœ ืฉืื ื—ื ื• ืœื ืื—ืจืื™ื ืœืืชืจ ื”ื–ื” ื•ืื•ืžืจื™ื ืžื™ ืื—ืจืื™. ื•ื›ืœ ื”ื‘ืงืฉื•ืช ืœ client.domain ื”ืคื ื” ืžื—ื“ืฉ ืœ-7.8.7.8. ื‘ืขืช ื”ื‘ื“ื™ืงื”, ืื ื• ืจื•ืื™ื ืืช ื”ืชืžื•ื ื” ื”ื‘ืื” (ื ืฉืžื™ื˜ ืืช ืžื” ืฉื™ืฉ ืœืœืงื•ื— ืฉื. ื–ื” ืœื ืžืฉื ื”):

# host test.client.domain
test.client.domain has address 7.8.9.241

ื”ึธื”ึตืŸ. ื”ืชื‘ืฉืจื ื• ืฉื™ืฉ ืจืฉื•ืžืช A ื›ื–ื• ื•ื”-IP ืฉืœื” ื”ื•ื 7.8.9.241. ืื™ืŸ ืžื™ื“ืข ืžื™ื•ืชืจ.

ืื™ืš ืืคืฉืจ ืœืขืฉื•ืช ืืช ืื•ืชื• ื”ื“ื‘ืจ ืขื ืจืฉืช ืžืฉื ื”?

ื›ื™ ืฉืจืช ื”-DNS ืฉืœื ื• ืจืฉื•ื ื‘-RIPE, ื•ืื– ื›ืืฉืจ ืžื‘ืงืฉื™ื ื›ืชื•ื‘ืช IP ืฉืœ PTR ืžื”ืจืฉืช ืฉืœื ื•, ื”ื‘ืงืฉื” ื”ืจืืฉื•ื ื” ืขื“ื™ื™ืŸ ืชื”ื™ื” ืืœื™ื ื•. ื”ื”ื™ื’ื™ื•ืŸ ื–ื”ื” ืœื–ื” ืฉืœ ื“ื•ืžื™ื™ื ื™ื. ืื‘ืœ ืื™ืš ืžื›ื ื™ืกื™ื ืชืช-ืจืฉืช ืœืงื•ื‘ืฅ ืื–ื•ืจ?

ื‘ื•ืื• ื ื ืกื” ืœื”ื–ื™ืŸ ืื•ืชื• ื›ืš:

255-240  IN  NS      7.8.7.8

ื•... ื”ื ืก ืœื ืงืจื”. ืื ื—ื ื• ืœื ืžืงื‘ืœื™ื ื”ืคื ื™ื” ืžื—ื“ืฉ ืฉืœ ื‘ืงืฉื”. ื”ืขื ื™ื™ืŸ ื”ื•ื ืฉ-bind ืืคื™ืœื• ืœื ื™ื•ื“ืข ืฉื”ืขืจื›ื™ื ื”ืืœื” ื‘ืงื•ื‘ืฅ ื”-reverse zone ื”ื ื›ืชื•ื‘ื•ืช IP, ื•ื™ื•ืชืจ ืžื›ืš ืœื ืžื‘ื™ืŸ ืืช ืขืจืš ื”ื˜ื•ื•ื—. ืžื‘ื—ื™ื ืชื•, ื–ื” ืจืง ืกื•ื’ ืฉืœ ืชืช-ื“ื•ืžื™ื™ืŸ ืกืžืœื™. ื”ึธื”ึตืŸ. ืขื‘ื•ืจ ืื™ื’ื“ ืœื ื™ื”ื™ื” ื”ื‘ื“ืœ ื‘ื™ืŸ "255-240"ื•"ืœืงื•ื—-ื”ืขืœ ืฉืœื ื•". ื•ื›ื“ื™ ืฉื”ื‘ืงืฉื” ืชื’ื™ืข ืœืืŸ ืฉื”ื™ื ืฆืจื™ื›ื” ืœื”ื’ื™ืข, ื”ื›ืชื•ื‘ืช ื‘ื‘ืงืฉื” ืฆืจื™ื›ื” ืœื”ื™ืจืื•ืช ื›ืš: 241.255-240.9.8.7.in-addr.arpa. ืื• ื›ืš ืื ืื ื• ืžืฉืชืžืฉื™ื ื‘ืชืช-ื“ื•ืžื™ื™ืŸ ืฉืœ ืชื•ื•ื™ื: 241.oursuperclient.9.8.7.in-addr.arpa. ื–ื” ืฉื•ื ื” ืžื”ืจื’ื™ืœ: 241.9.8.7.in-addr.harp.

ื™ื”ื™ื” ืงืฉื” ืœื”ื’ื™ืฉ ื‘ืงืฉื” ื›ื–ื• ื‘ืื•ืคืŸ ื™ื“ื ื™. ื•ื’ื ืื ื–ื” ืขื•ื‘ื“, ืขื“ื™ื™ืŸ ืœื ื‘ืจื•ืจ ืื™ืš ืœื™ื™ืฉื ืืช ื–ื” ื‘ื—ื™ื™ื ื”ืืžื™ืชื™ื™ื. ืื—ืจื™ ื”ื›ืœ, ืœืคื™ ื‘ืงืฉื” 7.8.9.241 ื”-DNS ืฉืœ ื”ืกืคืง ืขื“ื™ื™ืŸ ืขื•ื ื” ืœื ื•, ืœื ืฉืœ ื”ืœืงื•ื—.

ื•ื›ืืŸ ื”ื ื ื›ื ืกื™ื ืœืชืžื•ื ื” CNAME.

ื‘ืฆื“ ืฉืœ ื”ืกืคืง, ืืชื” ืฆืจื™ืš ืœืขืฉื•ืช ื›ื™ื ื•ื™ ืœื›ืœ ื›ืชื•ื‘ื•ืช ื”-IP ืฉืœ ืจืฉืช ื”ืžืฉื ื” ื‘ืคื•ืจืžื˜ ืฉื™ืขื‘ื™ืจ ืืช ื”ื‘ืงืฉื” ืœ-DNS ืฉืœ ื”ืœืงื•ื—.

255-240  IN  NS      ns1.client.domain.
241     IN  CNAME   241.255-240
242     IN  CNAME   242.255-240
ะธ ั‚.ะด.

ื–ื” ืœื—ืจื•ืฆื™ื =).

ื•ืœืขืฆืœืŸ, ื”ืขื™ืฆื•ื‘ ืœืžื˜ื” ืžืชืื™ื ื™ื•ืชืจ:

255-240  IN  NS      ns1.client.domain.
$GENERATE 240-255 $ CNAME $.255-240

ื›ืขืช ื‘ืงืฉ ืžื™ื“ืข ื‘ 7.8.9.241 ืฉืœ 241.9.8.7.in-addr.harp ื‘ืฉืจืช ื”-DNS ืฉืœ ื”ืกืคืง ื™ื•ืžืจ ืœ 241.255-240.9.8.7.in-addr.arpa ื•ื”ื•ืœืš ืœืœืงื•ื— dns.

ืฆื“ ื”ืœืงื•ื— ื™ืฆื˜ืจืš ืœื˜ืคืœ ื‘ื‘ืงืฉื•ืช ื›ืืœื”. ื‘ื”ืชืื ืœื›ืš, ืื ื• ื™ื•ืฆืจื™ื ืื–ื•ืจ 255-240.9.8.7.in-addr.arpa. ื‘ื•, ื‘ืื•ืคืŸ ืขืงืจื•ื ื™, ืื ื• ื™ื›ื•ืœื™ื ืœื”ืฆื™ื‘ ืขืจื›ื™ื ื”ืคื•ื›ื™ื ืขื‘ื•ืจ ื›ืœ ip ืฉืœ ื›ืœ ื”ืžืฉื ื” /24, ืื‘ืœ ื”ื ื™ืฉืืœื• ืื•ืชื ื• ืจืง ืขืœ ืืœื• ืฉื”ืกืคืง ืžืขื‘ื™ืจ ืืœื™ื ื•, ืื– ืœื ื ื•ื›ืœ ืœืฉื—ืง =).
ืœืฉื ื”ืžื—ืฉื”, ืืชืŸ ืฉื•ื‘ ื“ื•ื’ืžื” ืœืชื•ื›ืŸ ืฉืœ ืงื•ื‘ืฅ ืื–ื•ืจ ื”ืคื•ืš ืžืฆื“ ื”ืœืงื•ื—:

$ORIGIN 255-240.9.8.7.in-addr.arpa.
$TTL 1W
@                       1D IN SOA       ns1.client.domain. root.client.domain. (
                        2008152607      ; serial
                        3H              ; refresh
                        15M             ; retry
                        1W              ; expiry
                        1D )            ; minimum
@                       IN NS        ns1.client.domain.
@                       IN NS        ns2.client.domain.
241                     IN PTR          test.client.domain.
242                     IN PTR          test2.client.domain.
245                     IN PTR          test5.client.domain.

ื–ื” ื‘ื’ืœืœ ืฉืื ื—ื ื• ืžืฉืชืžืฉื™ื ื‘-CNAME ื‘ืฆื“ ืฉืœ ื”ืกืคืง, ื•ื‘ืชื’ื•ื‘ื” ืœื‘ืงืฉืช ื ืชื•ื ื™ื ืœืคื™ ื›ืชื•ื‘ืช IP ืื ื—ื ื• ืžืงื‘ืœื™ื ืฉืชื™ ืจืฉื•ืžื•ืช, ืœื ืื—ืช.

#>  host 7.8.9.245 
245.9.8.7.in-addr.arpa is an alias for 245.255-240.9.8.7.in-addr.arpa.
245.255-240.9.8.7.in-addr.arpa domain name pointer test5.client.domain.

ื•ืืœ ืชืฉื›ื— ืœื”ื’ื“ื™ืจ ืืช ื”-ACL ื‘ืฆื•ืจื” ื ื›ื•ื ื”. ื›ื™ ื–ื” ืœื ื”ื’ื™ื•ื ื™ ืœืงื—ืช ืœืขืฆืžืš ืื–ื•ืจ PTR ื•ืœื ืœื”ื’ื™ื‘ ืœืืฃ ืื—ื“ ืžื‘ื—ื•ืฅ =).

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”