Mikrotik split-dns: ๊ทธ๋“ค์ด ํ•ด๋ƒˆ์Šต๋‹ˆ๋‹ค

10๋…„์ด ์ฑ„ ์ง€๋‚˜์ง€ ์•Š์•„ RoS ๊ฐœ๋ฐœ์ž(์•ˆ์ •์ ์ธ 6.47)๋Š” ํŠน์ˆ˜ ๊ทœ์น™์— ๋”ฐ๋ผ DNS ์ฟผ๋ฆฌ๋ฅผ ๋ฆฌ๋””๋ ‰์…˜ํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋Šฅ์„ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด์ „์—๋Š” ๋ฐฉํ™”๋ฒฝ์—์„œ Layer-7 ๊ทœ์น™์œผ๋กœ ํšŒํ”ผํ•ด์•ผ ํ–ˆ์ง€๋งŒ ์ด์ œ๋Š” ๊ฐ„๋‹จํ•˜๊ณ  ์šฐ์•„ํ•˜๊ฒŒ ์ˆ˜ํ–‰๋ฉ๋‹ˆ๋‹ค.

/ip dns static
add forward-to=192.168.88.3 regexp=".*\.test1\.localdomain" type=FWD
add forward-to=192.168.88.56 regexp=".*\.test2\.localdomain" type=FWD

๋‚ด ํ–‰๋ณต์€ ๋์ด ์—†์Šต๋‹ˆ๋‹ค!

์ด๊ฒƒ์ด ์šฐ๋ฆฌ๋ฅผ ์œ„ํ˜‘ํ•˜๋Š” ๊ฒƒ์€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

์ตœ์†Œํ•œ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ด์ƒํ•œ NAT ๊ตฌ์กฐ๋ฅผ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค.


/ip firewall layer7-protocol
add comment="DNS Nat contoso.com" name=contoso.com regexp="\x07contoso\x03com"
/ip firewall mangle
add action=mark-packet chain=prerouting comment="mark dns contoso.com" dst-address-type=local dst-port=53 in-interface-list=DNSMASQ layer7-protocol=contoso.com new-packet-mark=dns-contoso.com passthrough=yes protocol=udp
add action=mark-packet chain=prerouting comment="mark dns contoso.com" dst-address-type=local dst-port=53 in-interface-list=DNSMASQ layer7-protocol=contoso.com new-packet-mark=dns-contoso.com passthrough=yes protocol=tcp
/ip firewall nat
add action=dst-nat chain=dstnat comment="DST-NAT dns contoso.com" dst-port=53 in-interface-list=DNSMASQ packet-mark=dns-contoso.com protocol=udp to-addresses=192.0.2.15
add action=dst-nat chain=dstnat comment="DST-NAT dns contoso.com" dst-port=53 in-interface-list=DNSMASQ packet-mark=dns-contoso.com protocol=tcp to-addresses=192.0.2.15
add action=masquerade chain=srcnat comment="mask dns contoso.com" dst-port=53 packet-mark=dns-contoso.com protocol=udp
add action=masquerade chain=srcnat comment="mask dns contoso.com" dst-port=53 packet-mark=dns-contoso.com protocol=tcp

๊ทธ๋ฆฌ๊ณ  ์ด๊ฒƒ์ด ์ „๋ถ€๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค. ์ด์ œ DNS ์žฅ์•  ์กฐ์น˜๋ฅผ ๋งŒ๋“œ๋Š” ๋ฐ ๋„์›€์ด ๋˜๋Š” ์—ฌ๋Ÿฌ ํฌ์›Œ๋”๋ฅผ ๋“ฑ๋กํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
์ง€๋Šฅํ˜• DNS ์ฒ˜๋ฆฌ๋ฅผ ํ†ตํ•ด ํšŒ์‚ฌ ๋„คํŠธ์›Œํฌ์— ipv6 ๋„์ž…์„ ์‹œ์ž‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ ์ „์—๋Š” ์ด๊ฒƒ์„ํ•˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค. ๊ทธ ์ด์œ ๋Š” ์—ฌ๋Ÿฌ DNS ์ด๋ฆ„์„ ๋กœ์ปฌ ์ฃผ์†Œ๋กœ ํ™•์ธํ•ด์•ผํ–ˆ๊ณ  ipv6์—์„œ๋Š” ๋‹ค์†Œ ํฐ ๋ชฉ๋ฐœ ์—†์ด๋Š” ์ˆ˜ํ–‰ ํ•  ์ˆ˜ ์—†์—ˆ๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : habr.com