Mikrotik split-dns: zij hebben het gedaan

Er is nauwelijks 10 jaar verstreken sinds de ontwikkelaars van RoS (in stable 6.47) functionaliteit hebben toegevoegd die het mogelijk maakt om DNS-verzoeken te routeren volgens speciale regels. Waar je vroeger moest worstelen met Layer-7 regels in de firewall, wordt dit nu eenvoudig en elegant gedaan:

/ip dns static
add forward-to=192.168.88.3 regexp=".*\.test1\.localdomain" type=FWD
add forward-to=192.168.88.56 regexp=".*\.test2\.localdomain" type=FWD

Mijn geluk kent geen grenzen!

Wat betekent dit voor ons?

In ieder geval worden we verlost van vreemde NAT-constructies zoals deze:


/ip firewall layer7-protocol
add comment="DNS Nat contoso.com" name=contoso.com regexp="\x07contoso\x03com"
/ip firewall mangle
add action=mark-packet chain=prerouting comment="mark dns contoso.com" dst-address-type=local dst-port=53 in-interface-list=DNSMASQ layer7-protocol=contoso.com new-packet-mark=dns-contoso.com passthrough=yes protocol=udp
add action=mark-packet chain=prerouting comment="mark dns contoso.com" dst-address-type=local dst-port=53 in-interface-list=DNSMASQ layer7-protocol=contoso.com new-packet-mark=dns-contoso.com passthrough=yes protocol=tcp
/ip firewall nat
add action=dst-nat chain=dstnat comment="DST-NAT dns contoso.com" dst-port=53 in-interface-list=DNSMASQ packet-mark=dns-contoso.com protocol=udp to-addresses=192.0.2.15
add action=dst-nat chain=dstnat comment="DST-NAT dns contoso.com" dst-port=53 in-interface-list=DNSMASQ packet-mark=dns-contoso.com protocol=tcp to-addresses=192.0.2.15
add action=masquerade chain=srcnat comment="mask dns contoso.com" dst-port=53 packet-mark=dns-contoso.com protocol=udp
add action=masquerade chain=srcnat comment="mask dns contoso.com" dst-port=53 packet-mark=dns-contoso.com protocol=tcp

En dat is nog niet alles, nu kunnen we meerdere servers doorstuurregels configureren, wat helpt bij het maken van DNS failover.
Intelligente DNS-verwerking maakt het mogelijk om de implementatie van IPv6 in het bedrijfsnetwerk te beginnen. Voorheen deed ik dit niet, omdat ik een aantal DNS-namen naar lokale adressen moest resolveren, en met IPv6 was dat niet mogelijk zonder behoorlijk ingewikkelde oplossingen.

Bron: habr.com

Koop betrouwbare webhosting met bescherming tegen DDoS, VPS VDS servers 🔥 Koop betrouwbare webhosting met bescherming tegen DDoS, VPS VDS servers | ProHoster