Mikrotik split-dns: au făcut-o

Nu au trecut nici 10 ani de când dezvoltatorii RoS (în stable 6.47) au adăugat funcționalitatea care permite redirecționarea cererilor DNS conform unor reguli speciale. Dacă anterior era necesar să ne complicăm cu regulile Layer-7 în firewall, acum se face simplu și elegant:

/ip dns static
add forward-to=192.168.88.3 regexp=".*\.test1\.localdomain" type=FWD
add forward-to=192.168.88.56 regexp=".*\.test2\.localdomain" type=FWD

Fericirea mea nu cunoaște limite!

Ce consecințe are aceasta pentru noi?

Cel puțin, ne eliberăm de structuri ciudate cu NAT de tipul acesta:


/ip firewall layer7-protocol
add comment="DNS Nat contoso.com" name=contoso.com regexp="\x07contoso\x03com"
/ip firewall mangle
add action=mark-packet chain=prerouting comment="mark dns contoso.com" dst-address-type=local dst-port=53 in-interface-list=DNSMASQ layer7-protocol=contoso.com new-packet-mark=dns-contoso.com passthrough=yes protocol=udp
add action=mark-packet chain=prerouting comment="mark dns contoso.com" dst-address-type=local dst-port=53 in-interface-list=DNSMASQ layer7-protocol=contoso.com new-packet-mark=dns-contoso.com passthrough=yes protocol=tcp
/ip firewall nat
add action=dst-nat chain=dstnat comment="DST-NAT dns contoso.com" dst-port=53 in-interface-list=DNSMASQ packet-mark=dns-contoso.com protocol=udp to-addresses=192.0.2.15
add action=dst-nat chain=dstnat comment="DST-NAT dns contoso.com" dst-port=53 in-interface-list=DNSMASQ packet-mark=dns-contoso.com protocol=tcp to-addresses=192.0.2.15
add action=masquerade chain=srcnat comment="mask dns contoso.com" dst-port=53 packet-mark=dns-contoso.com protocol=udp
add action=masquerade chain=srcnat comment="mask dns contoso.com" dst-port=53 packet-mark=dns-contoso.com protocol=tcp

Și asta nu e tot, acum putem defini mai multe servere redirecționări, ceea ce va ajuta la realizarea failover-ului DNS.
Prelucrarea inteligentă a DNS-ului va permite începutul implementării IPv6 în rețeaua companiei. Până acum, nu am făcut acest lucru deoarece trebuia să traduc mai multe nume DNS în adrese locale, iar în IPv6 acest lucru nu era posibil fără câteva soluții destul de complexe.

Sursa: habr.com

Cumpără un hosting fiabil pentru site-uri cu protecție DDoS, servere VPS VDS 🔥 Cumpără un hosting fiabil pentru site-uri cu protecție DDoS, servere VPS VDS | ProHoster