URL: https://www.opennet.ru/cgi-bin/openforum/vsluhboard.cgi
Форум: vsluhforumID1
Нить номер: 72906
[ Назад ]

Исходное сообщение
"DHCP->DNS помогите понять"

Отправлено deys , 16-Мрт-07 12:45 
помогите понять где ошибка. Не синхронизируется ДНС с ДХЦП. Вот конфиги:

named.conf
-------------
acl corpnets {
        192.168.1.0/24;
        192.168.2.0/24;
        192.168.3.0/24;
        192.168.4.0/24;
        192.168.5.0/24;
        192.168.6.0/24;
        127.0.0.1;
        };
options {
        directory "/var/named";

        dump-file "/var/named/data/cache_dump.db";
        statistics-file "/var/named/data/named_stats.txt";

        allow-query {
                corpnets;
                };
//      query-source port 53;
        forward only;
        forwarders {
                127.0.0.1;
                192.168.5.2;
                80.66.66.11;
                80.66.66.110;
                192.168.5.9;
                };
//
        listen-on port 53 {
                192.168.5.2;
                127.0.0.1;
                };
};
};

logging {
        channel update_debug {
                file "/var/log/named-update.log";
                severity debug 3;
                print-category yes;
                print-severity yes;
                print-time yes;
                };
        channel security_info {
                file "/var/log/named-auth.log";
                severity info;
                print-category yes;
                print-severity yes;
                print-time yes;
                };
        category security {
                security_info;
                };
        category update {
                update_debug;
                };
};

key rndc-key {
        algorithm hmac-md5;
        secret "c3Jc7fgR2f2i+YItIHyZdQ==";
        };

zone "." IN {
        type hint;
        file "named.ca";
};

zone "localhost" IN {
        type master;
        file "localhost.zone";
        allow-update {
                none;
                };
};

zone "0.0.127.in-addr.arpa" IN {
        type master;
        file "named.local";
        allow-update { none; };
};
/////// New Zone ////
zone "el.local" IN {
        type master;
        file "my.el.local";
        allow-update {
                key rndc-key;
                };
//      notify no;
        };

zone "6.168.192.in-addr.arpa" IN {
        type master;
        file "my.192.168.6";
        allow-update {
                key rndc-key;
                };
//      notify no;
        };
(дальше 5я,4я, 3я, 2я и 1я подсеть идентичны)
controls {
        inet 127.0.0.1 port 953 allow { 127.0.0.1; } keys { rndc-key; };
        };
------------------------

dhcpd.conf
------------------------
authoritative;
ddns-update-style interim;
deny duplicates;
stash-agent-options off;
update-static-leases on;
option ip-forwarding on;
option domain-name "el.local";
option domain-name-servers 192.168.5.9, 192.168.5.2;
option broadcast-address 255.255.255.255;
key rndc-key {
        secret c3Jc7fgR2f2i+YItIHyZdQ==;
        algorithm hmac-md5;
        }
zone el.local. {
primary 192.168.5.2;
# key DHCP_UPDATER;
    key rndc-key;
}
zone 6.168.192.IN-ADDR.ARPA. {
primary 192.168.5.2;
# key DHCP_UPDATER;
    key rndc-key;
}
(дальше идентично 5-1я подсеть)
class "dhcp-relay" {
    match if exists agent.circuit-id;
}
subnet 192.168.6.0 netmask 255.255.255.0 {
    default-lease-time 2764800;
    max-lease-time 2764800;
    ddns-domainname "el.local";
    deny client-updates;
    server-identifier 192.168.5.2;
    server-name proxy;
    option domain-name "el.local";
    option domain-name-servers 192.168.5.9, 192.168.5.2;
    option routers 192.168.6.1;
    option subnet-mask 255.255.255.0;
    option broadcast-address 192.168.6.255;
    option netbios-name-servers 192.168.5.9;
    option netbios-node-type 8;

pool {
    range 192.168.6.10 192.168.6.254;
        deny members of "dhcp-relay";
    }
(опять же для остальных идетничто)
-------------------

что я забыл сделать, чтоб автоматическая синхронизация была?


Содержание

Сообщения в этом обсуждении
"DHCP->DNS помогите понять"
Отправлено bass , 16-Мрт-07 13:49 
>помогите понять где ошибка. Не синхронизируется ДНС с ДХЦП. Вот конфиги:
>
>named.conf
>-------------
>acl corpnets {
>        192.168.1.0/24;
>        192.168.2.0/24;
>        192.168.3.0/24;
>        192.168.4.0/24;
>        192.168.5.0/24;
>        192.168.6.0/24;
>        127.0.0.1;
>        };
>options {
>        directory "/var/named";
>
>        dump-file "/var/named/data/cache_dump.db";
>        statistics-file "/var/named/data/named_stats.txt";
>
>        allow-query {
>            
>    corpnets;
>            
>    };
>//      query-source port 53;
>        forward only;
>        forwarders {
>            
>    127.0.0.1;
>            
>    192.168.5.2;
>            
>    80.66.66.11;
>            
>    80.66.66.110;
>            
>    192.168.5.9;
>            
>    };
>//
>        listen-on port 53 {
>
>            
>    192.168.5.2;
>            
>    127.0.0.1;
>            
>    };
>};
>};
>
>logging {
>        channel update_debug {
>            
>    file "/var/log/named-update.log";
>            
>    severity debug 3;
>            
>    print-category yes;
>            
>    print-severity yes;
>            
>    print-time yes;
>            
>    };
>        channel security_info {
>            
>    file "/var/log/named-auth.log";
>            
>    severity info;
>            
>    print-category yes;
>            
>    print-severity yes;
>            
>    print-time yes;
>            
>    };
>        category security {
>            
>    security_info;
>            
>    };
>        category update {
>            
>    update_debug;
>            
>    };
>};
>
>key rndc-key {
>        algorithm hmac-md5;
>        secret "c3Jc7fgR2f2i+YItIHyZdQ==";
>        };
>
>zone "." IN {
>        type hint;
>        file "named.ca";
>};
>
>zone "localhost" IN {
>        type master;
>        file "localhost.zone";
>        allow-update {
>            
>    none;
>            
>    };
>};
>
>zone "0.0.127.in-addr.arpa" IN {
>        type master;
>        file "named.local";
>        allow-update { none; };
>
>};
>/////// New Zone ////
>zone "el.local" IN {
>        type master;
>        file "my.el.local";
>        allow-update {
>            
>    key rndc-key;
>            
>    };
>//      notify no;
>        };
>
>zone "6.168.192.in-addr.arpa" IN {
>        type master;
>        file "my.192.168.6";
>        allow-update {
>            
>    key rndc-key;
>            
>    };
>//      notify no;
>        };
>(дальше 5я,4я, 3я, 2я и 1я подсеть идентичны)
>controls {
>        inet 127.0.0.1 port 953
>allow { 127.0.0.1; } keys { rndc-key; };
>        };
>------------------------
>
>dhcpd.conf
>------------------------
>authoritative;
>ddns-update-style interim;
>deny duplicates;
>stash-agent-options off;
>update-static-leases on;
>option ip-forwarding on;
>option domain-name "el.local";
>option domain-name-servers 192.168.5.9, 192.168.5.2;
>option broadcast-address 255.255.255.255;
>key rndc-key {
>        secret c3Jc7fgR2f2i+YItIHyZdQ==;
>        algorithm hmac-md5;
>        }
>zone el.local. {
> primary 192.168.5.2;
># key DHCP_UPDATER;
>    key rndc-key;
> }
>zone 6.168.192.IN-ADDR.ARPA. {
> primary 192.168.5.2;
># key DHCP_UPDATER;
>    key rndc-key;
> }
>(дальше идентично 5-1я подсеть)
>class "dhcp-relay" {
>    match if exists agent.circuit-id;
>}
>subnet 192.168.6.0 netmask 255.255.255.0 {
>    default-lease-time 2764800;
>    max-lease-time 2764800;
>    ddns-domainname "el.local";
>    deny client-updates;
>    server-identifier 192.168.5.2;
>    server-name proxy;
>    option domain-name "el.local";
>    option domain-name-servers 192.168.5.9, 192.168.5.2;
>    option routers 192.168.6.1;
>    option subnet-mask 255.255.255.0;
>    option broadcast-address 192.168.6.255;
>    option netbios-name-servers 192.168.5.9;
>    option netbios-node-type 8;
>
>pool {
>    range 192.168.6.10 192.168.6.254;
>        deny members of "dhcp-relay";
>
>    }
>(опять же для остальных идетничто)
>-------------------
>
>что я забыл сделать, чтоб автоматическая синхронизация была?


вы забыли его включить :)
ddns-updates on
ddns-domainname "el.local"

все ответы в логах