95 lines
		
	
	
		
			2.2 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
			
		
		
	
	
			95 lines
		
	
	
		
			2.2 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
| options {
 | |
|    directory "/var/cache/bind";
 | |
| 
 | |
|    // If there is a firewall between you and nameservers you want
 | |
|    // to talk to, you may need to fix the firewall to allow multiple
 | |
|    // ports to talk.  See http://www.kb.cert.org/vuls/id/800113
 | |
| 
 | |
|    // If your ISP provided one or more IP addresses for stable
 | |
|    // nameservers, you probably want to use them as forwarders.
 | |
|    // Uncomment the following block, and insert the addresses replacing
 | |
|    // the all-0's placeholder.
 | |
| 
 | |
|    // forwarders {
 | |
|    //    0.0.0.0;
 | |
|    // };
 | |
| 
 | |
|    //========================================================================
 | |
|    // If BIND logs error messages about the root key being expired,
 | |
|    // you will need to update your keys.  See https://www.isc.org/bind-keys
 | |
|    //========================================================================
 | |
|    dnssec-validation auto;
 | |
| 
 | |
|    // Security options
 | |
|    listen-on port 53 {
 | |
|       127.0.0.1;
 | |
|       172.16.42.1;
 | |
|       192.168.42.1;
 | |
|    };
 | |
| 
 | |
|    allow-query {
 | |
|       127.0.0.1;
 | |
|       172.16.0.0/16;
 | |
|       192.168.0.0/16;
 | |
|       10.0.0.0/8;
 | |
|    };
 | |
| 
 | |
|    // caching name services
 | |
|    recursion yes;
 | |
|    allow-recursion {
 | |
|       127.0.0.1;
 | |
|       172.16.0.0/16;
 | |
|       192.168.0.0/16;
 | |
|       10.0.0.0/16;
 | |
|    };
 | |
| 
 | |
|    allow-transfer { none; };
 | |
| 
 | |
|    auth-nxdomain no;    # conform to RFC1035
 | |
|    listen-on-v6 { any; };
 | |
| };
 | |
| 
 | |
| logging {
 | |
|    channel simple_log {
 | |
|       file "/var/log/named/bind.log" versions 3 size 5m;
 | |
|       //severity warning;
 | |
|       severity info;
 | |
|       print-time yes;
 | |
|       print-severity yes;
 | |
|       print-category  yes;
 | |
|    };
 | |
|    channel queries_log {
 | |
|       file "/var/log/named/query.log" versions 10 size 5m;
 | |
|       severity debug;
 | |
|       //severity notice;
 | |
|       print-time yes;
 | |
|       print-severity yes;
 | |
|       print-category no;
 | |
|    };
 | |
|    channel log_zone_transfers {
 | |
|       file "/var/log/named/axfr.log" versions 5 size 2m;
 | |
|       severity info;
 | |
|       print-time yes;
 | |
|       print-severity yes;
 | |
|       print-category yes;
 | |
|    };
 | |
|    category resolver {
 | |
|       queries_log;
 | |
|    };
 | |
|    category queries {
 | |
|       queries_log;
 | |
|    };
 | |
|    category xfer-in {
 | |
|       log_zone_transfers;
 | |
|    };
 | |
|    category xfer-out {
 | |
|       log_zone_transfers;
 | |
|    };
 | |
|    category notify {
 | |
|       log_zone_transfers;
 | |
|    };
 | |
|    category default{
 | |
|       simple_log;
 | |
|    };
 | |
| };
 |