Domain Name System
Total Page:16
File Type:pdf, Size:1020Kb
IBM i 7.2 Networking Domain Name System IBM Note Before using this information and the product it supports, read the information in “Notices” on page 49. This edition applies to IBM i 7.2 (product number 5770-SS1) and to all subsequent releases and modifications until otherwise indicated in new editions. This version does not run on all reduced instruction set computer (RISC) models nor does it run on CISC models. This document may contain references to Licensed Internal Code. Licensed Internal Code is Machine Code and is licensed to you under the terms of the IBM License Agreement for Machine Code. © Copyright International Business Machines Corporation 1998, 2013. US Government Users Restricted Rights – Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp. Contents Domain Name System............................................................................................1 What's new for IBM i 7.2..............................................................................................................................1 PDF file for Domain Name System...............................................................................................................2 DNS concepts...............................................................................................................................................2 Understanding zones..............................................................................................................................3 Understanding DNS queries................................................................................................................... 4 DNS domain setup..................................................................................................................................6 Dynamic updates....................................................................................................................................6 BIND 9 features......................................................................................................................................7 DNS resource records.............................................................................................................................9 Mail and MX records.............................................................................................................................14 DNS Security Extensions (DNSSEC) Introduction............................................................................... 15 Examples: DNS...........................................................................................................................................15 Example: Single DNS server for an intranet........................................................................................ 15 Example: Single DNS server with Internet access.............................................................................. 17 Example: DNS and DHCP on the same IBM i.......................................................................................19 Example: Splitting DNS over firewall by setting up two DNS servers on the same System i............. 21 Example: Splitting DNS over firewall by using view............................................................................ 23 Planning for DNS........................................................................................................................................ 25 Determining DNS authorities............................................................................................................... 25 Determining domain structure.............................................................................................................25 Planning security measures.................................................................................................................26 DNS requirements......................................................................................................................................27 Determining if DNS is installed............................................................................................................ 27 Installing DNS.......................................................................................................................................28 Configuring DNS.........................................................................................................................................28 Accessing DNS in IBM Navigator for i.................................................................................................. 28 Configuring name servers.................................................................................................................... 28 Creating a name server instance....................................................................................................29 Editing DNS server properties........................................................................................................ 29 Configuring zones on a name server.............................................................................................. 29 Configuring views on a name server...............................................................................................30 Configuring DNS to receive dynamic updates..................................................................................... 30 Configuring DNSSEC.............................................................................................................................31 Configuring Trusted-keys/Managed-keys...................................................................................... 31 Configuring DNSSEC options.......................................................................................................... 31 Signing a primary zone....................................................................................................................31 Re-signing a primary zone.............................................................................................................. 32 Un-signing a primary zone..............................................................................................................32 Configuring DNSSEC....................................................................................................................... 32 Configuring the allow-update option........................................................................................ 32 Configuring the update-policy option....................................................................................... 32 Configuring the auto-dnssec option......................................................................................... 33 Importing DNS files.............................................................................................................................. 33 Record validation............................................................................................................................ 33 Accessing external DNS data............................................................................................................... 34 Managing DNS............................................................................................................................................34 Verifying the DNS function is working..................................................................................................35 Managing security keys........................................................................................................................ 35 Managing DNS keys........................................................................................................................ 35 Managing dynamic update keys..................................................................................................... 36 iii Making manual updates to a dynamic zone........................................................................................ 36 Managing DNSSEC................................................................................................................................37 Verifying the DNSSEC function is working......................................................................................37 Re-signing a zone............................................................................................................................37 Key rollover consideration ............................................................................................................. 38 Managing DNSSEC for a dynamic zone.......................................................................................... 38 Accessing DNS server statistics...........................................................................................................39 Accessing server statistics............................................................................................................. 39 Accessing an active server database............................................................................................. 39 Maintaining DNS configuration files.....................................................................................................40 Advanced DNS features....................................................................................................................... 43 Starting or stopping DNS servers................................................................................................... 43 Changing