named
service to provide name resolution services or to act as an authority for a particular domain. However, BIND version 9 has a number of advanced features that allow for a more secure and efficient DNS
service.
Make sure the feature is supported
DNS
entries from clients outside of the local network, while allowing queries from clients inside the local network.
view
statement to the /etc/named.conf
configuration file. Use the match-clients
option to match IP
addresses or entire networks and give them special options and zone data.
IP
address-based method of transfer authorization, since attackers would not only need to have access to the IP
address to transfer the zone, but they would also need to know the secret key.
Secure the transfer
IP
address-based authentication only.
DNS
data, authenticated denial of existence, and data integrity. When a particular domain is marked as secure, the SERVFAIL
response is returned for each resource record that fails the validation.
dig
utility as described in Section 10.2.5, “Using the dig Utility”. Useful options are +dnssec
(requests DNSSEC-related resource records by setting the DNSSEC OK bit), +cd
(tells recursive nameserver not to validate the response), and +bufsize=512
(changes the packet size to 512B to get through some firewalls).
AAAA
resource records, and the listen-on-v6
directive as described in Table 10.3, “Commonly Used Configuration Options”.