-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathnamed.example.conf
70 lines (59 loc) · 1.67 KB
/
named.example.conf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
# vim: ft=named
# named.example.conf
# EugeneKay/dns
#
# Example named.conf
#
options {
listen-on port 53 { 127.0.0.1; any; };
listen-on-v6 port 53 { ::1; any; };
directory "/var/named";
dump-file "/var/named/data/cache_dump.db";
statistics-file "/var/named/data/named_stats.txt";
memstatistics-file "/var/named/data/named_mem_stats.txt";
allow-query { localhost; linode; he; global; };
recursion yes;
allow-recursion { localhost; global; };
allow-transfer { localhost; linode; he; };
allow-notify { nses; dcs; };
also-notify { 216.218.133.2; 2001:470:600::2; 69.93.127.10; 2600:3c00::a; 65.19.178.10; 2600:3c01::a; 75.127.96.10; 2600:3c02::a; 2600:3c03::a; 207.192.70.10; 2a01:7e00::a; 109.74.194.10; };
# These IPs are copied from acls.conf. The also-notify statement prior
# to BIND 9.9 does not support use of a masters-list.
dnssec-enable yes;
dnssec-validation yes;
dnssec-lookaside auto;
/* Path to ISC DLV key */
bindkeys-file "/etc/named.iscdlv.key";
managed-keys-directory "/var/named/dynamic";
pid-file "/run/named/named.pid";
session-keyfile "/run/named/session.key";
rate-limit {
responses-per-second 15;
window 5;
};
};
logging {
channel default_debug {
file "data/named.run";
severity dynamic;
};
channel dnssec_log {
file "data/dnssec";
severity dynamic;
};
};
key korg-dynamic {
algorithm hmac-md5;
secret "XXXXXXXXXXXXXXXXXXXXXX==";
};
zone "." IN {
type hint;
file "named.ca";
};
include "/etc/named.rfc1912.zones";
include "/etc/named.root.key";
include "/etc/named.d/acls.conf";
include "/etc/named.d/global.conf";
include "/etc/named.d/public.conf";
include "/etc/named.d/ad-slave.conf";
include "/etc/named.d/wa-slave.conf";