<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Archives des DNS - CoffeeBreak Info</title>
	<atom:link href="https://coffeebreak.en-images.info/tag/dns/feed/" rel="self" type="application/rss+xml" />
	<link>https://coffeebreak.en-images.info/tag/dns/</link>
	<description>Une petite pause :)</description>
	<lastBuildDate>Fri, 11 Nov 2022 15:00:54 +0000</lastBuildDate>
	<language>fr-FR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://coffeebreak.en-images.info/wp-content/uploads/2021/07/cropped-Tasse_Cafe-scaled-1-32x32.jpg</url>
	<title>Archives des DNS - CoffeeBreak Info</title>
	<link>https://coffeebreak.en-images.info/tag/dns/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>MODOP – Grafana/Promotheus pour DNS Primaire et Secondaire</title>
		<link>https://coffeebreak.en-images.info/modop-grafana-promotheus-pour-dns-primaire-et-secondaire/</link>
					<comments>https://coffeebreak.en-images.info/modop-grafana-promotheus-pour-dns-primaire-et-secondaire/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Tue, 20 Jul 2021 13:26:38 +0000</pubDate>
				<category><![CDATA[Grafana]]></category>
		<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Fedora]]></category>
		<category><![CDATA[grafana]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[promotheus]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=3547</guid>

					<description><![CDATA[<p>Mise en place d'une supervision afin de récupérer les métriques sur des serveurs BIND9 DNS Primaire et secondaire via Grafana/Promotheus. </p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-grafana-promotheus-pour-dns-primaire-et-secondaire/">MODOP – Grafana/Promotheus pour DNS Primaire et Secondaire</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span style="text-decoration: underline;"><img fetchpriority="high" decoding="async" class="wp-image-3548 aligncenter" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-300.png" width="903" height="308" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-300.png 1522w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-300-300x102.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-300-1024x349.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-300-768x262.png 768w" sizes="(max-width: 903px) 100vw, 903px" /></span></p>
<p>La machine sera une Fedora 33 Server en installation minimale</p>
<p><img decoding="async" class="wp-image-3549" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-301.png" width="649" height="187" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-301.png 778w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-301-300x86.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-301-768x221.png 768w" sizes="(max-width: 649px) 100vw, 649px" /></p>
<h3><span style="color: #000000;"><strong>1°) Prérequis</strong></span></h3>
<blockquote class="wp-embedded-content" data-secret="f3JENaZLOm"><p><a href="https://coffeebreak.en-images.info/modop-configurer-un-dns-primaire-et-secondaire-centos7/">MODOP &#8211; Configurer un DNS Primaire et Secondaire &#8211; Centos7</a></p></blockquote>
<p><iframe class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="« MODOP &#8211; Configurer un DNS Primaire et Secondaire &#8211; Centos7 » &#8212; CoffeeBreak Info" src="https://coffeebreak.en-images.info/modop-configurer-un-dns-primaire-et-secondaire-centos7/embed/#?secret=f3JENaZLOm" data-secret="f3JENaZLOm" width="600" height="338" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe></p>
<p><strong>Serveur DNS et Secondaire </strong><br />
dns-pri.house.cpb =&gt; IP : 172.16.185.1<br />
dns-sec.house.cpb =&gt; IP : 172.16.185.2</p>
<p>Inscription de la machine cliente grafana04 sur les DNS P et S</p>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>2°) Spécification machine </strong></span></span></h3>
<p><strong>Machine Grafana04</strong><br />
IP : <strong>192.168.1.6 (vSwitch vmbr0) </strong><br />
<strong>Host : grafanad.house.cpb</strong><br />
IP : <strong>172.16.185.23 (vSwitch vmbr1) </strong><br />
Disque 1 – Système 10Go<br />
RAM 2G</p>
<p><strong><img loading="lazy" decoding="async" width="863" height="222" class="wp-image-3550" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-302.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-302.png 863w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-302-300x77.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-302-768x198.png 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></strong></p>
<h3><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">3°) Installation de Middleware </span></span></h3>
<pre>[root@grafana04 ~]# <span style="color: #ff0000;"><strong>dnf -y update</strong></span>
[root@grafana04 ~]# <span style="color: #ff0000;"><strong>dnf -y install nmap net-tools wget</strong></span></pre>
<h3><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">4°) Suppression du selin<strong>ux </strong></span></span></h3>
<pre>[root@grafana04 ~]# <strong><span style="color: #ff0000;">sed -i 's/SELINUX=enforcing/SELINUX=disabled/g' /etc/selinux/config</span></strong>
[root@grafana04 ~]#<span style="color: #ff0000;"><strong> reboot</strong></span></pre>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>5°) Désactivation IPv6</strong></span></span></h3>
<pre>[root@grafana04 ~]# <span style="color: #ff0000;"><strong>vi /etc/sysctl.conf</strong></span>
<span style="color: #ff0000;"><em>net.ipv6.conf.all.disable_ipv6 = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv6.conf.all.autoconf = 0</em></span>
<span style="color: #ff0000;"><em>net.ipv6.conf.default.disable_ipv6 = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv6.conf.default.autoconf = 0</em></span></pre>
<pre>[root@grafana04 ~]# <span style="color: #ff0000;"><strong>sysctl -p</strong></span></pre>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>6°) Installation Promotheus</strong></span></span></h3>
<p><strong>Création User Promotheus</strong></p>
<pre>[root@grafana04 chris]#<span style="color: #ff0000;"><strong> useradd --no-create-home --shell /bin/false prometheus</strong></span></pre>
<p><strong>Récupération de promotheus</strong></p>
<pre>[root@grafana04 ~]#<strong><span style="color: #ff0000;"> cd /tmp</span></strong>
[root@grafana04 tmp]#<span style="color: #ff0000;"><strong> wget </strong></span><a href="https://github.com/prometheus/prometheus/releases/download/v2.8.1/prometheus-2.8.1.linux-amd64.tar.gz"><span style="color: #ff0000;"><strong>https://github.com/prometheus/prometheus/releases/download/v2.8.1/prometheus-2.8.1.linux-amd64.tar.gz</strong></span></a>
[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>tar xzvf prometheus-2.8.1.linux-amd64.tar.gz</strong></span>
[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>mv prometheus-2.8.1.linux-amd64 prometheuspackage</strong></span></pre>
<p><strong>Création structure Promotheus</strong></p>
<pre>[root@grafana04 tmp]# <strong><span style="color: #ff0000;">mkdir /etc/prometheus</span></strong>
[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>mkdir /var/lib/prometheus</strong></span>
[root@grafana04 tmp]#<span style="color: #ff0000;"><strong> chown prometheus:prometheus /etc/prometheus</strong></span>
[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>chown prometheus:prometheus /var/lib/prometheus</strong></span></pre>
<p><strong>Copier les binaires sur la structure Promotheus</strong></p>
<pre>[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>cp prometheuspackage/prometheus /usr/local/bin/</strong></span>
[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>cp prometheuspackage/promtool /usr/local/bin/</strong></span>
[root@grafana04 tmp]#<span style="color: #ff0000;"><strong> chown prometheus:prometheus /usr/local/bin/prometheus</strong></span>
[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>chown prometheus:prometheus /usr/local/bin/promtool</strong></span></pre>
<p><strong>Copier les fichiers conf sur la structure Promotheus</strong></p>
<pre>[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>cp -r prometheuspackage/consoles /etc/prometheus</strong></span>
[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>cp -r prometheuspackage/console_libraries /etc/prometheus</strong></span>
[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>chown -R prometheus:prometheus /etc/prometheus/consoles</strong></span>
[root@grafana04 tmp]#<span style="color: #ff0000;"><strong> chown -R prometheus:prometheus /etc/prometheus/console_libraries</strong></span></pre>
<p><strong>Création du service Promotheus</strong></p>
<pre>[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>vi /etc/systemd/system/prometheus.service</strong></span>

<em>[Unit]</em>
<em>Description=Prometheus</em>
<em>Wants=network-online.target</em>
<em>After=network-online.target</em>
<em>
[Service]</em>
<em>User=prometheus</em>
<em>Group=prometheus </em>
<em>Type=simple</em>
<em>ExecStart=/usr/local/bin/prometheus \</em>
<em>--config.file /etc/prometheus/prometheus.yml \</em>
<em>--storage.tsdb.path /var/lib/prometheus/ \</em>
<em>--web.console.templates=/etc/prometheus/consoles \</em>
<em>--web.console.libraries=/etc/prometheus/console_libraries</em>
<em>
[Install]</em>
<em>WantedBy=multi-user.target</em></pre>
<p><strong>Configurer Promotheus</strong></p>
<pre>[root@grafana04 tmp]#<span style="color: #ff0000;"><strong> vi /etc/prometheus/prometheus.yml</strong></span>

<em>global:</em>
<em> scrape_interval: 10s</em>
<em>scrape_configs:</em>
<em> - job_name: dns</em>
<em> scrape_interval: 5s</em>
<em> static_configs:</em>
<em> - targets: [</em><strong><em>'dns-pri.house.cpb:9153'</em></strong><em>]</em>
<em> - targets: [</em><strong><em>'dns-sec.house.cpb:9153'</em></strong><em>]</em>
</pre>
<p><strong>Démarrage du service Promotheus</strong></p>
<pre>[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>systemctl daemon-reload</strong></span>
[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>systemctl start prometheus &amp;&amp; systemctl enable prometheus</strong></span>
[root@grafana04 tmp]# <span style="color: #ff0000;"><strong>systemctl status prometheus</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1704" height="398" class="wp-image-3551" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-303.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-303.png 1704w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-303-300x70.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-303-1024x239.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-303-768x179.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-303-1536x359.png 1536w" sizes="auto, (max-width: 1704px) 100vw, 1704px" /></p>
<p><strong>Régle de Firewall – Promotheus /Exporter </strong></p>
<pre>[root@grafana04 ~]#<span style="color: #ff0000;"><strong> firewall-cmd --zone=public --add-port={9090,9153}/tcp --permanent</strong></span>
[root@grafana04 ~]# <strong><span style="color: #ff0000;">firewall-cmd  --reload</span></strong></pre>
<ul>
<li><em><strong>http://grafana.house.cpb:9090</strong></em></li>
</ul>
<pre><img loading="lazy" decoding="async" width="806" height="462" class="wp-image-3552" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-304.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-304.png 806w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-304-300x172.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-304-768x440.png 768w" sizes="auto, (max-width: 806px) 100vw, 806px" /></pre>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>7°) Installation Grafana</strong></span></span></h3>
<pre>[root@grafana04 ~]#<span style="color: #ff0000;"><strong> vi /etc/yum.repos.d/grafana.repo</strong></span>

<em>[grafana]</em>
<em>name=grafana</em>
<em>baseurl=https://packages.grafana.com/oss/rpm</em>
<em>repo_gpgcheck=1</em>
<em>enabled=1</em>
<em>gpgcheck=1</em>
<em>gpgkey=https://packages.grafana.com/gpg.key</em>
<em>sslverify=1</em>
<em>sslcacert=/etc/pki/tls/certs/ca-bundle.crt</em></pre>
<pre>[root@grafana04 ~]# <span style="color: #ff0000;"><strong>dnf update</strong></span>
[root@grafana04 ~]# <span style="color: #ff0000;"><strong>dnf install grafana</strong></span></pre>
<p><strong>Installation de font du Supplémentaire </strong></p>
<pre>[root@grafana04 ~]# <span style="color: #ff0000;"><strong>dnf install fontconfig freetype* urw-fonts</strong></span></pre>
<p><strong>Activer Grafana </strong></p>
<pre>[root@grafana04 ~]#<span style="color: #ff0000;"><strong> systemctl start grafana-server &amp;&amp; systemctl enable grafana-server</strong></span> [root@grafana04 ~]#<span style="color: #ff0000;"><strong> systemctl status grafana-server</strong></span></pre>
<p><strong>Régle de Firewall – grafana</strong></p>
<pre>[root@grafana04 ~]# <span style="color: #ff0000;"><strong>firewall-cmd --zone=public --add-port=3000/tcp --permanent</strong></span>
[root@grafana04 ~]# <span style="color: #ff0000;"><strong>firewall-cmd --reload</strong></span></pre>
<p><em><strong><a href="http://grafanad.house.cpb:3000">http://grafanad.house.cpb:3000</a></strong></em></p>
<p><img loading="lazy" decoding="async" width="1878" height="714" class="wp-image-3553" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-305.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-305.png 1878w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-305-300x114.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-305-1024x389.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-305-768x292.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-305-1536x584.png 1536w" sizes="auto, (max-width: 1878px) 100vw, 1878px" /></p>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>8°) Installer l’exporter BIND sur les 2 DNS P et S </strong></span></span></h3>
<p><strong>Installation de GO</strong></p>
<pre>[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>yum update -y</strong></span>
[root@dns-pri tmp]#<span style="color: #ff0000;"><strong> yum groupinstall 'Development Tools'</strong></span>
[root@dns-pri tmp]#<span style="color: #ff0000;"><strong> cd /tmp;wget https://golang.org/dl/go1.15.3.linux-amd64.tar.gz</strong></span>
[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>tar -zxvf go1.15.3.linux-amd64.tar.gz -C /usr/local</strong></span></pre>
<pre>[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>echo 'export GOROOT=/usr/local/go' | sudo tee -a /etc/profile</strong></span>
<span style="color: #ff0000;"><em>export GOROOT=/usr/local/go</em></span>
[root@dns-pri tmp]#<span style="color: #ff0000;"><strong>echo 'export PATH=$PATH:/usr/local/go/bin' | sudo tee -a /etc/profile</strong></span>
<span style="color: #ff0000;"><em>export PATH=$PATH:/usr/local/go/bin</em></span>
[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>source /etc/profile</strong></span></pre>
<pre>[root@dns-pri tmp]#<span style="color: #ff0000;"><strong> go version</strong></span>
<span style="color: #ff0000;"><em>go version go1.15.3 linux/amd64</em></span></pre>
<p><strong>Compilation et Installation de BIND exporter</strong></p>
<pre>[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>https://github.com/prometheus-community/bind_exporter.git</strong></span>
[root@dns-pri tmp]#<span style="color: #ff0000;"><strong> cd bind_exporter/</strong></span>
<span style="color: #ff0000;"><em>make</em></span>
[root@dns-pri bind_exporter]# <span style="color: #ff0000;"><strong>mv bind_exporter /usr/local/bin</strong></span></pre>
<p><strong>Création Group/User privilège</strong></p>
<pre>[root@dns-pri tmp]#<span style="color: #ff0000;"><strong> groupadd --system prometheus</strong></span>
[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>useradd -s /sbin/nologin --system -g prometheus prometheus</strong></span></pre>
<p><strong>Création du service exporter_Bind</strong></p>
<pre>[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>vi /etc/systemd/system/bind_exporter.service</strong></span>

<em>[Unit]</em>
<em>Description=Prometheus</em>
<em>Documentation=https://github.com/digitalocean/bind_exporter</em>
<em>Wants=network-online.target</em>
<em>After=network-online.target</em>
<em>
[Service]</em>
<em>Type=simple</em>
<em>User=prometheus</em>
<em>Group=prometheus</em>
<em>ExecReload=/bin/kill -HUP $MAINPID</em>
<em>ExecStart=/usr/local/bin/bind_exporter \</em>
<em> --bind.pid-file=/var/run/named/named.pid \</em>
<em> --bind.timeout=20s \</em>
<em> --web.listen-address=0.0.0.0:9153 \</em>
<em> --web.telemetry-path=/metrics \</em>
<em> --bind.stats-url=http://localhost:8053/ \</em>
<em> --bind.stats-groups=server,view,tasks</em>
<em>SyslogIdentifier=prometheus</em>
<em>Restart=always</em>
<em>
[Install]
WantedBy=multi-user.target
</em></pre>
<pre>[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>systemctl enable bind_exporter.service</strong></span>
[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>systemctl start bind_exporter.service</strong></span>
[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>systemctl status bind_exporter.service</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1706" height="245" class="wp-image-3554" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-306.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-306.png 1706w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-306-300x43.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-306-1024x147.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-306-768x110.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-306-1536x221.png 1536w" sizes="auto, (max-width: 1706px) 100vw, 1706px" /></p>
<p><strong>Régle de Firewall – exporter</strong></p>
<pre>[root@dns-pri tmp]#<span style="color: #ff0000;"><strong> firewall-cmd --zone=public --add-port=9153/tcp --permanent</strong></span>
[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>firewall-cmd --reload</strong></span></pre>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>9°) Configurer Service BIND pour l’exporter</strong></span></span></h3>
<pre>[root@dns-pri etc]# <span style="color: #ff0000;"><strong>vi /etc/named.conf</strong></span></pre>
<p>Ajouter</p>
<pre><em>statistics-channels {</em>
<em> inet 127.0.0.1 port 8053 allow { 127.0.0.1; };</em>
<em>};</em></pre>
<p><img loading="lazy" decoding="async" width="617" height="335" class="wp-image-3555" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-307.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-307.png 617w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-307-300x163.png 300w" sizes="auto, (max-width: 617px) 100vw, 617px" /></p>
<p>[root@dns-pri etc]# <span style="color: #ff0000;"><strong>systemctl reload named</strong></span></p>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>10°) Configurer Prometheus et Grafana</strong></span></span></h3>
<ul>
<li><em><strong><span style="color: #000000;"><a style="color: #000000;" href="http://grafanad.house.cpb:3000/">http://grafanad.house.cpb:3000/</a></span></strong></em></li>
</ul>
<p><img loading="lazy" decoding="async" width="1507" height="467" class="wp-image-3556" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-308.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-308.png 1507w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-308-300x93.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-308-1024x317.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-308-768x238.png 768w" sizes="auto, (max-width: 1507px) 100vw, 1507px" /><br />
« Ajouter DATA source »</p>
<p><img loading="lazy" decoding="async" width="895" height="160" class="wp-image-3557" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-309.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-309.png 895w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-309-300x54.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-309-768x137.png 768w" sizes="auto, (max-width: 895px) 100vw, 895px" /><br />
« Choisir la source »</p>
<p><img loading="lazy" decoding="async" width="656" height="298" class="wp-image-3558" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-310.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-310.png 656w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-310-300x136.png 300w" sizes="auto, (max-width: 656px) 100vw, 656px" /><br />
« Inscrire l’adresse du serveur Promotheus »</p>
<p><img loading="lazy" decoding="async" width="602" height="157" class="wp-image-3559" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-311.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-311.png 602w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-311-300x78.png 300w" sizes="auto, (max-width: 602px) 100vw, 602px" /></p>
<p><strong>Ajouter un Dasboard</strong><br />
<img loading="lazy" decoding="async" width="222" height="150" class="wp-image-3560" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-312.png" /><br />
« Import »</p>
<p><img loading="lazy" decoding="async" width="688" height="185" class="wp-image-3561" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-313.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-313.png 688w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-313-300x81.png 300w" sizes="auto, (max-width: 688px) 100vw, 688px" /><br />
« Ajouter l’ID souhaité » puis « Load »</p>
<p><img loading="lazy" decoding="async" width="607" height="566" class="wp-image-3562" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-314.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-314.png 607w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-314-300x280.png 300w" sizes="auto, (max-width: 607px) 100vw, 607px" /><br />
« Import »</p>
<p><img loading="lazy" decoding="async" width="1837" height="907" class="wp-image-3563" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-315.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-315.png 1837w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-315-300x148.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-315-1024x506.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-315-768x379.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-315-1536x758.png 1536w" sizes="auto, (max-width: 1837px) 100vw, 1837px" /><br />
« Arrivée des métriques »</p>
<h3><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">11°) Ajouter le DNS Secondaire sur le DashBoard</span></span></h3>
<p><strong>Création Group/User privilège (Service)</strong></p>
<pre>[root@dns-sec ~]# <strong><span style="color: #ff0000;">groupadd --system prometheus</span></strong>
[root@dns-sec ~]# <span style="color: #ff0000;"><strong>useradd -s /sbin/nologin --system -g prometheus prometheus</strong></span></pre>
<p><strong>Copier l’exporter sur le DNS Secondaire</strong></p>
<pre>[root@dns-sec ~]# <span style="color: #ff0000;"><strong>scp /usr/local/bin/bind_exporter root@dns-sec:/usr/local/bin/bind_exporter</strong></span></pre>
<p><strong>Copier le service exporter Bind</strong></p>
<pre>[root@dns-sec bind_exporter]# <span style="color: #ff0000;"><strong>scp/etc/systemd/system/bind_exporter.service <a style="color: #ff0000;" href="mailto:root@dns-sec:/etc/systemd/system/bind_exporter.service">root@dns-sec:/etc/systemd/system/bind_exporter.service</a></strong></span></pre>
<p><strong>Activer les statistiques dans Bind</strong></p>
<pre>[root@dns-sec ~]# <span style="color: #ff0000;"><strong>vi /etc/named.conf</strong></span></pre>
<p>Ajouter</p>
<pre><em>statistics-channels {</em>
<em> inet 127.0.0.1 port 8053 allow { 127.0.0.1; };</em>
<em>};</em></pre>
<p><strong>Lancer le service exporter</strong></p>
<pre>[root@dns-sec ~]# <span style="color: #ff0000;"><strong>systemctl enable bind_exporter.service</strong></span>
[root@dns-sec ~]#<span style="color: #ff0000;"><strong> systemctl start bind_exporter.service</strong></span>
[root@dns-sec ~]# <span style="color: #ff0000;"><strong>systemctl status bind_exporter.service</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1628" height="250" class="wp-image-3564" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-316.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-316.png 1628w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-316-300x46.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-316-1024x157.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-316-768x118.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-316-1536x236.png 1536w" sizes="auto, (max-width: 1628px) 100vw, 1628px" /></p>
<p><strong>Régle de Firewall – exporter sur le DNS Secondaire</strong></p>
<pre>[root@dns-pri tmp]#<span style="color: #ff0000;"><strong> firewall-cmd --zone=public --add-port=9153/tcp --permanent</strong></span>
[root@dns-pri tmp]# <span style="color: #ff0000;"><strong>firewall-cmd --reload</strong></span></pre>
<p>On récupère bien les deux DNS sur le Dasboard Grafana<br />
<img loading="lazy" decoding="async" width="791" height="205" class="wp-image-3565" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-317.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-317.png 791w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-317-300x78.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-317-768x199.png 768w" sizes="auto, (max-width: 791px) 100vw, 791px" /><br />
<img loading="lazy" decoding="async" width="1830" height="876" class="wp-image-3566" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-318.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-318.png 1830w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-318-300x144.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-318-1024x490.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-318-768x368.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-318-1536x735.png 1536w" sizes="auto, (max-width: 1830px) 100vw, 1830px" /></p>
<p>Views: 19</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-grafana-promotheus-pour-dns-primaire-et-secondaire/">MODOP – Grafana/Promotheus pour DNS Primaire et Secondaire</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-grafana-promotheus-pour-dns-primaire-et-secondaire/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP &#8211; Configurer un DNS Primaire et Secondaire &#8211; Centos7</title>
		<link>https://coffeebreak.en-images.info/modop-configurer-un-dns-primaire-et-secondaire-centos7/</link>
					<comments>https://coffeebreak.en-images.info/modop-configurer-un-dns-primaire-et-secondaire-centos7/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Sat, 05 Jun 2021 17:09:30 +0000</pubDate>
				<category><![CDATA[Système]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Cluster]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=1111</guid>

					<description><![CDATA[<p>Mise en place d'un DNS Primaire et Secondaire. Les deux annuaires de service permettent à un client d'identifier les autres machines sur le réseau.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-configurer-un-dns-primaire-et-secondaire-centos7/">MODOP &#8211; Configurer un DNS Primaire et Secondaire &#8211; Centos7</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>Les deux machines DNS seront des machines Centos7</strong></p>
<p><img loading="lazy" decoding="async" width="956" height="567" class="wp-image-1114" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-218.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-218.png 956w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-218-300x178.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-218-768x455.png 768w" sizes="auto, (max-width: 956px) 100vw, 956px" /><br />
Elles vont répondre à toutes les requêtes envoyées par les VM du réseau VM et privé pour identifier<br />
Les machines par leurs noms machines.</p>
<p><strong>Spécification des machines</strong><br />
Le Pool « Server_DNS » va être composé de deux machines virtuelles</p>
<ul>
<li>dns-pri.house.cpb =&gt; 172.16.185.1
<ul>
<li>2vCPU, 2G RAM, 32Go Disk</li>
</ul>
</li>
<li>dns-pri.house.cpb =&gt; 172.16.185.2
<ul>
<li>2vCPU, 2G RAM, 32Go Disk</li>
</ul>
</li>
</ul>
<p><img loading="lazy" decoding="async" width="999" height="164" class="wp-image-1115" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-219.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-219.png 999w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-219-300x49.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-219-768x126.png 768w" sizes="auto, (max-width: 999px) 100vw, 999px" /></p>
<p><strong>Désactiver SeLinux (sur les 2 machines)</strong></p>
<pre>[ @dns-pri ~]$ <span style="color: #ff0000;"><strong>vi /etc/sysconfig/selinux</strong></span>
<em><span style="color: #ff0000;">SELINUX=disabled</span></em></pre>
<p><span style="color: #ff0000;"><strong>Reboot Machine.</strong></span></p>
<p><strong>Désactiver IPv6 (sur les 2 machines)</strong></p>
<pre>[chris@dns-pri ~]$<strong><span style="color: #ff0000;"> vi /etc/sysctl.d/disableipv6.conf</span></strong>
<span style="color: #ff0000;"><em>net.ipv6.conf.all.disable_ipv6 = 1</em></span></pre>
<p><strong>Installation des paquets utiles (sur les 2 machines)</strong></p>
<pre>[root@dns-pri chris]# <strong><span style="color: #ff0000;">yum update &amp;&amp; yum upgrade</span></strong>
[root@dns-pri chris]# <strong><span style="color: #ff0000;">yum install qemu-guest-agent</span></strong>
[root@dns-pri chris]# <strong><span style="color: #ff0000;">yum install htop nmap net-tools</span></strong></pre>
<p>Installer le serveur BIND (sur les 2 machines)</p>
<pre>[root@dns-pri chris]# <span style="color: #ff0000;">yum install -y bind bind-utils</span></pre>
<h3><span style="text-decoration: underline;"><strong>1°) Mise en place Serveur Primaire (dns-pri.house.cpb)</strong></span></h3>
<p><strong>Configuration du serveur Primaire (dns-pri.house.cpb)</strong></p>
<pre>[root@dns-pri chris]# <strong><span style="color: #ff0000;">cp /etc/named.conf{,-old}</span></strong></pre>
<pre>[root@dns-pri chris]# <strong><span style="color: #ff0000;">vi /etc/named.conf</span></strong>
<span style="color: #ff0000;"><em>options {</em></span>
<span style="color: #ff0000;"><strong><em>listen-on port 53 { 127.0.0.1; 172.16.185.1 ; };</em></strong></span>
<span style="color: #ff0000;"><strong><em> #listen-on-v6 port 53 { ::1; };</em></strong></span>
<span style="color: #ff0000;"><em> directory "/var/named";</em></span>
<span style="color: #ff0000;"><em> dump-file "/var/named/data/cache_dump.db";</em></span>
<span style="color: #ff0000;"><em> statistics-file "/var/named/data/named_stats.txt";</em></span>
<span style="color: #ff0000;"><em> memstatistics-file "/var/named/data/named_mem_stats.txt";</em></span>
<span style="color: #ff0000;"><em> recursing-file "/var/named/data/named.recursing";</em></span>
<span style="color: #ff0000;"><em> secroots-file "/var/named/data/named.secroots";</em></span>
<span style="color: #ff0000;"><strong><em> allow-query { localhost; 172.16.185.0/24;};</em></strong></span>
<span style="color: #ff0000;"><strong><em> allow-transfer { localhost; 172.16.185.2; };</em></strong></span>

<span style="color: #ff0000;"><em>recursion yes;</em></span>

<span style="color: #ff0000;"><em>dnssec-enable yes;</em></span>
<span style="color: #ff0000;"><em> dnssec-validation yes;</em></span>

<span style="color: #ff0000;"><em>/* Path to ISC DLV key */</em></span>
<span style="color: #ff0000;"><em> bindkeys-file "/etc/named.root.key";</em></span>
<span style="color: #ff0000;"><em> managed-keys-directory "/var/named/dynamic";</em></span>
<span style="color: #ff0000;"><em> pid-file "/run/named/named.pid";</em></span>
<span style="color: #ff0000;"><em> session-keyfile "/run/named/session.key";</em></span>
<span style="color: #ff0000;"><em>};</em></span>

<span style="color: #ff0000;"><em>logging {</em></span>
<span style="color: #ff0000;"><em> channel default_debug {</em></span>
<span style="color: #ff0000;"><em> file "data/named.run";</em></span>
<span style="color: #ff0000;"><em> severity dynamic;</em></span>
<span style="color: #ff0000;"><em> };</em></span>
<span style="color: #ff0000;"><em>};</em></span>

<span style="color: #ff0000;"><em>zone "." IN {</em></span>
<span style="color: #ff0000;"><em> type hint;</em></span>
<span style="color: #ff0000;"><em> file "named.ca";</em></span>
<span style="color: #ff0000;"><em>};</em></span>

<span style="color: #ff0000;"><strong><em>zone "house.cpb" IN {</em></strong></span>
<span style="color: #ff0000;"><strong><em> type master;</em></strong></span>
<span style="color: #ff0000;"><strong><em> file "forward.house.cpb";</em></strong></span>
<span style="color: #ff0000;"><strong><em> allow-update { none; };</em></strong></span>
<span style="color: #ff0000;"><strong><em>};</em></strong></span>

<span style="color: #ff0000;"><strong><em>zone "185.16.172.in-addr.arpa" IN {</em></strong></span>
<span style="color: #ff0000;"><strong><em> type master;</em></strong></span>
<span style="color: #ff0000;"><strong><em> file "reverse.house.cpb";</em></strong></span>
<span style="color: #ff0000;"><strong><em> allow-update { none; };</em></strong></span>
<span style="color: #ff0000;"><strong><em>};</em></strong></span></pre>
<p><strong>Création du fichier de Zone « forward.house.cpb » (dns-pri.house.cpb)</strong></p>
<pre>[root@dns-pri chris]# <strong><span style="color: #ff0000;">vi /var/named/forward.house.cpb</span></strong>
<span style="color: #ff0000;"><em>$TTL 86400</em></span>
<span style="color: #ff0000;"><em>@ IN SOA dns-pri.house.cpb. root.house.cpb. (</em></span>
<span style="color: #ff0000;"><em> 2021040601 ;Serial</em></span>
<span style="color: #ff0000;"><em> 3600 ;Refresh</em></span>
<span style="color: #ff0000;"><em> 1800 ;Retry</em></span>
<span style="color: #ff0000;"><em> 604800 ;Expire</em></span>
<span style="color: #ff0000;"><em> 86400 ;Minimum TTL</em></span>
<span style="color: #ff0000;"><em>)</em></span>
<strong><span style="color: #ff0000;"><em>@ IN NS dns-pri.house.cpb.</em></span></strong>
<strong><span style="color: #ff0000;"><em>@ IN NS dns-sec.house.cpb.</em></span></strong>
<strong><span style="color: #ff0000;"><em>@ IN A 172.16.185.1</em></span></strong>
<strong><span style="color: #ff0000;"><em>@ IN A 172.16.185.2</em></span></strong>
<span style="color: #ff0000;"><em>; Machine Serveur DNS</em></span>
<strong><span style="color: #ff0000;"><em>dns-pri IN A 172.16.185.1</em></span></strong>
<strong><span style="color: #ff0000;"><em>dns-sec IN A 172.16.185.2</em></span></strong></pre>
<p><strong><span style="color: #000000;">Création du fichier de Zone « reverse.house.cpb » (dns-pri.house.cpb)</span></strong></p>
<pre><span style="color: #000000;">[root@dns-pri chris]# <span style="color: #ff0000;"><strong>vi /var/named/reverse.house.cpb</strong></span></span>
<span style="color: #ff0000;"><em>$TTL 86400</em></span>
<span style="color: #ff0000;"><em>@ IN SOA dns-pri.house.cpb. root.house.cpb. (</em></span>
<span style="color: #ff0000;"><em> 2021070601 ;Serial</em></span>
<span style="color: #ff0000;"><em> 3600 ;Refresh</em></span>
<span style="color: #ff0000;"><em> 1800 ;Retry</em></span>
<span style="color: #ff0000;"><em> 604800 ;Expire</em></span>
<span style="color: #ff0000;"><em> 86400 ;Minimum TTL</em></span>
<span style="color: #ff0000;"><em>)</em></span>
<strong><span style="color: #ff0000;"><em>@ IN NS dns-pri.house.cpb.</em></span></strong>
<strong><span style="color: #ff0000;"><em>@ IN NS dns-sec.house.cpb.</em></span></strong>
<strong><span style="color: #ff0000;"><em>dns-pri IN A 172.16.185.1</em></span></strong>
<strong><span style="color: #ff0000;"><em>dns-sec IN A 172.16.185.2</em></span></strong>
<strong><span style="color: #ff0000;"><em>1 IN PTR dns-pri.house.cpb.</em></span></strong>
<strong><span style="color: #ff0000;"><em>2 IN PTR dns-sec.house.cpb.</em></span></strong></pre>
<p><strong>Ajustement des droits (dns-pri.house.cpb)</strong></p>
<pre>[root@dns-pri named]# <strong><span style="color: #ff0000;">chmod 640 /var/named/reverse.house.cpb /var/named/forward.house.cpb</span></strong>
[root@dns-pri named]#<span style="color: #ff0000;"><strong> chown root.named /var/named/reverse.house.cpb /var/named/forward.house.cpb</strong></span></pre>
<p><strong>Test des Configurations (dns-pri.house.cpb)</strong></p>
<pre>[root@dns-pri named]# <strong><span style="color: #ff0000;">named-checkconf /etc/named.conf</span></strong>
[root@dns-pri named]# <span style="color: #ff0000;"><strong>named-checkzone house.cpb forward.house.cpb</strong></span>
<em>zone house.cpb/IN: loaded serial 2021040601</em>
<strong><span style="color: #00ff00;"><em>OK</em></span></strong>
[root@dns-pri named]# <span style="color: #ff0000;"><strong>named-checkzone house.cpb reverse.house.cpb</strong></span>
<em>zone house.cpb/IN: loaded serial 2021070601</em>
<span style="color: #00ff00;"><em>OK</em></span></pre>
<p><span style="color: #000000;"><strong>Démarrage du DNS (dns-pri.house.cpb</strong></span>)</p>
<pre>[root@dns-pri named]# <span style="color: #ff0000;"><strong>systemctl start named</strong></span>
[root@dns-pri named]# <strong><span style="color: #ff0000;">systemctl enable named</span></strong></pre>
<p><strong>Configuration du resolver.conf (dns-pri.house.cpb)</strong></p>
<pre>[root@dns-pri named]# <strong><span style="color: #ff0000;">vi /etc/resolv.conf</span></strong>
<span style="color: #ff0000;"><em>search house.cpb</em></span>
<span style="color: #ff0000;"><em>#nameserver 192.168.1.1</em></span>
<span style="color: #ff0000;"><em>nameserver 172.16.185.1</em></span>
<span style="color: #ff0000;"><em>nameserver 172.16.185.2</em></span></pre>
<p><strong>Test de la résolution du domaine « house.cpb » (dns-pri.house.cpb)</strong></p>
<pre>[root@dns-pri named]# <span style="color: #ff0000;"><strong>nslookup house.cpb</strong></span>
<span style="color: #ff0000;"><em>Server: 172.16.185.1</em></span>
<span style="color: #ff0000;"><em>Address: 172.16.185.1#53</em></span>

<span style="color: #ff0000;"><em>Name: house.cpb</em></span>
<span style="color: #ff0000;"><em>Address: 172.16.185.2</em></span>
<span style="color: #ff0000;"><em>Name: house.cpb</em></span>
<span style="color: #ff0000;"><em>Address: 172.16.185.1</em></span></pre>
<pre>[root@dns-pri named]# <span style="color: #ff0000;"><strong>dig house.cpb</strong></span>
<em>; &lt;&lt;&gt;&gt; DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.4 &lt;&lt;&gt;&gt; house.cpb</em>
<em>;; global options: +cmd</em>
<em>;; Got answer:</em>
<em>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 1610</em>
<em>;; flags: qr aa rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 2, ADDITIONAL: 3</em>

<em>;; OPT PSEUDOSECTION:</em>
<em>; EDNS: version: 0, flags:; udp: 4096</em>
<em>;; QUESTION SECTION:</em>
<em>;house.cpb. IN A</em>

<em>;; ANSWER SECTION:</em>
<span style="color: #ff0000;"><strong><em>house.cpb. 86400 IN A 172.16.185.1</em></strong></span>
<strong><em><span style="color: #ff0000;">house.cpb. 86400 IN A 172.16.185.2</span></em></strong>

<em>;; AUTHORITY SECTION:</em>
<span style="color: #ff0000;"><strong><em>house.cpb. 86400 IN NS dns-pri.house.cpb.</em></strong></span>
<span style="color: #ff0000;"><strong><em>house.cpb. 86400 IN NS dns-sec.house.cpb.</em></strong></span>

<em>;; ADDITIONAL SECTION:</em>
<span style="color: #ff0000;"><strong><em>dns-pri.house.cpb. 86400 IN A 172.16.185.1</em></strong></span>
<span style="color: #ff0000;"><strong><em>dns-sec.house.cpb. 86400 IN A 172.16.185.2</em></strong></span>

<em>;; Query time: 0 msec</em>
<em>;; SERVER: 172.16.185.1#53(172.16.185.1)</em>
<em>;; WHEN: Tue Apr 06 19:35:27 CEST 2021</em>
<em>;; MSG SIZE rcvd: 146</em></pre>
<p><strong>Ouverture des Rules dans le firewall (dns-pri.house.cpb)</strong></p>
<pre>[root@dns-pri named]# <strong><span style="color: #ff0000;">firewall-cmd --zone=public --add-port=53/tcp --permanent</span></strong>
[root@dns-pri named]# <strong><span style="color: #ff0000;">firewall-cmd --zone=public --add-port=53/udp --permanent</span></strong>
[root@dns-pri named]# <strong><span style="color: #ff0000;">firewall-cmd --reload</span></strong>
[root@dns-pri named]#<span style="color: #ff0000;"><strong> firewall-cmd --list-ports</strong></span>
<span style="color: #ff0000;"><strong>53/tcp 53/udp</strong></span></pre>
<h3><strong><u>2°)Mise en place Serveur secondaire (dns-sec.house.cpb)</u></strong></h3>
<p><strong>Configuration du serveur Secondaire (dns-sec.house.cpb)</strong></p>
<pre>[root@dns-sec cp219538]#<span style="color: #ff0000;"><strong> cp /etc/named.conf{,-old}</strong></span></pre>
<pre>[root@dns-sec cp219538]# <span style="color: #ff0000;"><strong>vi /etc/named.conf</strong></span>
<em> </em>
<span style="color: #ff0000;"><em>options {</em></span>
<span style="color: #ff0000;"><strong><em>        listen-on port 53 { 127.0.0.1;172.16.185.2; };</em></strong></span>
<span style="color: #ff0000;"><strong><em>        #listen-on-v6 port 53 { ::1; };</em></strong></span>
<span style="color: #ff0000;"><em>        directory       "/var/named";</em></span>
<span style="color: #ff0000;"><em>        dump-file       "/var/named/data/cache_dump.db";</em></span>
<span style="color: #ff0000;"><em>        statistics-file "/var/named/data/named_stats.txt";</em></span>
<span style="color: #ff0000;"><em>        memstatistics-file "/var/named/data/named_mem_stats.txt";</em></span>
<span style="color: #ff0000;"><em>        recursing-file  "/var/named/data/named.recursing";</em></span>
<span style="color: #ff0000;"><em>        secroots-file   "/var/named/data/named.secroots";</em></span>
<span style="color: #ff0000;"><em>        <strong>allow-query     { localhost;172.16.185.0/24; };</strong></em></span>
<span style="color: #ff0000;"><em> </em></span>
<span style="color: #ff0000;"><em>        recursion yes;</em></span>
<span style="color: #ff0000;"><em> </em></span>
<span style="color: #ff0000;"><em>        dnssec-enable yes;</em></span>
<span style="color: #ff0000;"><em>        dnssec-validation yes;</em></span>
<span style="color: #ff0000;"><em> </em></span>
<span style="color: #ff0000;"><em>        /* Path to ISC DLV key */</em></span>
<span style="color: #ff0000;"><em>        bindkeys-file "/etc/named.root.key";</em></span>
<span style="color: #ff0000;"><em> </em></span>
<span style="color: #ff0000;"><em>        managed-keys-directory "/var/named/dynamic";</em></span>
<span style="color: #ff0000;"><em> </em></span>
<span style="color: #ff0000;"><em>        pid-file "/run/named/named.pid";</em></span>
<span style="color: #ff0000;"><em>        session-keyfile "/run/named/session.key";</em></span>
<span style="color: #ff0000;"><em>};</em></span>
<span style="color: #ff0000;"><em> </em></span>
<span style="color: #ff0000;"><em>logging {</em></span>
<span style="color: #ff0000;"><em>        channel default_debug {</em></span>
<span style="color: #ff0000;"><em>                file "data/named.run";</em></span>
<span style="color: #ff0000;"><em>                severity dynamic;</em></span>
<span style="color: #ff0000;"><em>        };</em></span>
<span style="color: #ff0000;"><em>};</em></span>
<span style="color: #ff0000;"><em> </em></span>
<span style="color: #ff0000;"><em>zone "." IN {</em></span>
<span style="color: #ff0000;"><em>        type hint;</em></span>
<span style="color: #ff0000;"><em>        file "named.ca";</em></span>
<span style="color: #ff0000;"><em>};</em></span>
<span style="color: #ff0000;"><em> </em></span>
<span style="color: #ff0000;"><strong><em>zone "house.cpb" IN {</em></strong></span>
<span style="color: #ff0000;"><strong><em>    type slave;</em></strong></span>
<span style="color: #ff0000;"><strong><em>    file "slaves/forward.house.cpb";</em></strong></span>
<span style="color: #ff0000;"><strong><em>    masters { 172.16.185.1; };</em></strong></span>
<span style="color: #ff0000;"><strong><em>};</em></strong></span>
<span style="color: #ff0000;"><strong><em> </em></strong></span>
<span style="color: #ff0000;"><strong><em>zone "185.16.172.in-addr.arpa" IN {</em></strong></span>
<span style="color: #ff0000;"><strong><em>    type slave;</em></strong></span>
<span style="color: #ff0000;"><strong><em>    file "slaves/reverse.house.cpb";</em></strong></span>
<span style="color: #ff0000;"><strong><em>    masters { 172.16.185.1; };</em></strong></span>
<span style="color: #ff0000;"><strong><em>};</em></strong></span></pre>
<p><strong>Lancement serveur Secondaire (dns-sec.house.cpb)</strong></p>
<pre>[root@dns-sec cp219538]# <span style="color: #ff0000;"><strong>systemctl start named</strong></span>
[root@dns-sec cp219538]# <span style="color: #ff0000;"><strong>systemctl enable named</strong></span></pre>
<p><strong>Ouverture des Rules dans le firewall (dns-sec.house.cpb)</strong></p>
<pre>[root@dns-sec named]# <span style="color: #ff0000;"><strong>firewall-cmd --zone=public --add-port=53/tcp --permanent</strong></span>
[root@dns-sec named]#<strong><span style="color: #ff0000;"> firewall-cmd --zone=public --add-port=53/udp --permanent</span></strong>
[root@dns-sec named]# <span style="color: #ff0000;"><strong>firewall-cmd --reload</strong></span>
[root@dns-sec named]#<strong><span style="color: #ff0000;"> firewall-cmd --list-ports</span></strong>
<span style="color: #ff0000;"><strong>53/tcp 53/udp</strong></span></pre>
<p><strong>Vérifions la réplication du serveur Primaire vers le secondaire</strong></p>
<pre>[root@dns-sec cp219538]# <span style="color: #ff0000;"><strong>ls /var/named/slaves/</strong></span>
<span style="color: #ff0000;"><em>forward.house.cpb  reverse.house.cpb</em></span></pre>
<p><strong>Configuration du resolver.conf (dns-sec.house.cpb)</strong></p>
<pre>[root@dns-sec named]# <strong><span style="color: #ff0000;">vi /etc/resolv.conf</span></strong>
<span style="color: #ff0000;"><em>search house.cpb</em></span>
<span style="color: #ff0000;"><em>#nameserver 192.168.1.1</em></span>
<span style="color: #ff0000;"><em>nameserver 172.16.185.1</em></span>
<span style="color: #ff0000;"><em>nameserver 172.16.185.2</em></span></pre>
<h3><span style="text-decoration: underline;"><strong>3°) Ajouter des machines dans le DNS et propagation au DNS secondaire</strong></span></h3>
<p><strong>Editer le fichier « forward.house.cpb »</strong></p>
<pre>[root@dns-pri chris]# <strong><span style="color: #ff0000;">vi /var/named/forward.house.cpb</span></strong></pre>
<p>On ajoute les machines suivantes et on augmente le numéro de série + 1 dans la Zone SOA</p>
<pre><span style="color: #ff0000;"><em>$TTL 86400</em></span>
<span style="color: #ff0000;"><em>@ IN SOA dns-pri.house.cpb. root.house.cpb. (</em></span>
<span style="color: #ff0000;"><strong><em>2021051905 ;Serial</em></strong></span>
<span style="color: #ff0000;"><em> 3600 ;Refresh</em></span>
<span style="color: #ff0000;"><em> 1800 ;Retry</em></span>
<span style="color: #ff0000;"><em> 604800 ;Expire</em></span>
<span style="color: #ff0000;"><em> 86400 ;Minimum TTL</em></span>
<span style="color: #ff0000;"><em>)</em></span>
<span style="color: #ff0000;"><em>@ IN NS dns-pri.house.cpb.</em></span>
<span style="color: #ff0000;"><em>@ IN NS dns-sec.house.cpb.</em></span>
<span style="color: #ff0000;"><em>@ IN A 172.16.185.1</em></span>
<span style="color: #ff0000;"><em>@ IN A 172.16.185.2</em></span>

<strong><span style="color: #ff0000;"><em>; Serveur LAN VM - Mysql PERCONA</em></span></strong>
<strong><span style="color: #ff0000;"><em>node01-sql IN A 172.16.185.9</em></span></strong>
<strong><span style="color: #ff0000;"><em>node02-sql IN A 172.16.185.10</em></span></strong>
<strong><span style="color: #ff0000;"><em>node03-sql IN A 172.16.185.11</em></span></strong>
<strong><span style="color: #ff0000;"><em>node04-sql IN A 172.16.185.12</em></span></strong>

<strong><span style="color: #ff0000;"><em>; Serveur LAN VM - Web Cluster</em></span></strong>
<strong><span style="color: #ff0000;"><em>;Cluster NGINX</em></span></strong>
<strong><span style="color: #ff0000;"><em>node01-web IN A 172.16.185.13</em></span></strong>
<strong><span style="color: #ff0000;"><em>node02-web IN A 172.16.185.14</em></span></strong>
<strong><span style="color: #ff0000;"><em>node03-web IN A 172.16.185.15</em></span></strong></pre>
<p><strong>Editer le fichier « forward.house.cpb »</strong></p>
<pre>[root@dns-pri chris]#<span style="color: #ff0000;"><strong> vi /var/named/reverse.house.cpb</strong></span></pre>
<p>On ajoute les nouvelles machines dans le fichier de reverse et on augmente le numéro de série + 1 dans la Zone SOA</p>
<pre><span style="color: #ff0000;"><em>$TTL 86400</em></span>
<span style="color: #ff0000;"><em>@ IN SOA dns-pri.house.cpb. root.house.cpb. (</em></span>
<strong><span style="color: #ff0000;"><em> 2021042106 ;Serial</em></span></strong>
<span style="color: #ff0000;"><em> 3600 ;Refresh</em></span>
<span style="color: #ff0000;"><em> 1800 ;Retry</em></span>
<span style="color: #ff0000;"><em> 604800 ;Expire</em></span>
<span style="color: #ff0000;"><em> 86400 ;Minimum TTL</em></span>
<span style="color: #ff0000;"><em>)</em></span>
<span style="color: #ff0000;"><em>@ IN NS dns-pri.house.cpb.</em></span>
<span style="color: #ff0000;"><em>@ IN NS dns-sec.house.cpb.</em></span>
<span style="color: #ff0000;"><em>@ IN MX 1 mail.house.cpb.</em></span>

<strong><span style="color: #ff0000;"><em>; LAN VM - Mysql PERCONA</em></span></strong>
<strong><span style="color: #ff0000;"><em>9 IN PTR node01-sql.house.cpb.</em></span></strong>
<strong><span style="color: #ff0000;"><em>10 IN PTR node02-sql.house.cpb.</em></span></strong>
<strong><span style="color: #ff0000;"><em>11 IN PTR node03-sql.house.cpb.</em></span></strong>
<strong><span style="color: #ff0000;"><em>12 IN PTR node04-sql.house.cpb.</em></span></strong>

<strong><span style="color: #ff0000;"><em>; LAN VM - WEB</em></span></strong>
<strong><span style="color: #ff0000;"><em>13 IN PTR node01-web.house.cpb.</em></span></strong>
<strong><span style="color: #ff0000;"><em>14 IN PTR node02-web.house.cpb.</em></span></strong>
<strong><span style="color: #ff0000;"><em>15 IN PTR node03-web.house.cpb.</em></span></strong></pre>
<p><strong>Test des Configurations (dns-pri.house.cpb)</strong></p>
<pre>[root@dns-pri named]# <span style="color: #ff0000;"><strong>named-checkzone house.cpb forward.house.cpb</strong></span>
<em>zone house.cpb/IN: loaded serial <span style="color: #ff0000;"><strong>2021051905</strong></span></em>
<strong><span style="color: #99cc00;"><em>OK</em></span></strong>
[root@dns-pri named]# named-checkzone house.cpb reverse.house.cpb
<em>zone house.cpb/IN: loaded serial <strong><span style="color: #ff0000;">2021042106</span></strong></em>
<strong><span style="color: #99cc00;"><em>OK</em></span></strong></pre>
<p><strong>Recharger la zone DNS Primaire et secondaire</strong></p>
<pre>[root@dns-pri named]# <span style="color: #ff0000;"><strong>systemctl reload named</strong></span></pre>
<p>Coté Logs DNS Primaire<br />
<img loading="lazy" decoding="async" width="1580" height="204" class="wp-image-1117" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-220.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-220.png 1580w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-220-300x39.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-220-1024x132.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-220-768x99.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-220-1536x198.png 1536w" sizes="auto, (max-width: 1580px) 100vw, 1580px" /></p>
<p>Côté logs DNS Secondaire<br />
<img loading="lazy" decoding="async" width="1526" height="290" class="wp-image-1120" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-221.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-221.png 1526w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-221-300x57.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-221-1024x195.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-221-768x146.png 768w" sizes="auto, (max-width: 1526px) 100vw, 1526px" /></p>
<p><strong><span style="color: #ff0000;">La propagation est OK.</span></strong></p>
<p><strong>Test sur un client Lambda.</strong></p>
<pre>[root@test1 ~]# <span style="color: #ff0000;"><strong>yum install bind-utils</strong></span>
[root@test1 ~]# <strong><span style="color: #ff0000;">nslookup node01-sql.house.cpb</span></strong>
[root@test1 ~]# <span style="color: #ff0000;"><strong>nslookup node02-sql.house.cpb</strong></span>
[root@test1 ~]# <span style="color: #ff0000;"><strong>nslookup node03-sql.house.cpb</strong></span>
[root@test1 ~]# <span style="color: #ff0000;"><strong>nslookup node04-sql.house.cpb</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1124" height="418" class="wp-image-1122" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-222.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-222.png 1124w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-222-300x112.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-222-1024x381.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-222-768x286.png 768w" sizes="auto, (max-width: 1124px) 100vw, 1124px" /></p>
<p>La résolution des noms machine est OK</p>
<p>Views: 34</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-configurer-un-dns-primaire-et-secondaire-centos7/">MODOP &#8211; Configurer un DNS Primaire et Secondaire &#8211; Centos7</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-configurer-un-dns-primaire-et-secondaire-centos7/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
