Skip to content

Instantly share code, notes, and snippets.

@voodoonofx
Last active January 27, 2020 11:09
Show Gist options
  • Save voodoonofx/92db83a489127e56de2013348790abf4 to your computer and use it in GitHub Desktop.
Save voodoonofx/92db83a489127e56de2013348790abf4 to your computer and use it in GitHub Desktop.
Named Config - voodoonofx.io
; /etc/named.conf
options {
listen-on port 53 { 173.82.207.201; };
listen-on-v6 port 53 { ::1; };
directory "/var/named";
dump-file "/var/named/data/cache_dump.db";
statistics-file "/var/named/data/named_stats.txt";
memstatistics-file "/var/named/data/named_mem_stats.txt";
recursing-file "/var/named/data/named.recursing";
secroots-file "/var/named/data/named.secroots";
allow-query { any; };
/*
- If you are building an AUTHORITATIVE DNS server, do NOT enable recursion.
- If you are building a RECURSIVE (caching) DNS server, you need to enable
recursion.
- If your recursive DNS server has a public IP address, you MUST enable access
control to limit queries to your legitimate users. Failing to do so will
cause your server to become part of large scale DNS amplification
attacks. Implementing BCP38 within your network would greatly
reduce such attack surface
*/
recursion no;
dnssec-enable yes;
dnssec-validation yes;
/* Path to ISC DLV key */
bindkeys-file "/etc/named.root.key";
managed-keys-directory "/var/named/dynamic";
pid-file "/run/named/named.pid";
session-keyfile "/run/named/session.key";
};
logging {
channel default_debug {
file "data/named.run";
severity dynamic;
};
};
zone "." IN {
type hint;
file "named.ca";
};
zone "voodoonofx.io" IN {
type master;
file "voodoonofx.io.zone";
allow-update { none; };
};
include "/etc/named.rfc1912.zones";
include "/etc/named.root.key";
$TTL 1h
@ IN SOA ns1.voodoonofx.io. root.voodoonofx.io. (
2020012611 ; Serial
1D ; Refresh
1D ; Retry
4W ; Expire
1H ) ; Cache
; main domain name servers.
NS ns1
NS ns2
; main domain email servers.
MX 10 mail.voodoonofx.io.
; A records for name servers above.
ns1 A 173.82.207.201
ns2 A 198.211.41.204
mail A 104.194.253.201
nx A 173.82.239.154
www A 104.82.239.213
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment