[DNS] reverse domain ʹʱ (long) ժҪ˵: 1. IP addr. ʹõλ 2.reverse DNS ϵͳʹʱ 3.DNS Caching ( positive & negative caching ) 4. SPAM (e-mail, usenet), һ߸е֪ϴʩ
--------------------------------------------------------------------------------
˶ DNS , ͨһ֪. ʹϵͳʵʸ, ϵͳ, ʱ, һЩǶǵĹ.
, ЩλĹ, ˵ǻ security Ŀ, Բ forward and/or reverse domain name database.
, һʹ, ϵͳԱ, ܶ˶˽ forward domain zone, Ҫ÷. , ˵.
reverse domain name database, ڹ, һֱûеõӦе. -- , ûг ftp.uu.net ȹվ̨, access deny ľ... , 7/1 , Ҳ˻лʶһ, վ̨ access deny ...
ⱳ˵ ============ Ŀǰ Internet, SPAM (email spam, usenet spam, ...) . ൱ձ Щط, ѾǶ.
Ը SPAM, cracker Ϊ, ʽܶ. , ÿվ, ϻ. , , λ, ϶Ƕ, ԻæΪǰ. ʵʵ case, Ϊбλʹǩ, ͨ, ת, ȽСĽ.
, ʱ, ·λ, ijһλ·, úò ļ, Ҫ:
1) õλ reverse DNS ϵͳ, ¼Ƿ. 2) "postmaster@your-domain-zone", "abuse@your-domain-zone" e-mail addr. work. 3) mail Ĺȥ, ûлӦ, ش.
ϵ¼, or contact person û. , e-mail response û, , ˻кõĹ۸ ?
, . ڵվ, TANet, HiNet, SeedNet, ... ȵ, վ ⷽ涼ûúܺ.
ǿ, ͨӦÿ, ı.
Ϊʲ, ͨԭ, . , һ, ˵. Ϊ(ɲǵԳʽԾ), Щ, Ūͨ, ʣµ, ͺð.
, Ϊһ DES , ͬ key Ļ, , ע, reverse DNS ·ʹ, ͳƱķ. -- һ, ʿ̹ѧԺľ, Ҳʾվ, ¼, ƺȱܶ.
--, ƾʲȥ APNIC ȡĿ IP address.
ʵ, ˵, reverse domain name ĵǼ, æܶ. * scecurity, * access control * load balancing 趨.
, security ȷ, Ϊ˵. ============================================
, SeedNet , ʼӦⷽĶ, Ѷ, Ǻһ. -- , , ط, ǰ. ( Ҳ, תֹ֢֮һ )
µһ, ˵һ, һ reverse DNS 趨趨, DNS ϵͳ, AP Ļ.
Maggie Liang (liang@mozart.seed.net.tw) ᵽ: : kftseng.bbs@bbs.ccu.edu.tw (ư) wrote: : > 븺 seednet dialup domain Ĺעһ. : : ɷ֪ʲأ : : >Jun 1 10:30:35 ccnews nnrpd[16950]: : > gethostbyaddr: s26-49.dialup.seed.net.tw != 139.175.26.49
ѶϢʾ. domain name һµ.
AP, ڷгʱ, ͻὫЩѶ¼. -- IP addr forward domain name.
ڵ AP,( sendmail, news, ftp, rlogin, tcp wrapper, ...), ʱ, Ŷ.
------------------------------------------------------------------- 1) յһ IP addr. A connection , reverse DNS ȥ ҳһӦ forward domain name B. Ҳ, ֹͣ. * , , ͿԾ, access deny, :-) !
2) ݲ 1) ҵ domain name B, ȥ forward DNS "", ȡ һ IP addr. C ( Ϊһ, or , multi-homed host, router ).
3) ȶ IP addr. A, Ƿ IP addr. C . -- , ϵͳ. ѶϢ.
ʱ, Ҳ database . һֿ, .
ʱ, һλڵ forward & reverse domain zone, DNS , ά, ͬλ, ʱ, ҵС, Ҳ. -------------------------------------------------------------------
: ======== , ǿܻ.
Q1: ϵͳΪʲҪ鷳 ? 1). , Ϳ.
A: 2) 3), һΪ security ϵĿ. ҪЩ, һЩλ, , ȻһЪ߰ѶϢ, ָ. ݺ.
һЩ, access control. load balance . :
139.75.26.49, 192.72.90.129 Ŀǰ SeedNet IP. Ƚ *.seed.net.tw, һֱȽױ. ֻҪΪһ, Ͳ.
·ϵ traffic. IP addr. Ѷͨ, Ŀĵ, reverse DNS , û¼, Է AP access control, performance tuning ʱ, ÷dz. , λDz class C, IP address. ڷֱʱ. -----------------------------------------------------------------------
Q2: reverse DNS, ֻ forward domain name, DZȽʡ. traffic , 2), 3) ?
A: 鲻.
õ DNS server NS1, 1 , ʽ, query ijһ domain zone entry ʱ, ( forward & reverse domain ), ʱ, NS1 answer (data), NS1 , ϵ, root ϲijһ DNS server (e.g. NS2) , һ·, ҵ? domain zone ijһ DNS server (e.g NS3). Ȼ, NS1 query NS3, NS3 Լ database ( memory , ״̬ ), , ͽ answer, NS1. , NS1 ͽ answer, . ( µ NS3 ָ, ij domain zone DNS server ֮һ)
Ϊ caching, (ʽ), NS1 ͿϽ𰸻ظ.
, NS3 NS1, û query ĶӦ¼. NS1, ?
NS1 , ڵ BIND ( 4.9.5 or ), ʵͬ һ entry, ֻ NS3 (or ͬ DNS server) һ. ( һ, Ϊ caching, ֱ֪ NS3 or equivalent ), Ǻ ܻûд.
, NS1 --> NS3, NS3 --> NS1 Ĺ, ϵ.
Ƚ° BIND 8.1 ( 4.9.5-P1, ⲿݵĹܻǺ). , negative caching Ķ. Ҳ, NS3 NS1, ij һ query, ûжӦ DNS data entry ʱ, NS1 Ὣ, . 10 ( 600 sec), гʽ. NS1 ͬ query, Ͼ , , .
600 ȥ, гʽ, ͬ query ʱ, ʱ, NS1 ȥ NS3. , . ( ʱ, Ϳ˽, IJ )
һ, NS3 , ijϼʱ, ( e.g ǰڵ entry), &n[1] [2] һҳ
|
|