็†ฑ้–€ๅˆ†้กž
 ่ผ‰ๅ…ฅไธญ…
็›ฎ้Œ„

๐Ÿงฉ Windows DNS Server ๅฎŒๆ•ดๆžถ่จญๆŒ‡ๅ—:ๆญฃๅ‘/ๅๅ‘ๅ€ๅŸŸ、่จ˜้Œ„็ฎก็†ๅˆฐ PowerShell ๅ…จ่‡ชๅ‹•้ƒจ็ฝฒ

    ๐Ÿงฉ Windows DNS Server ๅฎŒๆ•ดๆžถ่จญๆŒ‡ๅ—:ๆญฃๅ‘/ๅๅ‘ๅ€ๅŸŸ、่จ˜้Œ„็ฎก็†ๅˆฐ PowerShell ๅ…จ่‡ชๅ‹•้ƒจ็ฝฒ

    DNS ๆ˜ฏ็ถฒ่ทฏๆ ธๅฟƒๆœๅ‹™ไน‹ไธ€,่ฒ ่ฒฌๅฐ‡ไบบ้กžๅฏ่ฎ€็š„็ถฒๅŸŸๅ็จฑ(ๅฆ‚ wwfandy.local)่ฝ‰ๆ›ๆˆ IP ไฝๅ€。 Windows Server ๅ…งๅปบ DNS Server ๅŠŸ่ƒฝ,ๅฏๆญ้… Active Directory ่‡ชๅ‹•่ค‡ๅฏซ、ๆ”ฏๆดๅ‹•ๆ…‹ๆ›ดๆ–ฐ、่ฝ‰็™ผๅ™จ(Forwarder)、ๅๅ‘ๆŸฅ่ฉข็ญ‰ๅฎŒๆ•ดไผๆฅญ้œ€ๆฑ‚。 ไปฅไธ‹ๆไพ› GUI + PowerShell ็š„ๅฎŒๆ•ดๅปบ็ฝฎๆต็จ‹,ๅŒ…ๅซๆญฃๅ‘ๅ€ๅŸŸ、ๅๅ‘ๅ€ๅŸŸ่ˆ‡่จ˜้Œ„็ฎก็†。

    ไธ€、ๅฎ‰่ฃ DNS ไผบๆœๅ™จ(GUI)

    1. ้–‹ๅ•Ÿ Server Manager
    2. Add Roles and Features
    3. ้ธๆ“‡「DNS Server」
    4. ๅฎŒๆˆๅฎ‰่ฃๅพŒ,ไผบๆœๅ™จไธŠๆœƒๅ‡บ็พ「DNS Manager」ๅทฅๅ…ท

    ไบŒ、ไฝฟ็”จ PowerShell ๅฎ‰่ฃ DNS Server(ๆŽจ่–ฆ)

    # ๅฎ‰่ฃ DNS Server ่ง’่‰ฒ
    Install-WindowsFeature DNS -IncludeManagementTools
    
    # ็ขบ่ช DNS ๅŠŸ่ƒฝ
    Get-WindowsFeature DNS
    

    ไธ‰、ๅปบ็ซ‹ๆญฃๅ‘ๆŸฅ่ฉขๅ€(Forward Lookup Zone)

    GUI ๅปบ็ซ‹ๆญฅ้ฉŸ

    1. ้–‹ๅ•Ÿ dnsmgmt.msc
    2. ๅณ้ต Forward Lookup Zones → New Zone
    3. ้กžๅž‹้ธๆ“‡:
      • Primary Zone(่‹ฅ้ž AD Domain Controller)
      • Active Directory Integrated(ๅปบ่ญฐๅœจ AD ็’ฐๅขƒไฝฟ็”จ)
    4. ่ผธๅ…ฅ็ถฒๅŸŸๅ็จฑ:ไพ‹ๅฆ‚ wwfandy.local
    5. ๅฎŒๆˆๅปบ็ซ‹

    PowerShell ๅปบ็ซ‹ Primary Zone

    Add-DnsServerPrimaryZone `
        -Name "wwfandy.local" `
        -ZoneFile "wwfandy.local.dns"
    

    PowerShell ๅปบ็ซ‹ AD ๆ•ดๅˆๅ€ๅŸŸ

    Add-DnsServerPrimaryZone `
        -Name "wwfandy.local" `
        -ReplicationScope "Domain"
    

    ๅ››、ๅปบ็ซ‹ๅๅ‘ๆŸฅ่ฉขๅ€(Reverse Lookup Zone)

    ๅๅ‘ๆŸฅ่ฉขๅ€็š„ๅ‘ฝๅๆ ผๅผไพ IP ่€Œๅฎš,ไพ‹ๅฆ‚:

    • 10.0.10.x → 10.0.10.in-addr.arpa

    PowerShell ๅปบ็ซ‹ๅๅ‘ๅ€ๅŸŸ

    Add-DnsServerPrimaryZone `
        -NetworkId "10.0.10.0/24" `
        -ReplicationScope "Domain"
    

    ไบ”、ๅปบ็ซ‹ DNS ่จ˜้Œ„(A / CNAME / PTR ็ญ‰)

    1. A ่จ˜้Œ„(ๆœ€ๅธธ็”จ)

    Add-DnsServerResourceRecordA `
        -Name "server01" `
        -ZoneName "wwfandy.local" `
        -IPv4Address "10.0.10.20"
    

    2. PTR ่จ˜้Œ„(ๅๅ‘ๅฐๆ‡‰)

    ่‹ฅๅๅ‘ๅ€ๅŸŸๅญ˜ๅœจ,ๅปบ็ซ‹ A ่จ˜้Œ„ๆ™‚ๅฏ่‡ชๅ‹•็”ข PTR;ไนŸๅฏๆ‰‹ๅ‹•ๆ–ฐๅขž:

    Add-DnsServerResourceRecordPtr `
        -Name "20" `
        -ZoneName "10.0.10.in-addr.arpa" `
        -PtrDomainName "server01.wwfandy.local"
    

    3. CNAME(ๅˆฅๅ่จ˜้Œ„)

    Add-DnsServerResourceRecordCName `
        -Name "web" `
        -HostNameAlias "server01.wwfandy.local" `
        -ZoneName "wwfandy.local"
    

    ๅ…ญ、่จญๅฎš Forwarder(่ฝ‰็™ผๅ™จ)

    Forwarder ๅฏ่ฎ“ DNS Server ๅฐ‡ๅค–้ƒจๆŸฅ่ฉข่ฝ‰็ตฆไธŠๆธธ DNS,ไพ‹ๅฆ‚:Google DNS(8.8.8.8)。

    PowerShell ่จญๅฎš่ฝ‰็™ผๅ™จ

    Add-DnsServerForwarder -IPAddress "8.8.8.8"
    Add-DnsServerForwarder -IPAddress "1.1.1.1"
    

    ไธƒ、ๅ…่จฑๆˆ–็ฆๆญขๅ‹•ๆ…‹ๆ›ดๆ–ฐ(Dynamic Update)

    AD ็’ฐๅขƒ้€šๅธธๅปบ่ญฐๅ•Ÿ็”จ「Secure Only」。

    Set-DnsServerPrimaryZone `
        -Name "wwfandy.local" `
        -DynamicUpdate Secure
    

    ๅ…ซ、ๆชขๆŸฅ DNS ไผบๆœๅ™จ็‹€ๆ…‹่ˆ‡ๆŸฅ่ฉขๆธฌ่ฉฆ

    ๆชขๆŸฅ DNS ๅ€ๅŸŸ

    Get-DnsServerZone
    

    ๆŸฅ่ฉข A ่จ˜้Œ„

    Resolve-DnsName server01.wwfandy.local
    

    ๆŸฅ่ฉขๅๅ‘่งฃๆž

    Resolve-DnsName 10.0.10.20
    

    ไน、DNS ๆ•…้šœๆŽ’ๆŸฅ่ˆ‡ๅธธ่ฆ‹ๅ•้กŒ

    1. ้˜ฒ็ซ็‰†ๆ˜ฏๅฆๅ…่จฑ 53 Port?

    New-NetFirewallRule -DisplayName "DNS TCP" -Direction Inbound -Protocol TCP -LocalPort 53 -Action Allow
    New-NetFirewallRule -DisplayName "DNS UDP" -Direction Inbound -Protocol UDP -LocalPort 53 -Action Allow
    

    2. ็”จๆˆถ็ซฏๆธ…้™ค DNS Cache

    ipconfig /flushdns
    

    3. ๆ›ดๆ–ฐ DNS ่จญๅฎš

    ipconfig /registerdns
    

    ๅ、PowerShell ่‡ชๅ‹•ๅŒ–้ƒจ็ฝฒ็ฏ„ไพ‹(ๅฏๅฎŒๆ•ดไธ€้ตๅฎ‰่ฃ)

    # ไธ€้ตๅปบ็ซ‹ DNS ไผบๆœๅ™จ่ˆ‡ๅ€ๅŸŸ
    
    Install-WindowsFeature DNS -IncludeManagementTools
    
    Add-DnsServerPrimaryZone -Name "wwfandy.local" -ReplicationScope "Domain"
    Add-DnsServerPrimaryZone -NetworkId "10.0.10.0/24" -ReplicationScope "Domain"
    
    Add-DnsServerForwarder -IPAddress "8.8.8.8"
    Add-DnsServerForwarder -IPAddress "1.1.1.1"
    
    # ๅปบ็ซ‹ๅธธ็”จ DNS ่จ˜้Œ„
    Add-DnsServerResourceRecordA -Name "server01" -ZoneName "wwfandy.local" -IPv4Address "10.0.10.20"
    Add-DnsServerResourceRecordCName -Name "web" -ZoneName "wwfandy.local" -HostNameAlias "server01.wwfandy.local"
    

    ๐Ÿ“˜ ็ต่ชž

    Windows DNS Server ๅœจไผๆฅญ็’ฐๅขƒไธญๆ‰ฎๆผ”้—œ้ต่ง’่‰ฒ,็‰นๅˆฅๆ˜ฏๆญ้… Active Directory ๆ™‚,ๆ›ดๆ˜ฏๆ‰€ๆœ‰้›ป่…ฆ็™ปๅ…ฅ、ๆฌŠๆ–、ๆœๅ‹™ๅฎšไฝ็š„ๆ ธๅฟƒ。 ้€้Žๆญฃๅ‘、ๅๅ‘ๅ€ๅŸŸ็š„ๅปบ็ซ‹่ˆ‡ PowerShell ่‡ชๅ‹•ๅŒ–,ๅฏไปฅๅฟซ้€Ÿ้ƒจ็ฝฒไธ€่‡ดไธ”ๅฏ้ ็š„ DNS ๆžถๆง‹。 ๆœฌๆ–‡ๆไพ›ๅฎŒๆ•ดๆต็จ‹,ๅฏไฝœ็‚บไฝ ็š„ไผๆฅญๆจ™ๆบ–ๅŒ–้ƒจ็ฝฒๆจกๆฟ。


    ๐Ÿ”— ๅปถไผธ้–ฑ่ฎ€

    — WWFandy・Windows Server ้ƒจ็ฝฒ็ญ†่จ˜

    ๐Ÿ”— ๅˆ†ไบซ้€™็ฏ‡ LINE Facebook X

    ๆฒ’ๆœ‰็•™่จ€:

    ๅผต่ฒผ็•™่จ€

    ๅญ—็ดš