๐งฉ Windows DNS Server ๅฎๆดๆถ่จญๆๅ:ๆญฃๅ/ๅๅๅๅ、่จ้็ฎก็ๅฐ PowerShell ๅ จ่ชๅ้จ็ฝฒ
DNS ๆฏ็ถฒ่ทฏๆ ธๅฟๆๅไนไธ,่ฒ ่ฒฌๅฐไบบ้กๅฏ่ฎ็็ถฒๅๅ็จฑ(ๅฆ wwfandy.local)่ฝๆๆ IP ไฝๅ。 Windows Server ๅ งๅปบ DNS Server ๅ่ฝ,ๅฏๆญ้ Active Directory ่ชๅ่คๅฏซ、ๆฏๆดๅๆ ๆดๆฐ、่ฝ็ผๅจ(Forwarder)、ๅๅๆฅ่ฉข็ญๅฎๆดไผๆฅญ้ๆฑ。 ไปฅไธๆไพ GUI + PowerShell ็ๅฎๆดๅปบ็ฝฎๆต็จ,ๅ ๅซๆญฃๅๅๅ、ๅๅๅๅ่่จ้็ฎก็。
ไธ、ๅฎ่ฃ DNS ไผบๆๅจ(GUI)
- ้ๅ Server Manager
- Add Roles and Features
- ้ธๆ「DNS Server」
- ๅฎๆๅฎ่ฃๅพ,ไผบๆๅจไธๆๅบ็พ「DNS Manager」ๅทฅๅ ท
ไบ、ไฝฟ็จ PowerShell ๅฎ่ฃ DNS Server(ๆจ่ฆ)
# ๅฎ่ฃ DNS Server ่ง่ฒ
Install-WindowsFeature DNS -IncludeManagementTools
# ็ขบ่ช DNS ๅ่ฝ
Get-WindowsFeature DNS
ไธ、ๅปบ็ซๆญฃๅๆฅ่ฉขๅ(Forward Lookup Zone)
GUI ๅปบ็ซๆญฅ้ฉ
- ้ๅ dnsmgmt.msc
- ๅณ้ต Forward Lookup Zones → New Zone
- ้กๅ้ธๆ:
- Primary Zone(่ฅ้ AD Domain Controller)
- Active Directory Integrated(ๅปบ่ญฐๅจ AD ็ฐๅขไฝฟ็จ)
- ่ผธๅ
ฅ็ถฒๅๅ็จฑ:ไพๅฆ
wwfandy.local - ๅฎๆๅปบ็ซ
PowerShell ๅปบ็ซ Primary Zone
Add-DnsServerPrimaryZone `
-Name "wwfandy.local" `
-ZoneFile "wwfandy.local.dns"
PowerShell ๅปบ็ซ AD ๆดๅๅๅ
Add-DnsServerPrimaryZone `
-Name "wwfandy.local" `
-ReplicationScope "Domain"
ๅ、ๅปบ็ซๅๅๆฅ่ฉขๅ(Reverse Lookup Zone)
ๅๅๆฅ่ฉขๅ็ๅฝๅๆ ผๅผไพ IP ่ๅฎ,ไพๅฆ:
- 10.0.10.x →
10.0.10.in-addr.arpa
PowerShell ๅปบ็ซๅๅๅๅ
Add-DnsServerPrimaryZone `
-NetworkId "10.0.10.0/24" `
-ReplicationScope "Domain"
ไบ、ๅปบ็ซ DNS ่จ้(A / CNAME / PTR ็ญ)
1. A ่จ้(ๆๅธธ็จ)
Add-DnsServerResourceRecordA `
-Name "server01" `
-ZoneName "wwfandy.local" `
-IPv4Address "10.0.10.20"
2. PTR ่จ้(ๅๅๅฐๆ)
่ฅๅๅๅๅๅญๅจ,ๅปบ็ซ A ่จ้ๆๅฏ่ชๅ็ข PTR;ไนๅฏๆๅๆฐๅข:
Add-DnsServerResourceRecordPtr `
-Name "20" `
-ZoneName "10.0.10.in-addr.arpa" `
-PtrDomainName "server01.wwfandy.local"
3. CNAME(ๅฅๅ่จ้)
Add-DnsServerResourceRecordCName `
-Name "web" `
-HostNameAlias "server01.wwfandy.local" `
-ZoneName "wwfandy.local"
ๅ ญ、่จญๅฎ Forwarder(่ฝ็ผๅจ)
Forwarder ๅฏ่ฎ DNS Server ๅฐๅค้จๆฅ่ฉข่ฝ็ตฆไธๆธธ DNS,ไพๅฆ:Google DNS(8.8.8.8)。
PowerShell ่จญๅฎ่ฝ็ผๅจ
Add-DnsServerForwarder -IPAddress "8.8.8.8"
Add-DnsServerForwarder -IPAddress "1.1.1.1"
ไธ、ๅ ่จฑๆ็ฆๆญขๅๆ ๆดๆฐ(Dynamic Update)
AD ็ฐๅข้ๅธธๅปบ่ญฐๅ็จ「Secure Only」。
Set-DnsServerPrimaryZone `
-Name "wwfandy.local" `
-DynamicUpdate Secure
ๅ ซ、ๆชขๆฅ DNS ไผบๆๅจ็ๆ ่ๆฅ่ฉขๆธฌ่ฉฆ
ๆชขๆฅ DNS ๅๅ
Get-DnsServerZone
ๆฅ่ฉข A ่จ้
Resolve-DnsName server01.wwfandy.local
ๆฅ่ฉขๅๅ่งฃๆ
Resolve-DnsName 10.0.10.20
ไน、DNS ๆ ้ๆๆฅ่ๅธธ่ฆๅ้ก
1. ้ฒ็ซ็ๆฏๅฆๅ ่จฑ 53 Port?
New-NetFirewallRule -DisplayName "DNS TCP" -Direction Inbound -Protocol TCP -LocalPort 53 -Action Allow
New-NetFirewallRule -DisplayName "DNS UDP" -Direction Inbound -Protocol UDP -LocalPort 53 -Action Allow
2. ็จๆถ็ซฏๆธ ้ค DNS Cache
ipconfig /flushdns
3. ๆดๆฐ DNS ่จญๅฎ
ipconfig /registerdns
ๅ、PowerShell ่ชๅๅ้จ็ฝฒ็ฏไพ(ๅฏๅฎๆดไธ้ตๅฎ่ฃ)
# ไธ้ตๅปบ็ซ DNS ไผบๆๅจ่ๅๅ
Install-WindowsFeature DNS -IncludeManagementTools
Add-DnsServerPrimaryZone -Name "wwfandy.local" -ReplicationScope "Domain"
Add-DnsServerPrimaryZone -NetworkId "10.0.10.0/24" -ReplicationScope "Domain"
Add-DnsServerForwarder -IPAddress "8.8.8.8"
Add-DnsServerForwarder -IPAddress "1.1.1.1"
# ๅปบ็ซๅธธ็จ DNS ่จ้
Add-DnsServerResourceRecordA -Name "server01" -ZoneName "wwfandy.local" -IPv4Address "10.0.10.20"
Add-DnsServerResourceRecordCName -Name "web" -ZoneName "wwfandy.local" -HostNameAlias "server01.wwfandy.local"
๐ ็ต่ช
Windows DNS Server ๅจไผๆฅญ็ฐๅขไธญๆฎๆผ้้ต่ง่ฒ,็นๅฅๆฏๆญ้ Active Directory ๆ,ๆดๆฏๆๆ้ป่ ฆ็ปๅ ฅ、ๆฌๆ、ๆๅๅฎไฝ็ๆ ธๅฟ。 ้้ๆญฃๅ、ๅๅๅๅ็ๅปบ็ซ่ PowerShell ่ชๅๅ,ๅฏไปฅๅฟซ้้จ็ฝฒไธ่ดไธๅฏ้ ็ DNS ๆถๆง。 ๆฌๆๆไพๅฎๆดๆต็จ,ๅฏไฝ็บไฝ ็ไผๆฅญๆจๆบๅ้จ็ฝฒๆจกๆฟ。
๐ ๅปถไผธ้ฑ่ฎ
- Windows Update ๆทฑๅบฆ่งฃๆ:USOClient、WaaS、WSUS ่ก็บๅทฎ็ฐ
- WSUS Client ๅผทๅถๅๅ ฑ(SYSTEM + COM + PsExec)
- Windows PE ๅฎๆดๆๅ(ๆถๆง็ฏ)
— WWFandy・Windows Server ้จ็ฝฒ็ญ่จ
ๆฒๆ็่จ:
ๅผต่ฒผ็่จ