You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

BIND9独立主服务器无法在SRV查询结果中返回附加A记录的问题求助

BIND9独立主服务器无法在SRV查询结果中返回附加A记录的问题求助

各位大佬好,我现在碰到一个BIND9服务器的棘手问题:查询SRV记录时,服务器能正确返回SRV条目,但就是不会把对应的主机A记录放到附加区域里。用Windows DNS服务器查询是完全正常的,但换成我的Ubuntu BIND9就不行了,麻烦帮忙看看哪里出问题了?

测试对比情况

Windows nslookup测试结果

先放正常的Windows DNS服务器查询结果:

set type=srv
_sip._udp.subdomain.example.com
Server: servername.activedir.example.com
Address: 10.1.2.8

_sip._udp.subdomain.example.com SRV service location:
priority = 0
weight = 0
port = 5060
svr srvname = srv1.example.com

_sip._udp.subdomain.example.com SRV service location:
priority = 1
weight = 0
port = 5060
svr srvname = srv2.example.com

srv1.example.com internet address = 192.168.1.100
srv2.example.com internet address = 192.168.2.100

再看我的BIND9服务器的nslookup结果:

server 10.1.2.17
Default Server: [10.1.2.17]
Address: 10.1.2.17

_sip._udp.subdomain.example.com
Server: [10.1.2.17]
Address: 10.1.2.17

_sip._udp.subdomain.example.com SRV service location:
priority = 0
weight = 0
port = 5060
svr srvname = srv1.example.com

_sip._udp.subdomain.example.com SRV service location:
priority = 1
weight = 0
port = 5060
svr srvname = srv2.example.com

很明显,BIND9这里完全没返回后面的A记录。

Dig命令测试结果

正常的Windows DNS服务器查询:

named$ dig @10.1.2.8 _sip._udp.subdomain.example.com SRV

; <<>> DiG 9.16.1-Ubuntu <<>> @10.1.2.8 _sip._udp.subdomain.example.com SRV
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 38735
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 3

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4000

;; QUESTION SECTION:
;_sip._udp.subdomain.example.com.     IN      SRV

;; ANSWER SECTION:
_sip._udp.subdomain.example.com. 3600 IN      SRV     1 0 5060 srv2.example.com.
_sip._udp.subdomain.example.com. 3600 IN      SRV     0 0 5060 srv1.example.com.

;; ADDITIONAL SECTION:
srv2.example.com.          3600    IN      A       192.168.57.120
srv1.example.com.          3600    IN      A       192.168.58.100

;; Query time: 0 msec
;; SERVER: 10.1.2.8#53(10.1.2.8)
;; WHEN: Wed Mar 08 17:11:17 MST 2023
;; MSG SIZE  rcvd: 152

这里的ADDITIONAL区域正常返回了两个对应的A记录。

我的BIND9服务器查询:

named$ dig @10.1.2.17 _sip._udp.subdomain.example.com SRV

; <<>> DiG 9.16.1-Ubuntu <<>> @10.1.2.17 _sip._udp.subdomain.example.com SRV
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 62383
;; flags: qr aa rd; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: 8b63436638b439ca0100000064092431bd2f2b3cd32542b5 (good)

;; QUESTION SECTION:
;_sip._udp.subdomain.example.com.     IN      SRV

;; ANSWER SECTION:
_sip._udp.subdomain.example.com. 300  IN      SRV     1 0 5060 srv2.example.com.
_sip._udp.subdomain.example.com. 300  IN      SRV     0 0 5060 srv1.example.com.

;; Query time: 0 msec
;; SERVER: 10.1.2.17#53(10.1.2.17)
;; WHEN: Wed Mar 08 17:11:29 MST 2023
;; MSG SIZE  rcvd: 148

这里的ADDITIONAL区域只有EDNS相关内容,完全没有期望的A记录。

另外单独查询主机A记录是正常的,比如:

; <<>> DiG 9.16.1-Ubuntu <<>> @10.1.2.17 srv1.example.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 22271
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: c68aa2c1d84416b8010000006409ffbaee89c08cb05f8de4 (good)

;; QUESTION SECTION:
;srv1.example.com.                 IN      A

;; ANSWER SECTION:
srv1.example.com.          300     IN      A       192.168.58.100

;; Query time: 0 msec
;; SERVER: 10.1.2.17#53(10.1.2.17)
;; WHEN: Thu Mar 09 08:48:10 MST 2023
;; MSG SIZE  rcvd: 86

我的BIND配置文件

下面是所有相关的配置文件内容,麻烦帮忙排查:

named.conf

include "/etc/bind/named.conf.options";
include "/etc/bind/named.conf.local";
include "/etc/bind/named.conf.log";

// include "/etc/bind/named.conf.default-zones"

named.conf.local

//
zone "subdomain.example.com" {
type master;
file "/etc/bind/zones/db.subdomain.example.com"; # zone file path
allow-transfer {"none";};
};

zone "example.com" {
type master;
file "/etc/bind/zones/db.example.com"; # zone file path
allow-transfer {"none";};
};

zone "1.10.in-addr.arpa" {
type primary;
file "/etc/bind/zones/db.10.1";  # 10.1.2.0/24 subnet
};

zone "168.192.in-addr.arpa" {
type primary;
file "/etc/bind/zones/db.192.168";  # 192.168.57 and 192.168.58 subnets
};

named.conf.options

options {
directory "/var/cache/bind";

recursion no;                 # enables recursive queries
// allow-recursion { any; };      # allows recursive queries from "trusted" clients

listen-on { any; };
allow-transfer { none; };      # disable zone transfers by default

dnssec-validation no;

allow-query { any; };
allow-query-cache { none; };

listen-on-v6 { none; };

// If there is a firewall between you and nameservers you want  // to talk to, you may need to fix the firewall to allow multiple
// ports to talk.  See http://www.kb.cert.org/vuls/id/800113

// If your ISP provided one or more IP addresses for stable
// nameservers, you probably want to use them as forwarders.
// Uncomment the following block, and insert the addresses replacing
// the all-0's placeholder.

// forwarders {
//      0.0.0.0;
// };

//========================================================================
// If BIND logs error messages about the root key being expired,
// you will need to update your keys.  See https://www.isc.org/bind-keys
//========================================================================
};

db.subdomain.example.com

; BIND data file for local IPv4 interface 10.1.2.17
;
$TTL    300
$ORIGIN subdomain.example.com.

@       IN      SOA     fqdn-dns1.subdomain.example.com. postmaster.subdomain.example.com. (
23030802         ; Serial
300         ; Refresh
300         ; Retry
300         ; Expire
300 )       ; Negative Cache TTL
;
; name server RR for the domain
subdomain.example.com.       IN      NS      fqdn-dns1.subdomain.example.com.

; the server where everything will run
fqdn-dns1 IN  A   10.1.2.17

; server1            IN     AAAA   2001:DB8:1000:2000::19 //IPv6 disabled//
;
; Use different names for each service.
; Don't use CNAMEs, the SRV records (further down)
; can't point to CNAME records.
;
;  DNS SRV and NAPTR records for SIP
;
@ 300 IN NAPTR  0 0 "S" "SIP+D2U" "" _sip._udp.subdomain.example.com.
;
_sip._udp.subdomain.example.com. IN SRV    0 0 5060 srv1.example.com.
_sip._udp.subdomain.example.com. IN SRV    1 0 5060 srv2.example.com.

db.example.com

; BIND data file for local IPv4 interface 10.1.2.26
;
$TTL    300
$ORIGIN example.com.

@       IN      SOA     fqdn-dns1. admin.example.com. (
23030803         ; Serial
300         ; Refresh
300         ; Retry
300         ; Expire
300 )       ; Negative Cache TTL
;
; name server RR for the domain
@                    IN NS  fqdn-dns1.example.com.

; the server where everything will run
fqdn-dns1.example.com. IN A   10.1.2.17
srv1.example.com.       IN A   192.168.58.100
srv2.example.com.       IN A   192.168.57.120

db.10.1(反向区域)

;
; BIND reverse data file for local loopback interface
;
$TTL    300
@       IN      SOA     fqdn-dns1.example.com. root.example.com. (
23030804         ; Serial
300         ; Refresh
300         ; Retry
300         ; Expire
300 )       ; Negative Cache TTL

; NS record for DNS server IPv4
@       IN      NS      fqdn-dns1.example.com.

; PTR Record for reverse to NS
17.2    IN      PTR     fqdn-dns1.example.com.    ; 10.1.2.17
17.2    IN      PTR     fqdn-dns1.subdomain.example.com  ; 10.1.2.17

db.192.168(反向区域)

;
; BIND reverse data file for 192.168. subnet
;
$TTL    300
@       IN      SOA     fqdn-dns1.example.com. root.example.com. (
4         ; Serial
300         ; Refresh
300         ; Retry
300         ; Expire
300 )       ; Negative Cache TTL
;
; NS record for DNS server IPv4
IN      NS      fqdn-dns1.example.com.

; PTR Record for reverse to Site Fabric Metaswitch subnets
120.57  IN      PTR     srv2.example.com.  ; 192.168.57.120
100.58  IN      PTR     srv1.example.com.  ; 192.168.58.100

现在我已经确认正向和反向区域都加载正常,单独查A记录没问题,但SRV查询就是不返回附加A记录,实在找不到原因了,求各位指点!

备注:内容来源于stack exchange,提问作者nube101

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 09:47:33