BIND9独立主服务器无法在SRV查询结果中返回附加A记录的问题求助
各位大佬好,我现在碰到一个BIND9服务器的棘手问题:查询SRV记录时,服务器能正确返回SRV条目,但就是不会把对应的主机A记录放到附加区域里。用Windows DNS服务器查询是完全正常的,但换成我的Ubuntu BIND9就不行了,麻烦帮忙看看哪里出问题了?
测试对比情况
Windows nslookup测试结果
先放正常的Windows DNS服务器查询结果:
set type=srv
_sip._udp.subdomain.example.com
Server: servername.activedir.example.com
Address: 10.1.2.8
_sip._udp.subdomain.example.com SRV service location:
priority = 0
weight = 0
port = 5060
svr srvname = srv1.example.com
_sip._udp.subdomain.example.com SRV service location:
priority = 1
weight = 0
port = 5060
svr srvname = srv2.example.com
srv1.example.com internet address = 192.168.1.100
srv2.example.com internet address = 192.168.2.100
再看我的BIND9服务器的nslookup结果:
server 10.1.2.17
Default Server: [10.1.2.17]
Address: 10.1.2.17
_sip._udp.subdomain.example.com
Server: [10.1.2.17]
Address: 10.1.2.17
_sip._udp.subdomain.example.com SRV service location:
priority = 0
weight = 0
port = 5060
svr srvname = srv1.example.com
_sip._udp.subdomain.example.com SRV service location:
priority = 1
weight = 0
port = 5060
svr srvname = srv2.example.com
很明显,BIND9这里完全没返回后面的A记录。
Dig命令测试结果
正常的Windows DNS服务器查询:
named$ dig @10.1.2.8 _sip._udp.subdomain.example.com SRV ; <<>> DiG 9.16.1-Ubuntu <<>> @10.1.2.8 _sip._udp.subdomain.example.com SRV ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 38735 ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 3 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4000 ;; QUESTION SECTION: ;_sip._udp.subdomain.example.com. IN SRV ;; ANSWER SECTION: _sip._udp.subdomain.example.com. 3600 IN SRV 1 0 5060 srv2.example.com. _sip._udp.subdomain.example.com. 3600 IN SRV 0 0 5060 srv1.example.com. ;; ADDITIONAL SECTION: srv2.example.com. 3600 IN A 192.168.57.120 srv1.example.com. 3600 IN A 192.168.58.100 ;; Query time: 0 msec ;; SERVER: 10.1.2.8#53(10.1.2.8) ;; WHEN: Wed Mar 08 17:11:17 MST 2023 ;; MSG SIZE rcvd: 152
这里的ADDITIONAL区域正常返回了两个对应的A记录。
我的BIND9服务器查询:
named$ dig @10.1.2.17 _sip._udp.subdomain.example.com SRV ; <<>> DiG 9.16.1-Ubuntu <<>> @10.1.2.17 _sip._udp.subdomain.example.com SRV ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 62383 ;; flags: qr aa rd; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; WARNING: recursion requested but not available ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ; COOKIE: 8b63436638b439ca0100000064092431bd2f2b3cd32542b5 (good) ;; QUESTION SECTION: ;_sip._udp.subdomain.example.com. IN SRV ;; ANSWER SECTION: _sip._udp.subdomain.example.com. 300 IN SRV 1 0 5060 srv2.example.com. _sip._udp.subdomain.example.com. 300 IN SRV 0 0 5060 srv1.example.com. ;; Query time: 0 msec ;; SERVER: 10.1.2.17#53(10.1.2.17) ;; WHEN: Wed Mar 08 17:11:29 MST 2023 ;; MSG SIZE rcvd: 148
这里的ADDITIONAL区域只有EDNS相关内容,完全没有期望的A记录。
另外单独查询主机A记录是正常的,比如:
; <<>> DiG 9.16.1-Ubuntu <<>> @10.1.2.17 srv1.example.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 22271 ;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; WARNING: recursion requested but not available ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ; COOKIE: c68aa2c1d84416b8010000006409ffbaee89c08cb05f8de4 (good) ;; QUESTION SECTION: ;srv1.example.com. IN A ;; ANSWER SECTION: srv1.example.com. 300 IN A 192.168.58.100 ;; Query time: 0 msec ;; SERVER: 10.1.2.17#53(10.1.2.17) ;; WHEN: Thu Mar 09 08:48:10 MST 2023 ;; MSG SIZE rcvd: 86
我的BIND配置文件
下面是所有相关的配置文件内容,麻烦帮忙排查:
named.conf
include "/etc/bind/named.conf.options"; include "/etc/bind/named.conf.local"; include "/etc/bind/named.conf.log"; // include "/etc/bind/named.conf.default-zones"
named.conf.local
// zone "subdomain.example.com" { type master; file "/etc/bind/zones/db.subdomain.example.com"; # zone file path allow-transfer {"none";}; }; zone "example.com" { type master; file "/etc/bind/zones/db.example.com"; # zone file path allow-transfer {"none";}; }; zone "1.10.in-addr.arpa" { type primary; file "/etc/bind/zones/db.10.1"; # 10.1.2.0/24 subnet }; zone "168.192.in-addr.arpa" { type primary; file "/etc/bind/zones/db.192.168"; # 192.168.57 and 192.168.58 subnets };
named.conf.options
options { directory "/var/cache/bind"; recursion no; # enables recursive queries // allow-recursion { any; }; # allows recursive queries from "trusted" clients listen-on { any; }; allow-transfer { none; }; # disable zone transfers by default dnssec-validation no; allow-query { any; }; allow-query-cache { none; }; listen-on-v6 { none; }; // If there is a firewall between you and nameservers you want // to talk to, you may need to fix the firewall to allow multiple // ports to talk. See http://www.kb.cert.org/vuls/id/800113 // If your ISP provided one or more IP addresses for stable // nameservers, you probably want to use them as forwarders. // Uncomment the following block, and insert the addresses replacing // the all-0's placeholder. // forwarders { // 0.0.0.0; // }; //======================================================================== // If BIND logs error messages about the root key being expired, // you will need to update your keys. See https://www.isc.org/bind-keys //======================================================================== };
db.subdomain.example.com
; BIND data file for local IPv4 interface 10.1.2.17 ; $TTL 300 $ORIGIN subdomain.example.com. @ IN SOA fqdn-dns1.subdomain.example.com. postmaster.subdomain.example.com. ( 23030802 ; Serial 300 ; Refresh 300 ; Retry 300 ; Expire 300 ) ; Negative Cache TTL ; ; name server RR for the domain subdomain.example.com. IN NS fqdn-dns1.subdomain.example.com. ; the server where everything will run fqdn-dns1 IN A 10.1.2.17 ; server1 IN AAAA 2001:DB8:1000:2000::19 //IPv6 disabled// ; ; Use different names for each service. ; Don't use CNAMEs, the SRV records (further down) ; can't point to CNAME records. ; ; DNS SRV and NAPTR records for SIP ; @ 300 IN NAPTR 0 0 "S" "SIP+D2U" "" _sip._udp.subdomain.example.com. ; _sip._udp.subdomain.example.com. IN SRV 0 0 5060 srv1.example.com. _sip._udp.subdomain.example.com. IN SRV 1 0 5060 srv2.example.com.
db.example.com
; BIND data file for local IPv4 interface 10.1.2.26 ; $TTL 300 $ORIGIN example.com. @ IN SOA fqdn-dns1. admin.example.com. ( 23030803 ; Serial 300 ; Refresh 300 ; Retry 300 ; Expire 300 ) ; Negative Cache TTL ; ; name server RR for the domain @ IN NS fqdn-dns1.example.com. ; the server where everything will run fqdn-dns1.example.com. IN A 10.1.2.17 srv1.example.com. IN A 192.168.58.100 srv2.example.com. IN A 192.168.57.120
db.10.1(反向区域)
; ; BIND reverse data file for local loopback interface ; $TTL 300 @ IN SOA fqdn-dns1.example.com. root.example.com. ( 23030804 ; Serial 300 ; Refresh 300 ; Retry 300 ; Expire 300 ) ; Negative Cache TTL ; NS record for DNS server IPv4 @ IN NS fqdn-dns1.example.com. ; PTR Record for reverse to NS 17.2 IN PTR fqdn-dns1.example.com. ; 10.1.2.17 17.2 IN PTR fqdn-dns1.subdomain.example.com ; 10.1.2.17
db.192.168(反向区域)
; ; BIND reverse data file for 192.168. subnet ; $TTL 300 @ IN SOA fqdn-dns1.example.com. root.example.com. ( 4 ; Serial 300 ; Refresh 300 ; Retry 300 ; Expire 300 ) ; Negative Cache TTL ; ; NS record for DNS server IPv4 IN NS fqdn-dns1.example.com. ; PTR Record for reverse to Site Fabric Metaswitch subnets 120.57 IN PTR srv2.example.com. ; 192.168.57.120 100.58 IN PTR srv1.example.com. ; 192.168.58.100
现在我已经确认正向和反向区域都加载正常,单独查A记录没问题,但SRV查询就是不返回附加A记录,实在找不到原因了,求各位指点!
备注:内容来源于stack exchange,提问作者nube101

