Docker/Portainer部署BIND9无法解析DNS请求问题求助
BIND9 DNS服务器解析失败问题修复
问题场景
在Portainer创建的Docker容器中运行BIND9作为DNS服务器,named.conf配置如下:
# DNS Settings # Access control list acl trusted { 10.10.0.0/16; 172.0.0.0/8; localhosts; localnets; }; options { directory "/var/cache/bind"; recursion yes; # enables resursive queries listen-on { any; }; # Configure forwarder where outgoing DNS queries will be sent to forwarders { 1.1.1.1; // Cloudflare DNS 8.8.8.8; // Google DNS }; allow-query { any; }; allow-recursion { trusted; }; # allows recursive queries from "internal" ACL allow-query-cache { trusted; }; };
容器运行无报错,但执行dig @10.10.30.12 google.com时返回REFUSED,容器日志报错:
24-Jun-2023 19:05:10.656 client @0x7f8f50022cd8 10.10.30.12#37211 (google.com): query (cache) 'google.com/A/IN' denied (allow-query-cache did not match)
已将Docker网络添加至ACL,但问题依旧。
错误分析
- ACL拼写错误:配置中
localhosts是无效条目,BIND9预定义ACL为localhost(无s后缀),该错误会导致此条目无法被识别,可能影响ACL整体匹配逻辑。 - Docker网络下的IP识别问题:若容器使用默认桥接模式,BIND可能无法获取客户端真实IP(仅看到Docker网关IP),导致客户端IP不在
trustedACL的匹配范围内。 - ACL匹配验证缺失:虽配置了
10.10.0.0/16网段,但需确认BIND是否正确将客户端IP(10.10.30.12)识别为该网段内地址。
修复步骤
1. 修正ACL拼写错误
将acl trusted中的localhosts改为localhost:
acl trusted { 10.10.0.0/16; 172.0.0.0/8; localhost; localnets; };
2. 验证容器网络模式
- 默认桥接模式:若使用端口映射(如
-p 53:53/udp -p 53:53/tcp),需确认Docker宿主机开启IP转发,且客户端请求的IP是宿主机IP而非容器内部IP。若无法获取真实客户端IP,可尝试切换为host网络模式启动容器(直接使用宿主机网络栈,让BIND获取真实客户端IP):docker run --name bind9 --network host -d [你的BIND9镜像] - Host模式:确认10.10.30.12确实属于
10.10.0.0/16网段,可通过ip addr验证客户端IP归属。
3. 临时放宽权限排查
临时修改options中的缓存和递归权限,测试是否为ACL匹配问题:
allow-recursion { any; }; allow-query-cache { any; };
修改后在容器内执行rndc reload重载配置,再执行dig @10.10.30.12 google.com测试。若解析正常,说明原ACL配置存在匹配问题,需进一步排查trusted条目有效性。
4. 开启调试日志排查匹配细节
在named.conf中添加日志配置,获取ACL匹配的详细过程:
logging { channel default_debug { file "/var/cache/bind/debug.log" versions 3 size 100k; severity dynamic; print-time yes; }; category default { default_debug; }; category security { default_debug; }; };
重载配置后再次发起查询,查看/var/cache/bind/debug.log,确认客户端IP的识别情况及ACL匹配结果。
5. 重载配置并验证
修改配置后,执行以下命令重载BIND配置:
docker exec -it [容器名/ID] rndc reload
再次执行dig @10.10.30.12 google.com,若返回正常解析结果,问题解决。
内容的提问来源于stack exchange,提问作者retronexus
相关产品推荐
相关产品推荐

