You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker/Portainer部署BIND9无法解析DNS请求问题求助

BIND9 DNS服务器解析失败问题修复

问题场景

在Portainer创建的Docker容器中运行BIND9作为DNS服务器,named.conf配置如下:

# DNS Settings
# Access control list
acl trusted {
    10.10.0.0/16;
    172.0.0.0/8;
    localhosts;
    localnets;
};

options {
    directory "/var/cache/bind";

    recursion yes;                 # enables resursive queries
    listen-on { any; };
    
    # Configure forwarder where outgoing DNS queries will be sent to
    forwarders {
        1.1.1.1; // Cloudflare DNS
        8.8.8.8; // Google DNS
    };

    allow-query { any; }; 
    allow-recursion { trusted; }; # allows recursive queries from "internal" ACL   
    allow-query-cache { trusted; };
};

容器运行无报错,但执行dig @10.10.30.12 google.com时返回REFUSED,容器日志报错:

24-Jun-2023 19:05:10.656 client @0x7f8f50022cd8 10.10.30.12#37211 (google.com): query (cache) 'google.com/A/IN' denied (allow-query-cache did not match)

已将Docker网络添加至ACL,但问题依旧。

错误分析

  1. ACL拼写错误:配置中localhosts是无效条目,BIND9预定义ACL为localhost(无s后缀),该错误会导致此条目无法被识别,可能影响ACL整体匹配逻辑。
  2. Docker网络下的IP识别问题:若容器使用默认桥接模式,BIND可能无法获取客户端真实IP(仅看到Docker网关IP),导致客户端IP不在trusted ACL的匹配范围内。
  3. ACL匹配验证缺失:虽配置了10.10.0.0/16网段,但需确认BIND是否正确将客户端IP(10.10.30.12)识别为该网段内地址。

修复步骤

1. 修正ACL拼写错误

将acl trusted中的localhosts改为localhost:

acl trusted {
    10.10.0.0/16;
    172.0.0.0/8;
    localhost;
    localnets;
};

2. 验证容器网络模式

  • 默认桥接模式:若使用端口映射(如-p 53:53/udp -p 53:53/tcp),需确认Docker宿主机开启IP转发,且客户端请求的IP是宿主机IP而非容器内部IP。若无法获取真实客户端IP,可尝试切换为host网络模式启动容器(直接使用宿主机网络栈,让BIND获取真实客户端IP):
    docker run --name bind9 --network host -d [你的BIND9镜像]
    
  • Host模式:确认10.10.30.12确实属于10.10.0.0/16网段,可通过ip addr验证客户端IP归属。

3. 临时放宽权限排查

临时修改options中的缓存和递归权限,测试是否为ACL匹配问题:

allow-recursion { any; };
allow-query-cache { any; };

修改后在容器内执行rndc reload重载配置,再执行dig @10.10.30.12 google.com测试。若解析正常,说明原ACL配置存在匹配问题,需进一步排查trusted条目有效性。

4. 开启调试日志排查匹配细节

在named.conf中添加日志配置,获取ACL匹配的详细过程:

logging {
    channel default_debug {
        file "/var/cache/bind/debug.log" versions 3 size 100k;
        severity dynamic;
        print-time yes;
    };
    category default { default_debug; };
    category security { default_debug; };
};

重载配置后再次发起查询,查看/var/cache/bind/debug.log,确认客户端IP的识别情况及ACL匹配结果。

5. 重载配置并验证

修改配置后,执行以下命令重载BIND配置:

docker exec -it [容器名/ID] rndc reload

再次执行dig @10.10.30.12 google.com,若返回正常解析结果,问题解决。


内容的提问来源于stack exchange,提问作者retronexus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 17:20:40