KISA-GD

Similar documents
DNS Áø´Üµµ±¸ - dig È°¿ë¹æ¹ý °¡À̵å(U0625).hwp

제20회_해킹방지워크샵_(이재석)

Microsoft Word - Solaris 10에_DNS_Bind-9.3.1_설치.doc

Microsoft Word - enterprise-linux-2-1.doc

DNS¼³Ä¡¿î¿µ.HWP

INDEX 1. 개요 DNS 서버구축하기 DNS 구축에필요한프로그램설치 DNS 설정 호스트추가. (zone 파일생성 ) 상위기관에네임서버등록.( 네임호스트추가 ) 활용

VPN제안서

Microsoft PowerPoint - 16_Linux_DNS_Server

bn2019_2

DNS (Domain Name System) Build for RHEL4(x86) Writer : 이경호

6강.hwp

개요 Windows 클라이언트와서버를위한이름풀이 (Name Resolution) DNS 서버설치와관리 DNS 영역 (Zones) 관리

°¡°Ç2¿ù-ÃÖÁ¾

<C0CCBCBCBFB52DC1A4B4EBBFF82DBCAEBBE7B3EDB9AE2D D382E687770>

DNS Domain name system : 도메인이름을 ip 주소로변환 Ip 숫자주소가기억하기어렵기때문에만들어짐. 큰통치킨시키는법. 전화번호부에서 ㅋ 으로시작하는부분찾기 => 크 으로시작하는부분찾기 => => 큰통치킨 : 를찾고전화걸기 2

Network seminar.key

PowerPoint 프레젠테이션

목차 1. 시작하며 간단한소개 설치...3 1) MySQL 설치...3 2) BIND RPM 설치...3 3) BIND 소스다운로드및설치...3 4) BIND 동작확인...5 5) 설정 스키마생성및테스트도메인입력 na

2 마고21동창회보 기를 촉촉이 적실 때쯤 영봉에 다다라 백운대를 바라본다. 여느 때와는 다른 감회 에 젖는다. 당신은 依 舊 하건만 어느덧 우리들은 노년에 접어들었구려. 하늘과 산도 우리의 기념등산을 축하해주는 듯 파아란 하늘 아래 펼쳐진 북한산의 신록이 눈이 시리도

personal-information-handling-policy


Microsoft PowerPoint - 12_name&address.ppt

[ 네트워크 1] 3 주차 1 차시. IPv4 주소클래스 3 주차 1 차시 IPv4 주소클래스 학습목표 1. IP 헤더필드의구성을파악하고요약하여설명할수있다. 2. Subnet ID 및 Subnet Mask 를설명할수있고, 각클래스의사용가능한호스트수와사설 IP 주소및네트


<BFC0B7A3C1F6C4B72DBBE7BFEBC0DABCB3B8EDBCAD5FC8AEC0E5BABB C7D1B1DB295F E6169>

보안(KDN)

USB USB DV25 DV25 REC SRN-475S REC SRN-475S LAN POWER LAN POWER Quick Network Setup Guide xdsl/cable Modem PC DVR 1~3 1.. DVR DVR IP xdsl Cable xdsl C

운영체제실습_명령어

TCP.IP.ppt

<C3CA3520B0FAC7D0B1B3BBE7BFEB202E687770>

KAA2005.9/10 Ãâ·Â

ARMBOOT 1

시스코 무선랜 설치운영 매뉴얼(AP1200s_v1.1)

Microsoft PowerPoint - MYDNS발표.pptx

PowerPoint 프레젠테이션

IT 관리자가알아야할보안키포인트 네트워크의미래를제시하는세미나 세미나 NetFocus 2003 : IT 관리자를위한네트워크보안방법론 오늘과내일 /

슬라이드 제목 없음

PowerPoint Presentation

Microsoft Word - DNS.doc

Microsoft Word doc

歯김병철.PDF

슬라이드 1

PWR PWR HDD HDD USB USB Quick Network Setup Guide xdsl/cable Modem PC DVR 1~3 1.. DVR DVR IP xdsl Cable xdsl Cable PC PC DDNS (

Microsoft PowerPoint - ch02_인터넷 이해와 활용.ppt

목차 BUG offline replicator 에서유효하지않은로그를읽을경우비정상종료할수있다... 3 BUG 각 partition 이서로다른 tablespace 를가지고, column type 이 CLOB 이며, 해당 table 을 truncate

2 247, Dec.07, 2007

KARAAUTO_4¿ù.qxd-ÀÌÆå.ps, page Normalize

Ⅰ. 서론 FOCUS 우리는매일컴퓨터와스마트폰의웹브라우저를통해웹사이트를접속하여뉴스를보고필요한정보를검색하거나인터넷쇼핑과뱅킹등을하고있다. 이같이웹사이트를가기위해서우리는웹브라우저주소창에도메인이름 ( 예. kisa.or.kr) 을입력한다. 그렇게되면우리의눈앞에우리가원하는웹사이

본교재는수업용으로제작된게시물입니다. 영리목적으로사용할경우저작권법제 30 조항에의거법적처벌을받을수있습니다. [ 실습 ] 스위치장비초기화 1. NVRAM 에저장되어있는 'startup-config' 파일이있다면, 삭제를실시한다. SWx>enable SWx#erase sta

자바-11장N'1-502

<4D F736F F D20C0A9B5B5BFEC BFA1BCAD20444E5320B0B3BFE420B9D720BCB3C1A420C0DBBEF720B9E6B9FD2E646F63>

untitled

GLOFA Series Cnet

歯sql_tuning2


Remote UI Guide

(

Sun Java System Messaging Server 63 64

BS-K1117□-M□□-3012_ProductGuide_KR_PDF

3ÆÄÆ®-14

PowerChute Personal Edition v3.1.0 에이전트 사용 설명서

UDP Flooding Attack 공격과 방어

歯한글사용설명서.PDF

1217 WebTrafMon II

hd1300_k_v1r2_Final_.PDF

침입방지솔루션도입검토보고서

< 목차 > Ⅰ. 개요 3 Ⅱ. 실시간스팸차단리스트 (RBL) ( 간편설정 ) 4 1. 메일서버 (Sendmail ) 설정변경 5 2. 스팸차단테스트 5 Ⅲ. 실시간스팸차단리스트 (RBL) (RBLDNSD 이용 ) 7 1. 시스템환경및프로그램상세내역 8 2.

003_°³Á¤3ÀúÀ۱dz»Áö

Solaris Express Developer Edition

SW_faq2000번역.PDF

ORANGE FOR ORACLE V4.0 INSTALLATION GUIDE (Online Upgrade) ORANGE CONFIGURATION ADMIN O

untitled

Contents Test Lab 홖경... 3 Windows 2008 R2 서버를도메인멤버서버로추가... 4 기존 Windows 2003 AD 홖경에서 Windows 2008 R2 AD 홖경으로업그레이드를위한사젂작업 7 기존 Windows 2003 AD의스키마확장...

PowerPoint 프레젠테이션

ETOS Series 사용설명서

SRC PLUS 제어기 MANUAL

<444E53BCADB9F6BFEEBFB5C1F6C4A7BCAD D30382D E687770>

(SW3704) Gingerbread Source Build & Working Guide

LXR 설치 및 사용법.doc

thesis-shk

Your title goes here

BS-K1217-M□□-3012_ProductGuide_KR_PDF

Sena Device Server Serial/IP TM Version

Subnet Address Internet Network G Network Network class B networ

특허청구의 범위 청구항 1 앵커(20)를 이용한 옹벽 시공에 사용되는 옹벽패널에 있어서, 단위패널형태의 판 형태로 구성되며, 내부 중앙부가 후방 하부를 향해 기울어지도록 돌출 형성되어, 전면이 오 목하게 들어가고 후면이 돌출된 결속부(11)를 형성하되, 이 결속부(11

인터넷프로토콜중간고사 학번 이름 1. ipconfig/all 을수행하면다수의인터페이스에 X.X 인주소가붙어있는 것을볼수있다. 이주소는어떤특수주소인가? [3 점 ] 2. Option 이없는 IP 헤더를그려라. 각필드의명칭을정확히기입하라.

ICANN 루트존키서명키 (KSK) 교체관련캐시 DNS 서버점검및조치방안 루트존 KSK 교체 o ICANN 의루트존의서명키의교체는국내시간으로 2017 년 10 월 12 일새벽 1 시 (10 월 11 일 16 시, UTC 기준 ) 에진행예정 인터넷이용자가 DNSSEC 서

file://\\......\paper\tr2001\tr \spam_relay_test.html

아래 항목은 최신( ) 이미지를 모두 제대로 설치하였을 때를 가정한다

Backup Exec

특허청구의 범위 청구항 1 회선 아이디 접속 시스템에 있어서, 온라인을 통해 실제 사용자 고유정보의 발급이 가능한 아이디 발급 사이트를 제공하기 위한 아이디 발급 수단; 오프라인을 통한 사용자의 회선 아이디 청약에 따라 가상의 사용자 고유정보 및 가인증 정보를 생성하고

MY FIRST BMW My First BMW

1. efolder 시스템구성 A. DB B. apache - mod-perl - PHP C. SphinxSearch ( 검색서비스 ) D. File Storage 2. efolder 설치순서 A. DB (MySQL) B. efolder Service - efolder

LCD Display

00인터넷지07+08-웹용.indd

(

Bulletin 04L41B01-01C-C

초보자를 위한 분산 캐시 활용 전략

uFOCS

4. 스위치재부팅을실시한다. ( 만약, Save 질문이나오면 'no' 를실시한다.) SWx#reload System configuration has been modified. Save? [yes/no]: no Proceed with reload? [confirm] (

Transcription:

KISA-GD-2011-0002 2011.9

1) RD(Recursive Desired) 플래그 : 리커시브네임서버로하여금재귀적 (recursive) 질의 ( 항목 1.3. 참고 ) 요청을표시함. RD 플레그값이 0 이면반복적 (iterative) 질의를요청

2) AA 플래그 : Authoritative Answer 의약자로써, 네임서버가해당응답데이터를자신이보유하고있는지유무를표시 3) Authoritative 네임서버 : 도메인존데이터를자신이데이터로보유하여이데이터만사용하여응답처리하는네임서버

4) RA 플래그 : Recursive Available 의약자로써, 응답하는네임서버가리커시브기능을갖는네임서버인지를표시

1

2

n n n n

1

2

3

1

2

1 2

Ÿ Ÿ

zone "my-domain.re.kr" IN { type master; // file "my-domain.kr.zone"; // allow-transfer { 192.168.2.53; 192.168.3.53; }; // };

zone "my-domain.re.kr" IN { type slave; // masters { 192.168.1.53; }; // IP allow-transfer { none; }; // }; $ORIGIN my-domain.re.kr. $TTL 300 @ SOA ns1.my-domain.re.kr. dnsadm.my-domain.re.kr ( 2009090101 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) NS ns1.my-domain.re.kr. NS ns2.my-domain.re.kr. NS ns3.my-domain.re.kr. ns1 A 192.168.1.53 ns2 A 192.168.2.53 ns3 A 192.168.3.53

Ÿ Ÿ

Ÿ

$ dig @211.182.233.3 version.bind ch txt +short "BIND 8.3.3" $ dig @193.0.14.129 version.bind ch txt +short "NSD 2.3.7" $ dig @152.99.1.10 version.bind ch txt +short "Nominum ANS 2.6.0.1" $ dig @222.239.76.130 version.bind ch txt +short "Served by POWERDNS 2.9.21 $Id: packethandler.cc 1036 2007-04-19 20:43:14Z ahu $" $ dig @203.255.112.34 version.bind ch txt +short "To err is human, to fix is divine - domain@higlobe.net" $ dig @210.204.251.22 version.bind ch txt +short "No!!"

C:\>nslookup.exe < > > server 211.182.233.3 < > > set class=chaos > set type=txt > version.bind Server: [211.182.233.3] Address: 211.182.233.3 VERSION.BIND text = > exit "BIND 8.3.3" options {...... version none; }; //

$ dig @localhost version.bind ch txt ; <<>> DiG 9.3.1 <<>> @localhost version.bind ch txt ; (1 server found) ;; global options: printcmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1146 ;; flags: qr aa rd; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: ;version.bind. CH TXT ;; AUTHORITY SECTION: version.bind. 86400 CH SOA version.bind. hostmaster.version.bind. 0 28800 7200 604800 86400 ;; Query time: 4 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: Fri Jun 12 19:09:52 2009 ;; MSG SIZE rcvd: 77 options {...... version UNKNOWN ; // }; $ dig @localhost version.bind ch txt ; <<>> DiG 9.3.1 <<>> @localhost version.bind ch txt ; (1 server found) ;; global options: printcmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 953 ;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: ;version.bind. CH TXT ;; ANSWER SECTION: version.bind. 0 CH TXT "UNKOWN"

;; AUTHORITY SECTION: version.bind. 0 CH NS version.bind. ;; Query time: 10 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: Fri Jun 12 19:10:35 2009 ;; MSG SIZE rcvd: 63 options {...... hostname none; // }; options {...... hostname ns ; // }; $ dig @202.30.50.51 hostname.bind ch txt ; <<>> DiG 9.3.1 <<>> @202.30.50.51 hostname.bind ch txt ; (1 server found) ;; global options: printcmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 2038 ;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0 ;; QUESTION SECTION: ;hostname.bind. CH TXT ;; ANSWER SECTION:

HOSTNAME.BIND. 0 CH TXT "ns" ;; Query time: 5 msec ;; SERVER: 202.30.50.51#53(202.30.50.51) ;; WHEN: Fri Jun 26 20:35:25 2009 ;; MSG SIZE rcvd: 60

Ÿ Ÿ

options {... recursion no; }; // // acl internal-hosts { localhost; localnets; 192.168.1.0/24; 192.168.5.0/24; }; options {... allow-recursion { internal-hosts; }; }; //

options {... recursion no; }; //

// acl internal-hosts { localhost; localnets; 192.168.1.0/24; 192.168.5.0/24; }; options {... allow-query { any; }; // allow-recursion { internal-hosts; }; // allow-query-cache { internal-hosts; }; // };

Ÿ Ÿ

options { allow-transfer { none; }; }; zone "my-domain.re.kr" IN { type master; // file "my-domain.kr"; // allow-transfer { 192.168.2.53; 192.168.3.53; }; // };

zone "my-domain.re.kr" IN { type slave; // masters { 192.168.1.53; }; // IP allow-transfer { none; }; // }; zone "my-domain.re.kr" IN { type slave; // masters { 192.168.1.53; }; // IP }; $ dig @192.168.2.53 my-domain.re.kr axfr +norec +multi ; <<>> DiG 9.3.1 <<>> @192.168.2.53 my-domain.re.kr axfr +norec +multi ; (1 server found) ;; global options: printcmd ; Transfer failed. $ dig @192.168.2.53 my-domain.re.kr axfr +norec +multi ; <<>> DiG 9.3.1 <<>> @192.168.2.53 my-domain.re.kr axfr +norec +multi ; (1 server found) ;; global options: printcmd my-domain.re.kr. 300 IN SOA ns1.my-domain.re.kr. dnsadm.my-domain.re.kr. ( 2009090105 ; serial

1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) my-domain.re.kr. 300 IN NS ns1.my-domain.re.kr. my-domain.re.kr. 300 IN NS ns2.my-domain.re.kr. my-domain.re.kr. 300 IN NS ns3.my-domain.re.kr. ns1.my-domain.re.kr. 300 IN A 192.168.1.53 ns2.my-domain.re.kr. 300 IN A 192.168.2.53 ns3.my-domain.re.kr. 300 IN A 192.168.3.53 www.my-domain.re.kr. 300 IN A 192.168.80.80 my-domain.re.kr. 300 IN SOA ns1.my-domain.re.kr. dnsadm.my-domain.re.kr. ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) ;; Query time: 19 msec ;; SERVER: 192.168.2.53#53(192.168.2.53) ;; WHEN: Tue Aug 11 16:56:00 2009 ;; XFR size: 9 records (messages 1)

Ÿ Ÿ

zone "my-domain.re.kr" IN { type master; // file "my-domain.kr.zone"; // allow-transfer { 192.168.2.53; 192.168.3.53; }; // };

zone "my-domain.re.kr" IN { type slave; // masters { 192.168.1.53; }; // IP allow-transfer { none; }; // }; $ORIGIN my-domain.re.kr. $TTL 300 @ SOA ns1.my-domain.re.kr. dnsadm.my-domain.re.kr ( 2009090101 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) NS ns1.my-domain.re.kr. NS ns2.my-domain.re.kr. NS ns3.my-domain.re.kr. ns1 A 192.168.1.53 ns2 A 192.168.2.53 ns3 A 192.168.3.53

Ÿ Ÿ Ÿ Ÿ

Ÿ kisa-ex.or.kr. 300 IN SOA ns1.kisa-ex.or.kr. domain.kisa-ex.or.kr. ( 2009072201 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) )

my-domain.re.kr. 300 IN SOA ns1.my-domain.re.kr. dnsadm.my-domain.re.kr. ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1.my-domain.re.kr. 300 IN NS ns2.my-domain.re.kr. 300 IN NS ns3.my-domain.re.kr. $ORIGIN my-domain.re.kr. @ 300 IN SOA ns1 dnsadm ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1.my-domain.re.kr. 300 IN NS ns2.my-domain.re.kr. 300 IN NS ns3.my-domain.re.kr.

$ORIGIN my-domain.re.kr. @ 300 IN SOA ns1.my-domain.re.kr dnsadm.my-domain.re.kr (... ) $ORIGIN my-domain.re.kr. @ 300 IN SOA ns1.example.kr. dnsadm ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours)

300 ; minimum (5 minutes) ) 300 IN NS ns1.example.kr. 300 IN NS ns2.example.kr. 300 IN NS ns3.example.kr.

Ÿ kisa-ex.or.kr. 300 IN SOA ns1.kisa-ex.or.kr. domain.kisa-ex.or.kr. ( 2009072201 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) )

my-domain.re.kr. 300 IN SOA ns1.my-domain.re.kr. dnsadm.my-domain.re.kr. ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1.my-domain.re.kr. 300 IN NS ns2.my-domain.re.kr. 300 IN NS ns3.my-domain.re.kr. $ORIGIN my-domain.re.kr.

@ 300 IN SOA ns1 dnsadm ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1.my-domain.re.kr. 300 IN NS ns2.my-domain.re.kr. 300 IN NS ns3.my-domain.re.kr. $ORIGIN my-domain.re.kr. @ 300 IN SOA ns1 dnsadm.example.kr. ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1.my-domain.re.kr. 300 IN NS ns2.my-domain.re.kr. 300 IN NS ns3.my-domain.re.kr.

Ÿ kisa-ex.or.kr. 300 IN SOA ns1.kisa-ex.or.kr. domain.kisa-ex.or.kr. ( 2009072201 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) )

Ÿ

Ÿ Ÿ Ÿ Ÿ Ÿ

n n

: : my-domain.re.kr. 300 IN SOA ns1.my-domain.re.kr. dnsadim.my-domain.re.kr. ( 2009100101 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) )

Ÿ Ÿ

my-domain.re.kr. 300 IN SOA ns1.my-domain.re.kr. dnsadm.my-domain.re.kr. ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1.my-domain.re.kr. 300 IN NS ns2.my-domain.re.kr. 300 IN NS ns3.my-domain.re.kr. ns1.my-domain.re.kr. 300 IN A 192.168.1.53 ns2.my-domain.re.kr. 300 IN A 192.168.2.53 ns3.my-domain.re.kr. 300 IN A 192.168.3.53 $ORIGIN my-domain.re.kr.

@ 300 IN SOA ns1 dnsadm ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1 300 IN NS ns2 300 IN NS ns3 ns1 300 IN A 192.168.1.53 ns2 300 IN A 192.168.2.53 ns3 300 IN A 192.168.3.53 $ORIGIN my-domain.re.kr. @ 300 IN SOA ns1 dnsadm ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1 300 IN NS ns2 300 IN NS ns3 ns1 300 IN CNAME dns1 ns2 300 IN CNAME dns2

ns3 300 IN CNAME dns3 dns1 300 IN A 192.168.1.53 dns2 300 IN A 192.168.2.53 dns3 300 IN A 192.168.3.53 $ORIGIN my-domain.re.kr. @ 300 IN SOA ns1.example.kr. dnsadm ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1.example.kr. 300 IN NS ns2.example.kr. 300 IN NS ns3.example.kr.

$ORIGIN my-domain.re.kr. @ 300 IN SOA ns1 dnsadm ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS 192.168.1.53 300 IN NS 192.168.2.53 300 IN NS 192.168.3.53

Ÿ Ÿ

my-domain.re.kr. 300 IN SOA ns1.my-domain.re.kr. dnsadm.my-domain.re.kr. ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1.my-domain.re.kr. 300 IN NS ns2.my-domain.re.kr. 300 IN NS ns3.my-domain.re.kr. 300 IN MX 10 smtp1.my-domain.re.kr. 300 IN MX 20 smtp2.my-domain.re.kr. 300 IN MX 30 smtp3.my-domain.re.kr. smtp1.my-domain.re.kr. 300 IN A 192.168.1.25 smtp2.my-domain.re.kr. 300 IN A 192.168.2.25 smtp3.my-domain.re.kr. 300 IN A 192.168.3.25 ns1.my-domain.re.kr. 300 IN A 192.168.1.53 ns2.my-domain.re.kr. 300 IN A 192.168.2.53 ns3.my-domain.re.kr. 300 IN A 192.168.3.53 $ORIGIN my-domain.re.kr. @ 300 IN SOA ns1 dnsadm ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1 300 IN NS ns2 300 IN NS ns3 300 IN MX 10 smtp1 300 IN MX 20 smtp2 300 IN MX 30 smtp3 smtp1 300 IN A 192.168.1.25

smtp2 300 IN A 192.168.2.25 smtp3 300 IN A 192.168.3.25 ns1 300 IN A 192.168.1.53 ns2 300 IN A 192.168.2.53 ns3 300 IN A 192.168.3.53 $ORIGIN my-domain.re.kr. @ 300 IN SOA ns1 dnsadm ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1 300 IN NS ns2 300 IN NS ns3 300 IN MX 10 smtp1 300 IN MX 20 smtp2

300 IN MX 30 smtp3 smtp1 smtp2 smtp3 300 IN CNAME mail1 300 IN CNAME mail2 300 IN CNAME mail3 mail1 300 IN A 192.168.1.25 mail2 300 IN A 192.168.2.25 mail3 300 IN A 192.168.3.25 ns1 300 IN A 192.168.1.53 ns2 300 IN A 192.168.2.53 ns3 300 IN A 192.168.3.53

$ORIGIN my-domain.re.kr. @ 300 IN SOA ns1.example.kr. dnsadm ( 2009090105 ; serial 1800 ; refresh (30 minutes) 300 ; retry (5 minutes) 3600000 ; expire (5 weeks 6 days 16 hours) 300 ; minimum (5 minutes) ) 300 IN NS ns1.example.kr. 300 IN NS ns2.example.kr. 300 IN NS ns3.example.kr. 300 IN MX 10 smtp1.example.kr. 300 IN MX 20 smtp2.example.kr. 300 IN MX 30 smtp3.example.kr.

my-domain.re.kr. IN TXT "v=spf1 ip4:1.2.3.4 ip4:1.2.3.5 -all" my-domain.re.kr. IN TXT "v=spf1 ip4:1.2.3.4 -all" my-domain.re.kr. IN TXT "v=spf1 ip4:1.2.3.5 -all"

$ dig www.kisa-ex.or.kr ; <<>> DiG 9.3.1 <<>> www.kisa-ex.or.kr ;; global options: printcmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1797 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 0 ;; QUESTION SECTION: ;www.kisa-ex.or.kr. IN A ;; ANSWER SECTION: www.kisa-ex.or.kr. 300 IN A 169.254.50.86

;; AUTHORITY SECTION: kisa-ex.or.kr. 300 IN NS ns0.kisa-ex.or.kr. kisa-ex.or.kr. 300 IN NS ns1.kisa-ex.or.kr. kisa-ex.or.kr. 300 IN NS ns2.kisa-ex.or.kr. ;; Query time: 59 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: Tue Jul 7 13:22:36 2009 ;; MSG SIZE rcvd: 102 ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1797 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 0

;; QUESTION SECTION: ;www.kisa-ex.or.kr. IN A ;; ANSWER SECTION: www.kisa-ex.or.kr. 300 IN A 169.254.50.86 ;; AUTHORITY SECTION: kisa-ex.or.kr. 300 IN NS ns0.kisa-ex.or.kr. kisa-ex.or.kr. 300 IN NS ns1.kisa-ex.or.kr. kisa-ex.or.kr. 300 IN NS ns2.kisa-ex.or.kr.

$ dig @ns0.kisa-ex.or.kr www.kisa-ex.or.kr +norecurse ; <<>> DiG 9.3.1 <<>> @ns0.kisa-ex.or.kr www.kisa-ex.or.kr +norecurse ; (1 server found) ;; global options: printcmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 811 ;; flags: qr aa; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 4 ;; QUESTION SECTION: ;www.kisa-ex.or.kr. IN A ;; ANSWER SECTION: www.kisa-ex.or.kr. 300 IN A 169.254.50.86 ;; AUTHORITY SECTION: kisa-ex.or.kr. 300 IN NS ns1.kisa-ex.or.kr. kisa-ex.or.kr. 300 IN NS ns2.kisa-ex.or.kr. kisa-ex.or.kr. 300 IN NS ns0.kisa-ex.or.kr. ;; ADDITIONAL SECTION: ns0.kisa-ex.or.kr. 300 IN A 169.254.1.53 ns0.kisa-ex.or.kr. 300 IN AAAA 2001:dc5:0:10:169:254:50:52 ns1.kisa-ex.or.kr. 300 IN A 169.254.50.51

ns2.kisa-ex.or.kr. 300 IN A 169.254.100.53 ;; Query time: 413 msec ;; SERVER: 169.254.1.53#53(169.254.1.53) ;; WHEN: Tue Jul 7 15:09:27 2009 ;; MSG SIZE rcvd: 178 ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 811 ;; flags: qr aa; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 4

$ dig www.kisa-ex.or.kr +trace ; <<>> DiG 9.3.1 <<>> www.kisa-ex.or.kr +trace ;; global options: printcmd. 508599 IN NS F.ROOT-SERVERS.NET.. 508599 IN NS G.ROOT-SERVERS.NET.. 508599 IN NS H.ROOT-SERVERS.NET.. 508599 IN NS I.ROOT-SERVERS.NET.. 508599 IN NS J.ROOT-SERVERS.NET.. 508599 IN NS K.ROOT-SERVERS.NET.. 508599 IN NS L.ROOT-SERVERS.NET.. 508599 IN NS M.ROOT-SERVERS.NET.. 508599 IN NS A.ROOT-SERVERS.NET.. 508599 IN NS B.ROOT-SERVERS.NET.. 508599 IN NS C.ROOT-SERVERS.NET.. 508599 IN NS D.ROOT-SERVERS.NET.. 508599 IN NS E.ROOT-SERVERS.NET. ;; Received 456 bytes from 127.0.0.1#53(127.0.0.1) in 5 ms kr. 172800 IN NS G.DNS.kr. kr. 172800 IN NS B.DNS.kr. kr. 172800 IN NS C.DNS.kr. kr. 172800 IN NS D.DNS.kr. kr. 172800 IN NS E.DNS.kr. kr. 172800 IN NS F.DNS.kr. ;; Received 284 bytes from 192.5.5.241#53(F.ROOT-SERVERS.NET) in 6 ms kisa-ex.or.kr. 86400 IN NS ns0.kisa-ex.or.kr. kisa-ex.or.kr. 86400 IN NS ns1.kisa-ex.or.kr. kisa-ex.or.kr. 86400 IN NS ns2.kisa-ex.or.kr. ;; Received 162 bytes from 202.31.190.1#53(G.DNS.kr) in 4 ms www.kisa-ex.or.kr. 300 IN A 169.254.50.86 kisa-ex.or.kr. 300 IN NS ns1.kisa-ex.or.kr. kisa-ex.or.kr. 300 IN NS ns2.kisa-ex.or.kr. kisa-ex.or.kr. 300 IN NS ns0.kisa-ex.or.kr. ;; Received 178 bytes from 169.254.1.53#53(ns0.kisa-ex.or.kr) in 3 ms

$ dig safedns.kr +nssearch SOA ns1.safedns.kr. domain-manager.nic.or.kr. 2009070701 3600 900 604800 7200 from server ns1.safedns.kr in 109 ms. SOA ns1.safedns.kr. domain-manager.nic.or.kr. 2009070701 3600 900 604800 7200 from server ns2.safedns.kr in 125 ms.

$ dig www.kisa-ex.or.kr +short 169.254.50.86

$ dig www.kisa-ex.or.kr +noall +comments +answer ; <<>> DiG 9.3.1 <<>> www.kisa-ex.or.kr +noall +comments +answer ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1996 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 0 ;; ANSWER SECTION: www.kisa-ex.or.kr. 281 IN A 169.254.50.86 ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1996 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 0 ;; ANSWER SECTION: www.kisa-ex.or.kr. 281 IN A 169.254.50.86

$ dig @b.root-servers.net. ns > named.root dig @192.168.1.53 my-domain.re.kr axfr +multiline > my-domain.re.kr-zone

n n n n n n n n

n n n n n n

n n

n C:\>nslookup Default Server: localhost Address: 127.0.0.1 > www.kisa-ex.or.kr Server: localhost Address: 127.0.0.1 Non-authoritative answer: Name: www.kisa-ex.or.kr Address: 169.254.50.86 > exit C:\> C:\>nslookup www.kisa-ex.or.kr Server: localhost Address: 127.0.0.1

Non-authoritative answer: Name: www.kisa-ex.or.kr Address: 169.254.50.86 C:\> $ dig @ns0.kisa-ex.or.kr www.kisa-ex.or.kr +norecurse C:\>nslookup Default Server: localhost Address: 127.0.0.1 > server ns0.kisa-ex.or.kr Default Server: ns0.kisa-ex.or.kr Address: 169.254.1.53 > set norecurse > www.kisa-ex.or.kr Server: ns0.kisa-ex.or.kr Address: 169.254.1.53 Name: www.kisa-ex.or.kr Address: 169.254.50.86 > exit

C:\>nslookup Default Server: localhost Address: 127.0.0.1 > set type=mx > kisa-ex.or.kr Server: localhost Address: 127.0.0.1 Non-authoritative answer: kisa-ex.or.kr MX preference = 0, mail exchanger = mailgw.kisa-ex.or.kr kisa-ex.or.kr nameserver = ns2.kisa-ex.or.kr kisa-ex.or.kr nameserver = ns0.kisa-ex.or.kr kisa-ex.or.kr nameserver = ns1.kisa-ex.or.kr mailgw.kisa-ex.or.kr internet address = 169.254.50.169 ns0.kisa-ex.or.kr internet address = 169.254.1.53 ns0.kisa-ex.or.kr AAAA IPv6 address = 2001:dc5:0:10:169:254:50:52 ns1.kisa-ex.or.kr internet address = 169.254.50.51 ns2.kisa-ex.or.kr internet address = 169.254.100.53 > exit

C:\>nslookup Default Server: localhost Address: 127.0.0.1 > server ns0.kisa-ex.or.kr Default Server: ns0.kisa-ex.or.kr Address: 169.254.1.53 > set norecurse > set debug > www.kisa-ex.or.kr Server: ns0.kisa-ex.or.kr Address: 169.254.1.53 ------------ Got answer: HEADER: opcode = QUERY, id = 3, rcode = NOERROR header flags: response, auth. answer questions = 1, answers = 1, authority records = 3, additional = 4 QUESTIONS: www.kisa-ex.or.kr, type = A, class = IN ANSWERS: -> www.kisa-ex.or.kr internet address = 169.254.50.86 ttl = 300 (5 mins) AUTHORITY RECORDS: -> kisa-ex.or.kr nameserver = ns0.kisa-ex.or.kr ttl = 300 (5 mins) -> kisa-ex.or.kr nameserver = ns1.kisa-ex.or.kr ttl = 300 (5 mins)

-> kisa-ex.or.kr nameserver = ns2.kisa-ex.or.kr ttl = 300 (5 mins) ADDITIONAL RECORDS: -> ns0.kisa-ex.or.kr internet address = 169.254.1.53 ttl = 300 (5 mins) -> ns0.kisa-ex.or.kr AAAA IPv6 address = 2001:dc5:0:10:169:254:50:52 ttl = 300 (5 mins) -> ns1.kisa-ex.or.kr internet address = 169.254.50.51 ttl = 300 (5 mins) -> ns2.kisa-ex.or.kr internet address = 169.254.100.53 ttl = 300 (5 mins) ------------ Name: www.kisa-ex.or.kr Address: 169.254.50.86 > exit

n n n

n n n

n n n

n

www.my-domain.re.kr. IN A 192.168.80.80 ftp.my-domain.re.kr. IN A 192.168.80.80 mail.my-domain.re.kr. IN A 192.168.80.80 www.my-domain.re.kr. IN A 192.168.80.80 ftp.my-domain.re.kr. IN CNAME www.my-domain.re.kr. mail.my-domain.re.kr. IN CNAME www.my-domain.re.kr.