> For the complete documentation index, see [llms.txt](https://paul-gleason.gitbook.io/firewalld/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://paul-gleason.gitbook.io/firewalld/ncae/dns.md).

# DNS

## Using bind on ubuntu:

### Network Setup:

<figure><img src="https://1220673619-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuD4vtKK2oQ2qWjsn9wDJ%2Fuploads%2F7DntrkLNci4wIUDjcIil%2Fimage.png?alt=media&amp;token=5911ab4e-c91e-4e3b-97bd-922590ad20ee" alt=""><figcaption></figcaption></figure>

### Step 1: Install BIND

First, update your package lists and install BIND9:

```sh
sudo apt update
sudo apt install bind9 dnsutils
```

### Step 2: Configure the DNS Zone for `team2.net`

Need to configure the forward and reverse DNS zones for `team2.net`.

#### **Forward Zone File Configuration**

Navigate to the BIND directory

```bash
cd /etc/bind
```

Create the forward zone file for `team2.net`. First, open the named configuration file to define the zone:

```bash
sudo nano named.conf.local
```

Add the following zone definition:

```conf
zone "team2.net" {
    type master;
    file "/etc/bind/zones/db.team2.net";
};
```

Create the directory for your zones if it doesn't already exist:

```bash
sudo mkdir /etc/bind/zones
```

Next, create and edit the zone file:

```bash
sudo nano /etc/bind/zones/db.team2.net
```

Add the following records to the zone file:

```
$TTL    604800
@       IN      SOA     ns1.team2.net. admin.team2.net. (
                           2         ; Serial
                      604800         ; Refresh
                       86400         ; Retry
                     2419200         ; Expire
                      604800 )       ; Negative Cache TTL
; Name servers
@       IN      NS      ns1.team2.net.

; A records for name server and other hosts
ns1     IN      A       192.168.2.12
www     IN      A       192.168.2.5
db      IN      A       192.168.2.7
```

#### Step 3: Reverse Zone File Configuration

This step is optional but recommended for resolving IP addresses back to hostnames.

Define the reverse zone in `named.conf.local`:

```bash
sudo nano named.conf.local
```

Add the reverse zone configuration:

```
zone "2.168.192.in-addr.arpa" {
    type master;
    file "/etc/bind/zones/db.192.168.2";
};
```

Create the reverse zone file:

```bash
sudo nano /etc/bind/zones/db.192.168.2
```

Add reverse mappings:

```
$TTL    604800
@       IN      SOA     team2.net. admin.team2.net. (
                           2         ; Serial
                      604800         ; Refresh
                       86400         ; Retry
                     2419200         ; Expire
                      604800 )       ; Negative Cache TTL
@       IN      NS      ns1.team2.net.
12      IN      PTR     ns1.team2.net.
5       IN      PTR     www.team2.net.
7       IN      PTR     db.team2.net.
```

#### Step 4: Check Configuration and Restart BIND

After setting up your zone files, check the configuration for errors:

```sh
sudo named-checkconf
sudo named-checkzone team2.net /etc/bind/zones/db.team2.net
sudo named-checkzone 2.168.192.in-addr.arpa /etc/bind/zones/db.192.168.2
```

If everything is configured correctly, restart BIND to apply changes:

```sh
sudo systemctl restart bind9
```

#### Step 5: Test DNS Server

Use `dig` or `nslookup` to test your DNS server and ensure it's resolving domain names correctly:

```sh
dig @192.168.2.12 www.team2.net +short
dig -x 192.168.2.5 @192.168.2.12 +short
```

### Final Config Output:

#### Config "/etc/bind/named.conf.local"

```bash
//
// Do any local configuration here
//

// Consider adding the 1918 zones here, if they are not used in your
// organization
//include "/etc/bind/zones.rfc1918";

zone "team2.net" {
    type master;
    file "/etc/bind/zones/db.team2.net";
};
zone "2.168.192.in-addr.arpa" {
    type master;
    file "/etc/bind/zones/db.192.168.2";
};

```

#### Config "/etc/bind/zones/db.team2.net"

<pre class="language-bash"><code class="lang-bash">TTL    604800
@       IN      SOA     ns1.team2.net. admin.team2.net. (
                           2         ; Serial
                      604800         ; Refresh
                       86400         ; Retry
                     2419200         ; Expire
                      604800 )       ; Negative Cache TTL
; Name servers
@       IN      NS      ns1.team2.net.

; A records for name server and other hosts
ns1     IN      A       192.168.2.12
<strong>www     IN      A       192.168.2.5
</strong>db      IN      A       192.168.2.7

</code></pre>

#### Config "/etc/bind/zones/db.192.168.2"

```bash
TTL    604800
@       IN      SOA     team2.net. admin.team2.net. (
                           2         ; Serial
                      604800         ; Refresh
                       86400         ; Retry
                     2419200         ; Expire
                      604800 )       ; Negative Cache TTL
@       IN      NS      ns1.team2.net.
12      IN      PTR     ns1.team2.net.
5       IN      PTR     www.team2.net.
7       IN      PTR     db.team2.net.
```
