servidor de nomes fora de vps

0

eu criei o servidor dns com bind9 e tudo está ok dentro do servidor. Eu posso pingar o meu domínio e eu posso cavar. mas fora do meu vps, o nome domin não tem servidor de nomes.

eu uso este comando

dig @89.42.210.210 fdoc.ir

dig a saída do comando dentro do servidor

; <<>> DiG 9.10.3-P4-Ubuntu <<>> @89.42.210.210 fdoc.ir
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4257
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;fdoc.ir.           IN  A

;; ANSWER SECTION:
fdoc.ir.        10800   IN  A   89.42.210.210

;; AUTHORITY SECTION:
fdoc.ir.        10800   IN  NS  ns2.fdoc.ir.
fdoc.ir.        10800   IN  NS  ns1.fdoc.ir.

;; ADDITIONAL SECTION:
ns1.fdoc.ir.        10800   IN  A   89.42.210.210
ns2.fdoc.ir.        10800   IN  A   89.42.210.210

;; Query time: 0 msec
;; SERVER: 89.42.210.210#53(89.42.210.210)
;; WHEN: Thu Feb 22 16:03:36 EST 2018
;; MSG SIZE  rcvd: 120

digita a saída do comando fora do servidor

; <<>> DiG 9.10.3-P4-Ubuntu <<>> @89.42.210.210 fdoc.ir
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 48479
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;fdoc.ir.           IN  A

;; Query time: 180 msec
;; SERVER: 89.42.210.210#53(89.42.210.210)
;; WHEN: Fri Feb 23 00:33:22 +0330 2018
;; MSG SIZE  rcvd: 36

configuração do nginx

# You should look at the following URL's in order to grasp a solid understanding
# of Nginx configuration files in order to fully unleash the power of Nginx.
# http://wiki.nginx.org/Pitfalls
# http://wiki.nginx.org/QuickStart
# http://wiki.nginx.org/Configuration
#
# Generally, you will want to move this file somewhere, and start with a clean
# file but keep this around for reference. Or just disable in sites-enabled.
#
# Please see /usr/share/doc/nginx-doc/examples/ for more detailed examples.
##

# Default server configuration
#
server {
    listen 80;
    listen [::]:80;

    # SSL configuration
    #
    # listen 443 ssl default_server;
    # listen [::]:443 ssl default_server;
    #
    # Note: You should disable gzip for SSL traffic.
    # See: https://bugs.debian.org/773332
    #
    # Read up on ssl_ciphers to ensure a secure configuration.
    # See: https://bugs.debian.org/765782
    #
    # Self signed certs generated by the ssl-cert package
    # Don't use them in a production server!
    #
    # include snippets/snakeoil.conf;

    root /var/www/fdoc.ir/html/public;

    # Add index.php to the list if you are using PHP
    index index.php index.html index.htm index.nginx-debian.html;

    server_name fdoc.ir www.fdoc.ir;


        location / {
                try_files $uri $uri/ /index.php?$query_string;
        }

        location ~ \.php$ {
            fastcgi_pass unix:/run/php/php7.1-fpm.sock;
            include snippets/fastcgi-php.conf;
            fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        }

        location ~ /\.ht {
                deny all;
        }

    # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000
    #
    #location ~ \.php$ {
    #   include snippets/fastcgi-php.conf;
    #
    #   # With php7.0-cgi alone:
    #   fastcgi_pass 127.0.0.1:9000;
    #   # With php7.0-fpm:
    #   fastcgi_pass unix:/run/php/php7.0-fpm.sock;
    #}

    # deny access to .htaccess files, if Apache's document root
    # concurs with nginx's one
    #
    #location ~ /\.ht {
    #   deny all;
    #}
}


# Virtual Host configuration for example.com
#
# You can move that to a different file under sites-available/ and symlink that
# to sites-enabled/ to enable it.
#
#server {
#   listen 80;
#   listen [::]:80;
#
#   server_name example.com;
#
#   root /var/www/example.com;
#   index index.html;
#
#   location / {
#       try_files $uri $uri/ =404;
#   }
#}

/ etc / hosts

127.0.0.1   localhost
127.0.1.1   ubuntu 
89.42.210.210 fdoc.ir www.fdoc.ir
    
por Hosein 22.02.2018 / 23:20

2 respostas

0

Existem possivelmente dois culpados.

Primeiro, verifique se o seu servidor de bind está escutando no IP externo ou em qualquer IP (0.0.0.0), por exemplo, em /etc/bind/named.conf.options , algo como

listen-on port 53 { any; }

A segunda e mais provável é verificar as regras do iptables para permitir que o tráfego UDP atinja a porta 53. Se você executar iptables -L -n , deverá ter algo como

Chain INPUT (policy DROP)
ACCEPT     udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:53

Se não tiver, você pode adicionar temporariamente essa regra executando como root

iptables -I INPUT -p udp --dport 53 -j ACCEPT

É claro que qualquer outro firewall entre o seu servidor e a internet também pode bloquear o tráfego.

    
por Spacy 23.02.2018 / 00:53
0

obrigado pela ajuda, mas o problema foi resolvido.

/etc/named.conf.local 
//include "/etc/bind/zones.rfc1918";

e apenas descomente a linha acima e tudo funciona como deveria.

    
por Hosein 23.02.2018 / 01:59