apt-get install unboundcd /etc/unboundwget ftp://FTP.INTERNIC.NET/domain/named.cacheunbound-control-setupchown unbound:root unbound_*chmod 440 unbound_*
mv /etc/unbound/unbound.conf /etc/unbound/unbound.conf1nano /etc/unbound/unbound.conf
server:verbosity: 1statistics-interval: 120statistics-cumulative: yesextended-statistics: yesnum-threads: 1interface: 0.0.0.0outgoing-range: 512num-queries-per-thread: 1024msg-cache-size: 16mrrset-cache-size: 32mmsg-cache-slabs: 4rrset-cache-slabs: 4cache-max-ttl: 86400infra-host-ttl: 60infra-lame-ttl: 120
infra-cache-numhosts: 10000infra-cache-lame-size: 10kdo-ip4: yesdo-ip6: nodo-udp: yesdo-tcp: yesdo-daemonize: yes#access-control: 0.0.0.0/0 allowaccess-control: 192.168.0.0/16 allowaccess-control: 172.16.0.0/12 allowaccess-control: 10.0.0.0/8 allowaccess-control: 127.0.0.0/8 allowaccess-control: 0.0.0.0/0 refuse
chroot: "/etc/unbound"username: "unbound"directory: "/etc/unbound"#logfile: "/etc/unbound/unbound.log" use-syslog: yeslogfile: ""use-syslog: nopidfile: "/etc/unbound/unbound.pid"root-hints: "/etc/unbound/named.cache"
identity: "DNS"version: "1.4"hide-identity: yeshide-version: yesharden-glue: yesdo-not-query-address: 127.0.0.1/8do-not-query-localhost: yesmodule-config: "iterator"
#zone localhostlocal-zone: "localhost." staticlocal-data: "localhost. 10800 IN NS localhost."local-data: "localhost. 10800 IN SOA localhost. nobody.invalid. 1 3600 1200 604800 10800"local-data: "localhost. 10800 IN A 127.0.0.1"local-zone: "127.in-addr.arpa." staticlocal-data: "127.in-addr.arpa. 10800 IN NS localhost."local-data: "127.in-addr.arpa. 10800 IN SOA localhost. nobody.invalid. 2 3600 1200 604800 10800"local-data: "1.0.0.127.in-addr.arpa. 10800 IN PTR localhost."
#zone cache.dns.nizy.net.idlocal-zone: "cache.dns.nizy.net.id." staticlocal-data: "nizy.net.id. 86400 IN NS cache.dns.nizy.net.id."local-data: "nizy.net.id. 86400 IN SOA nizy.net.id. proxy.nizy.net.id. 3 3600 1200 604800 86400"local-data: "nizy.net.id. 86400 IN A 192.168.200.2"local-data: "www.nizy.net.id. 86400 IN A 192.168.200.2"local-data: "cache.dns.nizy.net.id. 86400 IN A 192.168.200.2"
local-zone: "200.168.192.in-addr.arpa." staticlocal-data: "200.168.192.in-addr.arpa. 10800 IN NS nizy.net.id."local-data: "200.168.192.in-addr.arpa. 10800 IN SOA nizy.net.id. proxy.nizy.net.id. 4 3600 1200 604800 864000"local-data: "2.200.168.192.in-addr.arpa. 10800 IN PTR nizy.net.id."
forward-zone:name: "."forward-addr: 203.130.193.74forward-addr: 202.134.1.10forward-addr: 203.130.196.6forward-addr: 202.134.0.61forward-addr: 125.160.2.162forward-addr: 222.124.204.34forward-addr: 202.134.0.155forward-addr: 222.124.204.34forward-addr: 208.67.222.222forward-addr: 208.67.220.220forward-addr: 8.8.8.8forward-addr: 8.8.4.4
remote-control:control-enable: yescontrol-interface: 127.0.0.1control-port: 953server-key-file: "/etc/unbound/unbound_server.key"server-cert-file: "/etc/unbound/unbound_server.pem"control-key-file: "/etc/unbound/unbound_control.key"control-cert-file: "/etc/unbound/unbound_control.pem"
reboot pc !!!
setelah reboot, cek dengan perintah
root@nizy:~# unbound-control statsthread0.num.queries=619787thread0.num.cachehits=238858thread0.num.cachemiss=380929thread0.num.prefetch=0thread0.num.recursivereplies=380929thread0.requestlist.avg=1.19214thread0.requestlist.max=47thread0.requestlist.overwritten=0thread0.requestlist.exceeded=0thread0.requestlist.current.all=0thread0.requestlist.current.user=0thread0.recursion.time.avg=0.000442thread0.recursion.time.median=0.0510188total.num.queries=619787total.num.cachehits=238858total.num.cachemiss=380929total.num.prefetch=0total.num.recursivereplies=380929
lanjut lagi:
nano /etc/network/interfacesdns-nameservers 192.168.200.1ganti:dns-nameservers 127.0.0.1/etc/init.d/networking restart
nano /etc/resolv.confnameserver 192.168.200.1ganti:nameserver 127.0.0.1
cek:unbound-checkconfnslookup 192.168.200.2nslookup nizy.net.iddig google.comdig -x 127.0.0.1dig -x 192.168.200.2lsof -i UDP:53unbound-control stats
di mikrotik:
/ip dnsset allow-remote-requests=yes cache-max-ttl=1w cache-size=10240KiB max-udp-packet-size=\512 servers=192.168.200.2/ip dns staticadd address=192.168.200.2 comment="" disabled=no name=nizy.net.id ttl=5m
/ip firewall natadd action=dst-nat chain=dstnat comment="Transparan DNS" disabled=no dst-port=53 \in-interface=ether3-lan protocol=udp to-addresses=192.168.200.2 to-ports=53add action=dst-nat chain=dstnat comment="" disabled=no dst-port=53 in-interface=\ether3-lan protocol=tcp to-addresses=192.168.200.2 to-ports=53
sumber: http://www.forummikrotik.com/guide/14263-share-mari-incip2-dns-unbound-high-performance.html
Comments
Post a Comment