ããŒã§ã¯ãªãå Žåãææ°ã®ãããã¯ãŒã¯ã§ã®ãµãŒãã¹ã DNSãµãŒãã¹ãæ°ãããªã人ã¯ãæåã®éšåãå®å šã«ã¹ãããã§ããŸãã
å 容ïŒ
1.åºæ¬æ å ±
2. DNSã¡ãã»ãŒãžåœ¢åŒã«ã€ããŠå°ã
3. TCPããã³UDP
4. Windows Server 2008ããã³2012ã®DNS
5. DNSããã³Active Directory
6.æ å ±æº
ïŒã¢ã³ã«ãŒããªããããã³ã³ãã³ãã«ã¯ãªã³ã¯ããããŸããïŒ
1.åºæ¬æ å ±
DNSã¯ããããã¯ãŒã¯ãªããžã§ã¯ãåã®IPã¢ãã¬ã¹ãžã®ãããã³ã°ã«é¢ããæ å ±ãäž»ã«å«ãããŒã¿ããŒã¹ã§ãã ãåºæ¬çã«ã-ãããšä»ã®ããã€ãã®æ å ±ãä¿åãããŠããããã å ·äœçã«ã¯ã次ã®ã¿ã€ãã®ãªãœãŒã¹ã¬ã³ãŒãïŒãªãœãŒã¹ã¬ã³ãŒã-RRïŒïŒ
ãã㊠-ã·ã³ããªãã¯ãã¡ã€ã³åã®IPã¢ãã¬ã¹ãžã®åããããã³ã°ã
AAAAã¯Aãšåãã§ãããIPv6ã¢ãã¬ã¹çšã§ãã
CNAME -Canonical NAMEã¯ãšã€ãªã¢ã¹ã§ãã ã³ãŒãã¬ãŒãããŒã¿ã«ãå®è¡ãããŠããnsk-dc2-0704-ibmãªã©ã®èªã¿åãäžèœãªååã®ãµãŒããŒãããŒã ããŒã¿ã«ã«å¿çããå Žåã¯ãããŒã ããŒã¿ã«ãšåãIPã¢ãã¬ã¹ãæã€å¥ã®ã¿ã€ãAã¬ã³ãŒããäœæã§ããŸãã ãããããã®åŸãIPã¢ãã¬ã¹ãå€æŽãããå ŽåïŒäœãçºçããŠãããŸããŸããïŒããã®ãããªã¬ã³ãŒãããã¹ãŠåäœæããå¿ èŠããããŸãã ãŸããnsk-dc2-0704-ibmãæãååããŒã¿ã«ã§CNAMEãäœæããå Žåãäœãå€æŽããå¿ èŠã¯ãããŸããã
MX -Mail eXchanger-ã¡ãŒã«ãšã¯ã¹ãã§ã³ãžã£ãŒãžã®ãã€ã³ã¿ãŒã CNAMEãšåæ§ã«ãããã¯ã¿ã€ãAã®æ¢åã®ã¬ã³ãŒããžã®ã·ã³ããªãã¯ãã€ã³ã¿ãŒã§ãããååã«å ããŠãåªå 床ãå«ãŸããŠããŸãã 1ã€ã®ã¡ãŒã«ãã¡ã€ã³ã«å¯ŸããŠè€æ°ã®MXã¬ã³ãŒããååšããå ŽåããããŸããããŸãåªå 床ãã£ãŒã«ãã«äœãå€ã瀺ãããŠãããµãŒããŒã«ã¡ãŒã«ãéä¿¡ãããŸãã å©çšã§ããªãå Žå-次ã®ãµãŒããŒãªã©ãž
NS-ããŒã ãµãŒããŒ-ãã®ãã¡ã€ã³ãæ åœããDNSãµãŒããŒã®ååãå«ãŸããŠããŸãã åœç¶ãNSã¿ã€ãã®åã¬ã³ãŒãã«ã¯ãAã¿ã€ãã®å¯Ÿå¿ããã¬ã³ãŒããå¿ èŠã§ãã
SOA-æš©éã®éå§-ã©ã®NSãµãŒããŒããã®ãã¡ã€ã³ã«é¢ããåç §æ å ±ããŸãŒã³ã®è²¬ä»»è ã®é£çµ¡å æ å ±ããã£ãã·ã¥ã«æ å ±ãä¿åããã¿ã€ãã³ã°ãä¿åãããã瀺ããŸãã
SRV-ãµãŒããŒãžã®ãã€ã³ã¿ãŒããµãŒãã¹ã®ææè ïŒADãµãŒãã¹ããã³Jabberãªã©ã«äœ¿çšïŒã ãµãŒããŒåã«å ããŠãåªå 床ïŒMXã«é¡äŒŒïŒãééïŒåãåªå 床ã®ãµãŒããŒéã§è² è·ãåæ£ããããã«äœ¿çšãããŸã-ã¯ã©ã€ã¢ã³ãã¯ãéã¿ãšããŒãçªå·-ããŒãçªå·ã«åºã¥ãã確çã§ãµãŒããŒãã©ã³ãã ã«éžæããŸãïŒãµãŒãã¹ããªã¯ãšã¹ãããªãã¹ã³ããå Žæã
äžèšã®ãã¹ãŠã®ã¬ã³ãŒãã¿ã€ãã¯ãDNSã®åæ¹åç §ãŸãŒã³ã«ãããŸãã ãŸããéåŒãåç §ãŸãŒã³ããããŸã-PTRã¿ã€ãã®ã¬ã³ãŒããããã«ä¿åãããŸã-PoinTeR-ã¬ã³ãŒãã¯ã¿ã€ãAã®å察ã§ããIPã¢ãã¬ã¹ãšãã®ã·ã³ããªãã¯åã®ãããã³ã°ãä¿åããŸãã éåŒãèŠæ±ãåŠçããããã«å¿ èŠã§ã-ãã®IPã¢ãã¬ã¹ã«ãã£ãŠãã¹ãåã決å®ããŸãã DNSã®æ©èœã«ã¯å¿ èŠãããŸããããããŸããŸãªèšºæãŠãŒãã£ãªãã£ããã¡ãŒã«ãµãŒãã¹ã®äžéšã®çš®é¡ã®ã¹ãã 察çä¿è·ã«å¿ èŠã§ãã
ããã«ããã¡ã€ã³ã«é¢ããæ å ±ãæ ŒçŽãããŸãŒã³èªäœã¯ã2ã€ã®ã¿ã€ãïŒã¯ã©ã·ãã¯ïŒã§ãã
ã¡ã€ã³ïŒãã©ã€ããªïŒ -ãã¡ã€ã³ã®ãã¹ããšãµãŒãã¹ã«é¢ããæ å ±ãå«ãããã¹ããã¡ã€ã«ã§ãã ãã¡ã€ã«ãç·šéã§ããŸãã
è¿œå ïŒã»ã«ã³ããªïŒãããã¹ããã¡ã€ã«ã§ãããã¡ã€ã³ã®ãã¡ã€ã«ãšã¯ç°ãªããç·šéã§ããŸããã ã¡ã€ã³ãŸãŒã³ãæ ŒçŽãããµãŒããŒããèªåçã«çž®å°ããŸãã å¯çšæ§ãšä¿¡é Œæ§ãåäžããŸãã
ã€ã³ã¿ãŒãããã§ãã¡ã€ã³ãç»é²ããã«ã¯ãå°ãªããšã2ã€ã®DNSãµãŒããŒããã®ãã¡ã€ã³ã«é¢ããæ å ±ãä¿åããå¿ èŠããããŸãã
Windows 2000ã¯ã ADã«çµ±åããããã®ã¿ã€ãã®ãŸãŒã³ãå°å ¥ããŸããããŸãŒã³ã¯ããã¹ããã¡ã€ã«ã§ã¯ãªãADããŒã¿ããŒã¹ã«ä¿åãããè€è£œã¡ã«ããºã ã䜿çšããŠADãšãšãã«ä»ã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒã«è€è£œã§ããŸãã ãã®ãªãã·ã§ã³ã®äž»ãªå©ç¹ã¯ãDNSã§å®å šãªåçç»é²ãå®è£ ã§ããããšã§ãã ã€ãŸãããã¡ã€ã³ã®ã¡ã³ããŒã§ããã³ã³ãã¥ãŒã¿ãŒã®ã¿ãèªåèªèº«ã«é¢ããã¬ã³ãŒããäœæã§ããŸãã
Windows 2003ã§ã¯ã ã¹ã¿ããŸãŒã³ïŒã¹ã¿ããŸãŒã³ïŒãå°å ¥ãããŸããã ãã®ãã¡ã€ã³ã«å¯ŸããŠæš©éã®ããDNSãµãŒããŒã«é¢ããæ å ±ã®ã¿ãä¿åããŸãã ã€ãŸããNSã¬ã³ãŒãã ããã¯ãåãããŒãžã§ã³ã®Windows Serverã«ç»å Žããæ¡ä»¶ä»ã転éã«æå³ã䌌ãŠããŸãããèŠæ±ã®è»¢éå ã®ãµãŒããŒã®ãªã¹ãã¯èªåçã«æŽæ°ãããŸãã
å埩ã¯ãšãªãšååž°ã¯ãšãªã
åäžã®DNSãµãŒããŒãã€ã³ã¿ãŒãããäžã®ãã¹ãŠã®ãã¡ã€ã³ãèªèããŠããªãããšã¯æããã§ãã ãããã£ãŠã圌ãç¥ããªãã¢ãã¬ã¹ãããšãã°metro.yandex.ruãžã®èŠæ±ãåä¿¡ãããšã次ã®äžé£ã®å埩ãéå§ãããŸãã
DNSãµãŒããŒã¯ãã€ã³ã¿ãŒãããã«ãŒããµãŒããŒã®1ã€ã«ã¢ã¯ã»ã¹ããŸããã€ã³ã¿ãŒãããã«ãŒããµãŒããŒã«ã¯ã第1ã¬ãã«ãã¡ã€ã³ãŸãã¯ãŸãŒã³ïŒruãorgãcomãªã©ïŒã®æ¿èªãããææè ã«é¢ããæ å ±ãæ ŒçŽãããŸãã 圌ã¯ãæš©éã®ãããµãŒããŒã®åä¿¡ã¢ãã¬ã¹ãã¯ã©ã€ã¢ã³ãã«å ±åããŸãã
ã¯ã©ã€ã¢ã³ãã¯ãåãèŠæ±ã§ruãŸãŒã³ã®ææè ã«é£çµ¡ããŸãã
RUãŸãŒã³ã®DNSãµãŒããŒã¯ãã£ãã·ã¥å ã§å¯Ÿå¿ããã¬ã³ãŒããæ€çŽ¢ããèŠã€ãããªãå Žåãã¯ã©ã€ã¢ã³ãã«ç¬¬2ã¬ãã«ãã¡ã€ã³ïŒãã®å Žåã¯yandex.ruïŒã«å¯ŸããŠæš©éã®ãããµãŒããŒã®ã¢ãã¬ã¹ãè¿ããŸãã
ã¯ã©ã€ã¢ã³ãã¯åãã¯ãšãªã§yandex.ru DNSã«ã¢ã¯ã»ã¹ããŸãã
Yandex DNSã¯ãç®çã®ã¢ãã¬ã¹ãè¿ããŸãã
ç§ãã¡ã®æ代ã«ã¯ããã®äžé£ã®ã€ãã³ãã¯ãŸãã§ãã ååž°ã¯ãšãªã®ãããªãã®ããããã-ããã¯ãã¯ã©ã€ã¢ã³ããæåã«ã¢ãã¬ã¹æå®ããDNSãµãŒããŒãã¯ã©ã€ã¢ã³ãã«ä»£ãã£ãŠãã¹ãŠã®å埩ãå®è¡ããã¯ã©ã€ã¢ã³ãã«æºåå®äºã®å¿çãè¿ããåä¿¡ããæ å ±ããã£ãã·ã¥ã«æ ŒçŽãããšãã§ãã ãµãŒããŒã§ååž°ã¯ãšãªã®ãµããŒããç¡å¹ã«ããããšãã§ããŸãããã»ãšãã©ã®ãµãŒããŒã§ãµããŒããããŠããŸãã
ã¯ã©ã€ã¢ã³ãã¯ãååãšããŠããååž°ãå¿ èŠããšãããã©ã°ãæã€ãªã¯ãšã¹ããäœæããŸãã
2. DNSã¡ãã»ãŒãžåœ¢åŒã«ã€ããŠå°ã
ã¡ãã»ãŒãžã¯ã12ãã€ãã®ããããŒãšããã«ç¶ã4ã€ã®å¯å€é·ãã£ãŒã«ãã§æ§æãããŸãã
ããããŒã¯æ¬¡ã®ãã£ãŒã«ãã§æ§æãããŸãã
![](https://habrastorage.org/getpro/habr/post_images/450/0ee/f4a/4500eef4a0a8599c44c4511d4f5cac2d.gif)
DNSã¡ãã»ãŒãžåœ¢åŒ
èå¥-ç¹å®ã®èå¥åããã®ãã£ãŒã«ãã§ã¯ã©ã€ã¢ã³ãã«ãã£ãŠçæããã察å¿ãããµãŒããŒå¿çãã£ãŒã«ãã«ã³ããŒããããããå¿çãã©ã®èŠæ±ã«å±ããããç解ã§ããŸãã
ãã©ã°-8ãããã«åå²ããã16ããããã£ãŒã«ãïŒ
- QR ïŒã¡ãã»ãŒãžã¿ã€ãïŒã1ããããã£ãŒã«ãïŒ0ã¯èŠæ±ã1ã¯å¿çãæå³ããŸãã
- ãªãã³ãŒã ïŒ opcode ïŒã4ããããã£ãŒã«ãã ããã©ã«ãå€ã¯0ïŒæšæºãªã¯ãšã¹ãïŒã§ãã ä»ã®å€ã¯1ïŒéèŠæ±ïŒãš2ïŒãµãŒããŒã¹ããŒã¿ã¹èŠæ±ïŒã§ãã
- AAã¯ããä¿¡é Œã§ããå¿çããæå³ãã1ãããã®ãã©ã°ã§ãã DNSãµãŒããŒã«ã¯ã質åã»ã¯ã·ã§ã³ã§ãã®ãã¡ã€ã³ã«å¯Ÿããæš©éããããŸãã
- TCã¯ããåãæšãŠããããããšãæå³ãã1ãããã®ãã£ãŒã«ãã§ãã UDPã®å Žåãããã¯ãåèšå¿çãµã€ãºã512ãã€ããè¶ ããããšãæå³ããŸãããå¿çã®æåã®512ãã€ãã®ã¿ãè¿ãããŸããã
- RDã¯ããååž°ãå¿ èŠããæå³ãã1ãããã®ãã£ãŒã«ãã§ãã èŠæ±ã§ããããèšå®ããå¿çã§è¿ãããšãã§ããŸãã ãã®ãã©ã°ã§ã¯ãDNSãµãŒããŒããã®èŠæ±èªäœãåŠçããå¿ èŠããããŸãïŒã€ãŸãããµãŒããŒèªäœãå¿ èŠãªIPã¢ãã¬ã¹ã決å®ããå¥ã®DNSãµãŒããŒã®ã¢ãã¬ã¹ãè¿ããªãå¿ èŠããããŸãïŒãããã¯ååž°ã¯ãšãªãšåŒã°ããŸãã ãã®ããããèšå®ãããŠããããèŠæ±ãããDNSãµãŒããŒã«ä¿¡é Œã§ããå¿çããªãå ŽåãèŠæ±ããããµãŒããŒã¯ãå¿çãåä¿¡ããããã«åç §ããå¿ èŠãããä»ã®DNSãµãŒããŒã®ãªã¹ããè¿ããŸãã ããã¯ãå埩ã¯ãšãªãšåŒã°ããŸãã 次ã®äŸã§ã¯ãäž¡æ¹ã®ã¿ã€ãã®ã¯ãšãªã®äŸãèŠãŠãããŸãã
- RAã¯ããå©çšå¯èœãªååž°ããæå³ãã1ãããã®ãã£ãŒã«ãã§ãã ãµãŒããŒãååž°ããµããŒãããŠããå Žåããã®ãããã¯å¿çã§1ã«èšå®ãããŸãã äŸã§ã¯ãããã€ãã®ã«ãŒããµãŒããŒãé€ããã»ãšãã©ã®DNSãµãŒããŒãååž°ããµããŒãããŠããããšãããããŸãïŒãšããžãµãŒããŒã¯ãã¯ãŒã¯ããŒãã®ããã«ååž°ã¯ãšãªãåŠçã§ããŸããïŒã
- 0-ãã®3ããããã£ãŒã«ãã¯0ã§ãªããã°ãªããŸããã
- rcodeã¯4ãããã®æ»ãã³ãŒããã£ãŒã«ãã§ãã äžè¬çãªå€ã¯0ïŒãšã©ãŒãªãïŒããã³3ïŒååãšã©ãŒïŒã§ãã ååãšã©ãŒã¯ãæš©éã®ããDNSãµãŒããŒããã®ã¿è¿ããããªã¯ãšã¹ãã§æå®ããããã¡ã€ã³åãååšããªãããšãæå³ããŸãã
次ã®4ã€ã®16ããããã£ãŒã«ãã¯ãèšé²ãå®äºãã4ã€ã®å¯å€é·ãã£ãŒã«ãã®ãã€ã³ãæ°ã瀺ããŸãã ã¯ãšãªã§ã¯ã質åã®æ°ã¯éåžž1ã§ãä»ã®3ã€ã®ã«ãŠã³ã¿ãŒã¯0ã§ããå¿çã§ã¯ãåçã®æ°ã¯å°ãªããšã1ã§ãæ®ãã®2ã€ã®ã«ãŠã³ã¿ãŒã¯ãŒããŸãã¯éãŒãã®ããããã§ãã
äŸïŒping www.ruã³ãã³ãã®å®è¡æã«WinDumpã䜿çšããŠååŸïŒïŒ
IP KKasachev-nb.itcorp.it.ru.51036 > ns1.it.ru.53: 36587+ A? www.ru. (24)
IP ns1.it.ru.53 > KKasachev-nb.itcorp.it.ru.51036: 36587 1/2/5 A 194.87.0.50 (196)
æåã®è¡ã¯ãªã¯ãšã¹ãã§ãïŒPCã®ååã51036ã¯ã©ã³ãã ã«éžæãããéä¿¡ããŒãã53ã¯DNSãµãŒããŒã®æ¢ç¥ã®ããŒãã36587ã¯ãªã¯ãšã¹ãIDã+-ãååž°ãå¿ èŠããAã¯ã¬ã³ãŒãã¿ã€ãAã®ãªã¯ãšã¹ããçå笊ã¯ãããæå³ããŸãå¿çã§ã¯ãªãèŠæ±ã æ¬åŒ§å ã¯ãã¡ãã»ãŒãžã®é·ãïŒãã€ãåäœïŒã§ãã
2è¡ç®ã¯ãµãŒããŒã®å¿çã§ããæå®ãããèŠæ±IDãæã€æå®ãããéä¿¡å ããŒããžã®å¿çã§ãã å¿çã«ã¯ãèŠæ±ã«å¯Ÿããå¿çã§ãã1ã€ã®RRïŒDNSãªãœãŒã¹ã¬ã³ãŒãïŒã2ã€ã®æ¿èªã¬ã³ãŒããããã³5ã€ã®è¿œå ã¬ã³ãŒããå«ãŸããŸãã å¿çã®åèšã®é·ãã¯196ãã€ãã§ãã
3. TCPããã³UDP
åã«ãããšãDNSã¯UDPïŒããŒã53ïŒäžã§åäœããŸãã ãããå®éã®ããã©ã«ãã§ããèŠæ±ãšå¿çã¯UDPãä»ããŠéä¿¡ãããŸãã ãã ããã¡ãã»ãŒãžããããŒã«TCïŒTruncatedïŒãã©ã°ãååšããããšã¯äžèšã®ãšããã§ãã å¿çãµã€ãºã512ãã€ãïŒUDPå¿çã®å¶éïŒãè¶ ãããš1ã«èšå®ãããŸããããã¯ãå¿çãåæãããæåã®512ãã€ãã®ã¿ãã¯ã©ã€ã¢ã³ãã«éä¿¡ãããããšãæå³ããŸãã ãã®å Žåãã¯ã©ã€ã¢ã³ãã¯èŠæ±ãç¹°ãè¿ããŸãããTCPã䜿çšãããšããã®ç¹ç°æ§ã«ããã倧éã®ããŒã¿ãå®å šã«è»¢éã§ããŸãã
ãŸããã¡ã€ã³ãµãŒããŒããè¿œå ãµãŒããŒãžã®ãŸãŒã³ã®è»¢éã¯TCPãä»ããŠå®è¡ãããŸãããã®å Žåã512ãã€ããã¯ããã«è¶ ããããŒã¿ãéä¿¡ãããããã§ãã
4. Windows Server 2008ããã³2012ã®DNS
Windows 2008ã§ã¯ã次ã®æ©èœãå°å ¥ãããŸããã
ãŸãŒã³ã®ããã¯ã°ã©ãŠã³ãèªã¿èŸŒã¿
Active Directoryãã¡ã€ã³ãµãŒãã¹ã䜿çšããŠDNSããŒã¿ãä¿åããéåžžã«å€§ããªãŸãŒã³ãæã€éåžžã«å€§èŠæš¡ãªçµç¹ã§ã¯ãDNSããŒã¿ããã£ã¬ã¯ããªãµãŒãã¹ããååŸããããŸã§ãDNSãµãŒããŒã®åèµ·åã«1æé以äžãããããšããããŸãã åæã«ãActive Directoryãã¡ã€ã³ãµãŒãã¹ãŸãŒã³ãèªã¿èŸŒãã§ããéãã¯ã©ã€ã¢ã³ãèŠæ±ãåžžã«åŠçããããã«DNSãµãŒããŒã䜿çšã§ããŸããã
Windows Server 2008 DNSãµãŒããŒã¯ãåèµ·åæã«ããã¯ã°ã©ãŠã³ãã§Active Directoryãã¡ã€ã³ãµãŒãã¹ãããŸãŒã³ããŒã¿ãããŠã³ããŒãããä»ã®ãŸãŒã³ããã®ããŒã¿èŠæ±ãåŠçã§ããããã«ãªããŸããã DNSãµãŒããŒãèµ·åãããšã次ã®ã¢ã¯ã·ã§ã³ãå®è¡ãããŸãã
- ããŒãããããã¹ãŠã®ãŸãŒã³ãå®çŸ©ãããŠããŸãã
- ã«ãŒããªã³ã¯ã¯ããã¡ã€ã«ãŸãã¯Active Directoryãã¡ã€ã³ãµãŒãã¹ãªããžããªããããŒããããŸãã
- ãã¡ã€ã«ããµããŒããããŠãããã¹ãŠã®ãŸãŒã³ãã€ãŸãActive Directoryãã¡ã€ã³ãµãŒãã¹ã§ã¯ãªããã¡ã€ã«ã«ä¿åãããŠãããŸãŒã³ãèªã¿èŸŒãŸããŸãã
- èŠæ±ããã³ãªã¢ãŒãããã·ãŒãžã£ã³ãŒã«ïŒRPCïŒã®åŠçãéå§ãããŸãã
- Active Directoryãã¡ã€ã³ãµãŒãã¹ã«æ ŒçŽãããŠãããŸãŒã³ãèªã¿èŸŒãããã«ã1ã€ä»¥äžã®ã¹ã¬ãããäœæãããŸãã
ãŸãŒã³ã®èªã¿èŸŒã¿ã¿ã¹ã¯ã¯åå¥ã®ã¹ã¬ããã«ãã£ãŠå®è¡ããããããDNSãµãŒããŒã¯ãŸãŒã³ã®èªã¿èŸŒã¿äžã«èŠæ±ãåŠçã§ããŸãã DNSã¯ã©ã€ã¢ã³ãããæ¢ã«ããŒããããŠãããŸãŒã³å ã®ãã¹ãã®ããŒã¿ãèŠæ±ããå ŽåãDNSãµãŒããŒã¯ããŒã¿ïŒãŸãã¯ãé©åãªå Žåã¯åŠå®å¿çïŒã§å¿çããŸãã ã¡ã¢ãªã«ãŸã ããŒããããŠããªãããŒãã«å¯ŸããŠã¯ãšãªãå®è¡ããããšãDNSãµãŒããŒã¯Active Directoryãã¡ã€ã³ãµãŒãã¹ããããŒãããŒã¿ãèªã¿åããããã«å¿ããŠããŒãã¬ã³ãŒãã®ãªã¹ããæŽæ°ããŸãã
IPv6ã¢ãã¬ã¹ã®ãµããŒã
ã€ã³ã¿ãŒããããããã³ã«ããŒãžã§ã³6ïŒIPv6ïŒã¯ã32ãããé·ã®IPããŒãžã§ã³4ïŒIPv4ïŒã¢ãã¬ã¹ãšã¯å¯Ÿç §çã«ã128ãããé·ã®ã¢ãã¬ã¹ãå®çŸ©ããŸãã
Windows Server 2008 DNSãµãŒããŒã¯ãIPv4ã¢ãã¬ã¹ãšIPv6ã¢ãã¬ã¹ã®äž¡æ¹ãå®å šã«ãµããŒãããããã«ãªããŸããã dnscmdã³ãã³ãã©ã€ã³ããŒã«ã¯ãäž¡æ¹ã®åœ¢åŒã®ã¢ãã¬ã¹ãåãå ¥ããŸãã ãã©ã¯ãŒããŒã®ãªã¹ãã«ã¯ãIPv4ã¢ãã¬ã¹ãšIPv6ã¢ãã¬ã¹ã®äž¡æ¹ãå«ããããšãã§ããŸãã DHCPã¯ã©ã€ã¢ã³ãã¯ãIPv4ã¢ãã¬ã¹ãšãšãã«ïŒãŸãã¯IPv4ã¢ãã¬ã¹ã®ä»£ããã«ïŒIPv6ã¢ãã¬ã¹ãç»é²ããããšãã§ããŸãã æåŸã«ãDNSãµãŒããŒã¯åŸæ¹äžèŽã®ããã«ip6.arpaãã¡ã€ã³åå空éããµããŒãããããã«ãªããŸããã
DNSã¯ã©ã€ã¢ã³ãã®å€æŽ
LLMNRåå解決
DNSã¯ã©ã€ã¢ã³ãã³ã³ãã¥ãŒã¿ãŒã¯ããã«ããã£ã¹ãDNSãŸãã¯mDNSãšãåŒã°ããLLMNRïŒãªã³ã¯ããŒã«ã«ãã«ããã£ã¹ãåå解決ïŒã䜿çšããŠãDNSãµãŒããŒãå©çšã§ããªãLANã»ã°ã¡ã³ãã®ååã解決ã§ããŸãã ããšãã°ãã«ãŒã¿ãŒã®èª€åäœã«ãããµããããããããã¯ãŒã¯å ã®ãã¹ãŠã®DNSãµãŒããŒããåé¢ãããŠããå ŽåãLLMNRåå解決ããµããŒããããã®ãµããããäžã®ã¯ã©ã€ã¢ã³ãã¯ããããã¯ãŒã¯ãžã®æ¥ç¶ã埩å ããããŸã§ããã¢ããŒãã¢ã¹ããŒã ã䜿çšããŠååã解決ã§ããŸãã
ãããã¯ãŒã¯é害ãçºçããå Žåã®ååã®è§£æ±ºã«å ããŠãLLMNRé¢æ°ã¯ã空枯ã©ãŠã³ãžãªã©ã§ãã¢ããŒãã¢ãããã¯ãŒã¯ãå±éããå Žåã«ã圹ç«ã¡ãŸãã
DNSã«é¢ããWindows 2012ã®å€æŽã¯ãäž»ã«DNSSECãã¯ãããžã«åœ±é¿ãïŒDNSã¬ã³ãŒãã«ããžã¿ã«çœ²åãè¿œå ããããšã§DNSã»ãã¥ãªãã£ã確ä¿ããŸãïŒãç¹ã«ãWindows Server 2008ã§DNSSECãæå¹ã«ãªã£ããšãã«å©çšã§ããªãã£ãåçæŽæ°ãæäŸããŸããã
5. DNSããã³Active Directory
Active Directoryã¯ããã®æäœã«é¢ããŠDNSã«å€§ããäŸåããŠããŸãã ããã«ããããã¡ã€ã³ã³ã³ãããŒã©ãŒã¯è€è£œã®ããã«ãäºããæ¢ããŸãã ã¯ã©ã€ã¢ã³ãïŒããã³NetlogonãµãŒãã¹ïŒã䜿çšããŠãã¯ã©ã€ã¢ã³ãã¯æ¿èªã®ããã«ãã¡ã€ã³ã³ã³ãããŒã©ãŒãå®çŸ©ããŸãã
æ€çŽ¢ãæäŸããããã«ããµãŒããŒäžã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®åœ¹å²ãäžããããã»ã¹ã§ããã®NetlogonãµãŒãã¹ã¯å¯Ÿå¿ããAããã³SRVã¬ã³ãŒããDNSã«ç»é²ããŸãã
Net Logonã«ãã£ãŠèšé²ãããSRVã¬ã³ãŒãïŒ
_ldap._tcp.DnsDomainName
_ldap._tcp.SiteName._sites.DnsDomainName
_ldap._tcp.dc._msdcs.DnsDomainName
_ldap._tcp.SiteName._sites.dc._msdcs.DnsDomainName
_ldap._tcp.pdc._msdcs.DnsDomainName
_ldap._tcp.gc._msdcs.DnsForestName
_ldap._tcp.SiteName._sites.gc._msdcsã DnsForestName
_gc._tcp.DnsForestName
_gc._tcp.SiteName._sites.DnsForestName
_ldap._tcp.DomainGuid.domains._msdcs.DnsForestName
_kerberos._tcp.DnsDomainNameã
_kerberos._udp.DnsDomainName
_kerberos._tcp.SiteName._sites.DnsDomainName
_kerberos._tcp.dc._msdcs.DnsDomainName
_kerberos.tcp.SiteName._sites.dc._msdcs.DnsDomainName
_kpasswd._tcp.DnsDomainName
_kpasswd._udp.DnsDomainName
SRVã¬ã³ãŒãã®æåã®éšåã¯ãSRVã¬ã³ãŒããæããµãŒãã¹ãèå¥ããŸãã 次ã®ãµãŒãã¹ãå©çšã§ããŸãã
_ldap -Active Directoryã¯ãLDAPãµãŒããŒãšããŠæ©èœãããã¡ã€ã³ã³ã³ãããŒã©ãŒãåããLDAPæºæ ã®ãã£ã¬ã¯ããªãµãŒãã¹ã§ãã ã¬ã³ãŒã_ldap SRVã¯ããããã¯ãŒã¯ã§å©çšå¯èœãªLDAPãµãŒããŒãèå¥ããŸãã ãããã®ãµãŒããŒã¯ãWindows Server 2000+ãã¡ã€ã³ã³ã³ãããŒã©ãŒãŸãã¯ä»ã®LDAPãµãŒããŒã«ããããšãã§ããŸãã
_kerberos - SRKã¬ã³ãŒã_kerberosã¯ããããã¯ãŒã¯äžã®ãã¹ãŠã®ããŒé åžã»ã³ã¿ãŒïŒKDCïŒãèå¥ããŸãã ãããã¯ãWindows Server 2003ãŸãã¯ä»ã®KDCãµãŒããŒãåãããã¡ã€ã³ã³ã³ãããŒã©ãŒã«ããããšãã§ããŸãã
_kpassword-ãããã¯ãŒã¯äžã®Kerberosãã¹ã¯ãŒãå€æŽãµãŒããŒãèå¥ããŸãã
_gcã¯ãActive Directoryã®ã°ããŒãã«ã«ã¿ãã°æ©èœã«é¢é£ãããšã³ããªã§ãã
_mcdcsãµããã¡ã€ã³ã«ã¯ãMicrosoft Windows Serverãã¡ã€ã³ã³ã³ãããŒã©ãŒã®ã¿ãç»é²ãããŠããŸãã ãã®ãµããã¡ã€ã³ã«ãã¹ã¿ãŒã¬ã³ãŒããšãšã³ããªã®äž¡æ¹ãäœæããŸãã ãã€ã¯ããœãã以å€ã®ãµãŒãã¹ã¯ããã¹ã¿ãŒãšã³ããªã®ã¿ãäœæããŸãã
SiteNameãµã€ãèå¥åãå«ãã¬ã³ãŒãã¯ãã¯ã©ã€ã¢ã³ããèªåã®ãµã€ãã§æ¿èªçšã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒãèŠã€ããããšãã§ããäœéãã£ã³ãã«ãä»ããŠå¥ã®éœåžã«ãã°ã€ã³ããããã«ç»ããªãããã«ããããã«å¿ èŠã§ãã
DomainGuidã¯ãã°ããŒãã«ãã¡ã€ã³èå¥åã§ãã ãã¡ã€ã³ã®ååãå€æŽãããå Žåããããå«ãã¬ã³ãŒããå¿ èŠã§ãã
DCæ€çŽ¢ããã»ã¹ã¯ã©ã®ããã«é²ã¿ãŸãã
ãŠãŒã¶ãŒã®ãã°ã€ã³æã«ãã¯ã©ã€ã¢ã³ãã¯ãªã¢ãŒãããã·ãŒãžã£ã³ãŒã«ïŒRPCïŒã䜿çšããŠNetLogonãµãŒãã¹ã䜿çšããŠDNSãã±ãŒã¿ãŒãéå§ããŸãã åæããŒã¿ãšããŠãã³ã³ãã¥ãŒã¿ãŒåããã¡ã€ã³ãããã³ãµã€ãåãããã·ãŒãžã£ã«è»¢éãããŸãã
ãµãŒãã¹ã¯ãAPIé¢æ°DsGetDcNameïŒïŒã䜿çšããŠ1ã€ä»¥äžã®èŠæ±ãéä¿¡ããŸã
DNSãµãŒããŒã¯ãåªå 床ãšéã¿ã«åŸã£ãŠãœãŒãããããµãŒããŒã®èŠæ±ãªã¹ããè¿ããŸãã ã¯ã©ã€ã¢ã³ãã¯ãUDPããŒã389ã䜿çšããŠãè¿ãããé ã«åã¬ã³ãŒãã¢ãã¬ã¹ã«LDAPèŠæ±ãéä¿¡ããŸãã
䜿çšå¯èœãªãã¹ãŠã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒããã®èŠæ±ã«å¿çãããã®ç¶æ ãå ±åããŸãã
ãã¡ã€ã³ã³ã³ãããŒã©ãæ€åºãããåŸãã¯ã©ã€ã¢ã³ãã¯Active Directoryãžã®ã¢ã¯ã»ã¹ãååŸããããã«LDAPã³ã³ãããŒã©ã確ç«ããŸãã ãã€ã¢ãã°ã®äžéšãšããŠããã¡ã€ã³ã³ã³ãããŒã©ãŒã¯IPã¢ãã¬ã¹ã«åºã¥ããŠã¯ã©ã€ã¢ã³ãããã¹ããããŠãããµã€ãã決å®ããŸãã ã¯ã©ã€ã¢ã³ããæãè¿ãDCã«æ¥ç¶ããªãã£ãããããšãã°ãæè¿å¥ã®ãµã€ãã«ç§»åããå€ããµã€ãããç¿æ £çã«èŠæ±ãããDCããªããªã£ãããšãå€æããå ŽåïŒãµã€ãæ å ±ã¯ãæåŸã«æåãããã°ã€ã³ã®çµæã«åºã¥ããŠã¯ã©ã€ã¢ã³ãã«ãã£ãã·ã¥ãããŸãïŒãã³ã³ãããŒã©ãŒã¯åœŒã«ãã®ååïŒã¯ã©ã€ã¢ã³ãïŒãéä¿¡ããŸãæ°ãããµã€ãã ã¯ã©ã€ã¢ã³ãããã§ã«ãã®ãµã€ãã§ã³ã³ãããŒã©ãŒãèŠã€ããããšãããã圹ã«ç«ããªãå Žåã¯ãèŠã€ãã£ãã³ã³ãããŒã©ãŒãåŒãç¶ã䜿çšããŸãã ããã§ãªãå Žåã¯ãæ°ãããµã€ãã瀺ãæ°ããDNSã¯ãšãªãéå§ãããŸãã
NetlogonãµãŒãã¹ã¯ããã¡ã€ã³ã³ã³ãããŒã©ãŒã®å Žæã«é¢ããæ å ±ããã£ãã·ã¥ããŠãDCã«ã¢ã¯ã»ã¹ããå¿ èŠããããã³ã«æé å šäœãéå§ããªãããã«ããŸãã ãã ãããå¥ã®ãµã€ãã«ããããæé©ã§ãªããDCã䜿çšãããŠããå Žåãã¯ã©ã€ã¢ã³ãã¯15ååŸã«ãã®ãã£ãã·ã¥ãã¯ãªã¢ããïŒæé©ãªã³ã³ãããŒã©ãŒãèŠã€ããããã«ïŒæ€çŽ¢ãåéããŸãã
ãã£ãã·ã¥ã«ãµã€ãã«é¢ããæ å ±ããªãå Žåãã³ã³ãã¥ãŒã¿ãŒã¯ãã¡ã€ã³ã³ã³ãããŒã©ãŒã«æ¥ç¶ããŸãã ãã®åäœãæå¶ããããã«ãDNSã§NetMask Orderingãæ§æã§ããŸãã DNSã¯ãã¯ã©ã€ã¢ã³ããšåããããã¯ãŒã¯äžã«ããã³ã³ãããŒã©ãŒãæåã®é çªã§DCãªã¹ãã衚瀺ããŸãã
äŸïŒ Dnscmd / Config / LocalNetPriorityNetMask 0x0000003Fã¯ãåªå DCã®ãµãããããã¹ã¯255.255.255.192ãæå®ããŸãã ããã©ã«ãã®ãã¹ã¯ã¯255.255.255.0ïŒ0x000000FFïŒã§ã
æ å ±æºïŒ
www.hardline.ru/4/49/1236/1630-25.html
www.inadmin.ru/2010/02/26/dns-internet-domain
minergimn.ru/statii/16-adwin2003132
technet.microsoft.com/en-us/library/cc728909.aspx
support.microsoft.com/kb/247811/en-us?fr=1