This shows you the differences between two versions of the page.
manuals:server:secondary_dns [2024/07/20 17:25] – created aither | manuals:server:secondary_dns [2024/07/21 13:35] (current) – Hidden primary server aither | ||
---|---|---|---|
Line 7: | Line 7: | ||
The list of secondary servers shows their status, i.e., the current zone serial number and the dates of the last load, the next refresh, and expiration. | The list of secondary servers shows their status, i.e., the current zone serial number and the dates of the last load, the next refresh, and expiration. | ||
+ | |||
+ | ===== Hidden primary server ===== | ||
+ | It is possible to run your primary server on a private IPv4 address, or to simply not have it | ||
+ | accessible from the Internet at all. In that case, delegate your domain at your registrar only to | ||
+ | the shared secondary servers, i.e. ns3.vpsfree.cz and ns4.vpsfree.cz. | ||
===== TSIG ===== | ===== TSIG ===== | ||
Zone transfers between primary and secondary servers can be further secured using TSIG. First, create a shared key in the menu DNS -> TSIG Keys. Each key is identified by an arbitrary name, chosen algorithm, and secret code. These values must match on all servers. When adding primary servers to a zone, you can set the selected TSIG key. The sample configuration again shows how to set up TSIG on the primary server. | Zone transfers between primary and secondary servers can be further secured using TSIG. First, create a shared key in the menu DNS -> TSIG Keys. Each key is identified by an arbitrary name, chosen algorithm, and secret code. These values must match on all servers. When adding primary servers to a zone, you can set the selected TSIG key. The sample configuration again shows how to set up TSIG on the primary server. | ||