0:00–0:10
Recap
0:10–1:45
Lab 3D
1:45–1:55
Bonus
1:55–2:00
Wrap
0:00 – 0:10Recap · 10 min

Forward DNS verified — now extend with reverse and redundancy

0:10 – 1:45Lab 3D · 95 min

Lab 3D — Reverse zone, secondary DNS on S2, zone transfer verification, allow-transfer, dig

Part 1 — Add the reverse zone declaration (15 min)

Part 2 — Create the reverse zone database file (20 min)

Part 3 — Configure S2 as a secondary DNS server (30 min)

Part 4 — Using dig for DNS interrogation (30 min)

Lab 3D complete when: Reverse zone loaded and PTR records resolve correctly via dig -x. S2 has successfully transferred both zones from S1 (confirmed in logs). S2 can answer queries for yourname.net. allow-transfer restricts AXFR to S2 only — S3 receives REFUSED. dig examples tested and output sections documented in lab sheet.
1:45 – 1:55Bonus · 10 min

Public zone transfer with dig — what AXFR reveals

1:55 – 2:00Wrap · 5 min

Learning outcomes — by end of Day 4, students can…

Build a reverse lookup zoneWrite a zone declaration using in-addr.arpa notation and create a zone file with correct PTR records and trailing dots on FQDNs
Configure secondary DNSWrite a type secondary zone declaration on S2 with the primaries directive, and verify successful zone transfer in the BIND9 log
Restrict zone transfersAdd allow-transfer to a primary zone and confirm AXFR is refused from unauthorised sources
Use dig for DNS interrogationQuery specific record types, interpret all four dig output sections, and explain what AXFR exposes

Common issues and fixes

IssueLikely causeFix
Reverse lookup returns NXDOMAINPTR records missing trailing dots on FQDNs, or zone not reloaded after adding PTR recordsEvery PTR target must end with a dot: 1 PTR s1.yourname.net. Reload: sudo systemctl reload named
Zone transfer on S2 fails — "connection refused" in logS1's named.conf.local still has notify no and no allow-transfer for S2Add allow-transfer { 192.168.50.2; }; to both zone declarations on S1. Change notify no to notify yes. Restart S1's named
dig AXFR from S2 returns REFUSEDallow-transfer not yet added to S1's zone, or added to wrong zone blockCheck S1's named.conf.local — allow-transfer must be inside the zone block, not outside it. Run named-checkconf after editing
S2's zone transfer succeeds but dig @S2 returns SERVFAILS2's BIND9 loaded a corrupted or incomplete zone file from the transferDelete the cached file on S2: sudo rm /var/cache/bind/db.yourname.net. Restart S2's named to re-transfer
← Day 3 Lab 3D Handout Day 5 →