Network and System AdministrationUnit 312 min read
DNS: Servers, Zones, Records, Security & Virtual Hosting
Unit 3 of Network and System Administration explores the Domain Name System (DNS), covering its architecture, server types (primary, secondary, caching), zone transfers, record types (A, MX, CNAME), DNS security (DNSSEC), and virtual hosting techniques (name-based vs. IP-based). Real-world examples from eSewa, Ncell, a
TAKEAWAYS:
- DNS translates human-readable domain names (e.g.,
esewa.com.np) into machine-readable IP addresses (e.g.,103.10.10.10) using a hierarchical, distributed database. - DNS servers are classified into primary (authoritative), secondary (slave), and caching (resolver) types, each with distinct roles in resolving queries.
- Zone transfers (AXFR/IXFR) synchronize DNS data between primary and secondary servers, ensuring redundancy and load balancing.
- DNS record types (A, AAAA, MX, CNAME, NS, TXT, SOA) define how data is stored and resolved, with each serving a specific purpose (e.g., MX for email routing).
- DNS security relies on DNSSEC (Domain Name System Security Extensions) to prevent spoofing and cache poisoning via digital signatures.
- Virtual hosting (name-based or IP-based) allows a single server to host multiple websites, with name-based being more scalable but less secure than IP-based.
1. What is DNS? The Internet’s Phonebook
DNS stands for Domain Name System, the backbone of the internet’s naming system. Without DNS, you’d have to memorize IP addresses like 103.10.10.10 instead of typing esewa.com.np. It’s a distributed, hierarchical database that maps domain names to IP addresses and manages other records (e.g., email servers, load balancers).
How DNS Works: A Step-by-Step Trace
When you type khalti.com in your browser, this happens:
- Local Cache Check: Your device checks its local DNS cache (stored in
hostsfile or browser). - Recursive Resolver Query: If not found, your request goes to a recursive DNS resolver (e.g., Ncell’s
10.10.10.10or Google’s8.8.8.8). - Root Server: The resolver queries the root DNS server (
.) to find the Top-Level Domain (TLD) server for.com. - TLD Server: The
.comserver directs the resolver to the authoritative name server forkhalti.com. - Authoritative Server: The name server returns the A record (IP address) for
khalti.com. - Response: The resolver caches the result and sends it back to your device.
sequenceDiagram
participant User
participant LocalCache
participant RecursiveResolver
participant RootServer
participant TLDServer
participant AuthoritativeServer
User->>LocalCache: khalti.com?
LocalCache-->>User: Not found
User->>RecursiveResolver: khalti.com?
RecursiveResolver->>RootServer: .com?
RootServer-->>RecursiveResolver: TLD: .com server IP
RecursiveResolver->>TLDServer: khalti.com?
TLDServer-->>RecursiveResolver: Authoritative: ns1.khalti.com
RecursiveResolver->>AuthoritativeServer: khalti.com A record?
AuthoritativeServer-->>RecursiveResolver: 103.10.10.20
RecursiveResolver-->>User: 103.10.10.20 (cached)2. DNS Server Types: Roles and Responsibilities
DNS servers are categorized based on their function:
| Server Type | Role | Example | Port |
|---|---|---|---|
| Primary (Master) | Authoritative; stores original zone data; updates records. | ns1.esewa.com.np |
53 (TCP/UDP) |
| Secondary (Slave) | Replicates data from primary via zone transfer; provides redundancy. | ns2.esewa.com.np |
53 |
| Caching (Resolver) | Stores frequently accessed records to speed up future queries. | Google Public DNS (8.8.8.8) |
53 |
| Forwarding | Sends queries to another resolver if it can’t resolve locally. | Corporate DNS servers | 53 |
| Root Server | Top of the DNS hierarchy; directs to TLD servers. | a.root-servers.net |
53 |
Why Use Secondary Servers?
- Redundancy: If the primary server fails, secondaries take over.
- Load Balancing: Distributes query load.
- Geographic Distribution: Secondaries can be hosted in different regions (e.g., Kathmandu vs. Pokhara).
Worked Example: Ncell’s DNS Setup Ncell uses a primary-secondary DNS pair:
- Primary:
ns1.ncell.com.np(hosts zone files forncell.com.np). - Secondary:
ns2.ncell.com.np(replicates data via zone transfer every 2 hours). - If
ns1crashes,ns2answers queries untilns1recovers.
3. DNS Zone Transfers: Keeping Servers in Sync
A zone transfer (AXFR: Asynchronous Xfer or IXFR: Incremental Xfer) copies DNS zone data from a primary to a secondary server.
How It Works
- The secondary server sends a SOA query to the primary to check for updates.
- If the serial number in the SOA record has changed, the primary initiates a transfer.
- AXFR: Transfers the entire zone file (inefficient for large zones).
- IXFR: Transfers only changed records (faster, used by modern DNS servers like BIND).
sequenceDiagram
participant SecondaryServer
participant PrimaryServer
SecondaryServer->>PrimaryServer: SOA Query (Check serial)
PrimaryServer-->>SecondaryServer: Serial=2024051501
SecondaryServer->>PrimaryServer: Request IXFR
PrimaryServer-->>SecondaryServer: Incremental updates (only changes)When is Zone Transfer Used?
- After manual updates to DNS records (e.g., changing
esewa.com.npto point to a new server). - During DNS failover (e.g., if the primary server is down).
Security Risk: Zone Walking
- Attackers can exploit misconfigured servers to enumerate all domains in a zone.
- Fix: Restrict zone transfers to trusted IPs using
allow-transferin BIND.
4. DNS Record Types: The Building Blocks
DNS records store different types of data. Here are the most important ones:
| Record Type | Purpose | Example | TTL (Default) |
|---|---|---|---|
| A | Maps a domain to an IPv4 address. | esewa.com.np A 103.10.10.10 |
86400 sec |
| AAAA | Maps a domain to an IPv6 address. | google.com AAAA 2607:f8b0:4009 |
3600 sec |
| MX | Specifies mail exchange servers for email routing. | khalti.com MX 10 mail.khalti.com |
3600 sec |
| CNAME | Creates an alias for another domain. | www.esewa.com.np CNAME esewa.com.np |
3600 sec |
| NS | Defines authoritative name servers for a domain. | esewa.com.np NS ns1.esewa.com.np |
86400 sec |
| SOA | Start of Authority; contains zone metadata (admin, refresh rate). | esewa.com.np SOA ns1.esewa.com.np |
86400 sec |
| TXT | Stores text records (e.g., SPF, DKIM, verification). | esewa.com.np TXT "v=spf1 include:_spf.esewa.com" |
3600 sec |
| PTR | Reverse DNS; maps an IP to a domain (used for email anti-spam). | 10.10.10.10 PTR esewa.com.np |
86400 sec |
Worked Example: NEPSE’s DNS Records
NEPSE (nepse.com.np) uses:
- A Record:
nepse.com.np → 192.168.1.100 - MX Record:
nepse.com.np → mail.nepse.com.np(for emails) - CNAME:
www.nepse.com.np → nepse.com.np(redirectswwwto root) - TXT Record: SPF record to prevent email spoofing.
5. DNS Security: Preventing Attacks
DNS is a prime target for attacks like:
- DNS Spoofing (Cache Poisoning): Fake records redirect users to malicious sites.
- DNS Amplification Attacks: Attackers exploit open resolvers to flood targets.
- Domain Hijacking: Attackers change DNS records to steal traffic.
DNSSEC: Securing DNS with Digital Signatures
DNSSEC adds cryptographic signatures to DNS records to verify authenticity.
How DNSSEC Works:
- Each zone has a Zone Signing Key (ZSK) and Key Signing Key (KSK).
- Records are signed with the ZSK, and the ZSK is signed by the KSK.
- Resolvers verify signatures using the public key stored in DNSKEY records.
stateDiagram-v2
[*] --> Resolver: Queries DNS
Resolver --> Authoritative: Requests Record
Authoritative --> Resolver: Signed Record + DNSKEY
Resolver --> TrustAnchor: Validates with Root KSK
TrustAnchor --> Resolver: Verifies Signature
Resolver --> User: Returns Secure ResponseReal-World Example: Google’s DNSSEC
Google Public DNS (8.8.8.8) supports DNSSEC, preventing attacks like:
- Redirecting
esewa.com.npto a fake login page. - Spoofing
khalti.comto steal payment details.
6. Virtual Hosting: Serving Multiple Websites on One Server
Virtual hosting allows a single server to host multiple websites. Two methods:
| Method | How It Works | Pros | Cons |
|---|---|---|---|
| Name-Based | Uses Host header in HTTP requests to distinguish sites. | - No extra IPs needed. | - Requires HTTP (not HTTPS by default). |
| IP-Based | Each site has a dedicated IP address. | - Works with HTTPS. | - Needs multiple IPs. |
Worked Example: Daraz’s Virtual Hosting
Daraz (daraz.com.np) uses name-based virtual hosting:
- A single server (
103.10.10.50) hosts:daraz.com.np(main site)www.daraz.com.np(CNAME alias)blog.daraz.com.np(separate subdomain)
- The web server (Apache/Nginx) uses the
Hostheader to serve the correct site.
Proxy ACL (Access Control List)
- Restricts which IPs can access certain virtual hosts.
- Example: Only allow
192.168.1.0/24to accessadmin.daraz.com.np.
classDiagram
class Server {
+IP: 103.10.10.50
+Hosts: daraz.com.np, blog.daraz.com.np
}
class Apache {
+Uses Host header
+VirtualHost directive
}
class User {
+Requests daraz.com.np
}
User --> Apache : HTTP Request (Host: daraz.com.np)
Apache --> Server : Serves correct site7. Real-World Applications of DNS
Example 1: eSewa’s DNS Setup
- Primary DNS:
ns1.esewa.com.np(hosts all records). - Secondary DNS:
ns2.esewa.com.np(replicates via IXFR every hour). - Records Used:
Aforesewa.com.np → 103.10.10.10MXfor email routing tomail.esewa.com.npTXTfor SPF/DKIM to prevent email fraud.
- Why? Ensures high availability (if one server fails, the other takes over).
Example 2: Ncell’s Load Balancing with DNS
- Ncell uses round-robin DNS to distribute traffic:
ncell.com.npresolves to:103.10.10.1(Server 1)103.10.10.2(Server 2)
- Each request alternates between servers, balancing load.
Example 3: Google’s Global DNS (Anycast)
- Google uses Anycast DNS to route queries to the nearest server:
- A request to
8.8.8.8is answered by the closest Google DNS server (e.g., Kathmandu vs. Singapore).
- A request to
- Benefit: Faster response times and redundancy.
Exam Tip: How to Score Full Marks
- Define Clearly: Always start with a precise definition (e.g., "DNS is a distributed hierarchical database that translates domain names to IP addresses").
- Use Diagrams: Draw sequence diagrams for DNS lookups and state diagrams for DNSSEC validation.
- Compare Tables: For virtual hosting, use a pros/cons table (name-based vs. IP-based).
- Real-World Links: Relate answers to Nepali examples (eSewa, Ncell, Daraz) or global examples (Google DNS, Anycast).
- Security Focus: Always mention DNSSEC when discussing security.
- Worked Examples: Solve zone transfer scenarios (e.g., "If the SOA serial changes from 2024051501 to 2024051502, what happens?").
Common Pitfalls to Avoid:
- Confusing AXFR (full transfer) and IXFR (incremental).
- Forgetting TTL (Time to Live) in record explanations.
- Not mentioning SOA records in zone transfer questions.
Based on the TU BIT syllabus for Network and System Administration (BIT451), unit 3.
Discussion
Loading…